Oh wow. I've seen this before.

I can't remember the name, something like an 'inadvertent reflective
DDOS attack'.

Here's whats happening. A spammer is sending you emails to known bad
addresses at your domain, with the real intended address forged as the
return address. Your machine will faithfully 'return' the 'poorly'
addressed email to the 'sender', in effect reflecting the spam off of
you..

The last time I saw this, I couldn't block the offending IP's ( over 2k
of them ), and filtering was such a huge load on the machine ( over 500k
a month, and climbing ), the only option left was changing domain names
or co-locating a beefier Declude box upstream... Changing domain names
was cheaper.


Karl Drugge
 
 
 
 
 
 


-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Stan Buck
Sent: Tuesday, September 21, 2004 11:50 AM
To: [EMAIL PROTECTED]
Subject: [Declude.Virus] Attack?


For three days now we've been getting these emails addressed to random
strings every few minutes.  IPs keep changing.  Sometimes one mail per
IP, sometimes several.  What is this?  Zombie computers?  Forged IPs?
And how many hits are you going to get with random strings?

09:21 00:00 SMTPD(54FA0120) [10.0.0.109] connect 216.167.161.91 port
34112 09:21 00:00 SMTPD(54FA0120) [216.167.161.91] EHLO
pop3.nts-online.net 09:21 00:00 SMTPD(54FA0120) [216.167.161.91] MAIL
FROM:<> 09:21 00:00 SMTPD(54FA0120) [216.167.161.91] RCPT
TO:<[EMAIL PROTECTED]>
09:21 00:00 SMTPD(54FA0120) [216.167.161.91] ERR mdchildcare.org invalid
user <[EMAIL PROTECTED] 09:21 00:01 SMTPD(56180120)
[10.0.0.109] connect 131.103.218.79 port 20368 09:21 00:01
SMTPD(56180120) [131.103.218.79] HELO mail15a.boca15-verio.com 09:21
00:01 SMTPD(56180120) [131.103.218.79] MAIL FROM:<> 09:21 00:01
SMTPD(56180120) [131.103.218.79] RCPT TO:<[EMAIL PROTECTED]> 09:21
00:01 SMTPD(56180120) [131.103.218.79] ERR mdchildcare.org invalid user
<[EMAIL PROTECTED] 09:21 00:14 SMTPD(6B9E0124) [10.0.0.109]
connect 64.29.144.72 port 49234 09:21 00:14 SMTPD(6B9E0124)
[64.29.144.72] EHLO mx305.megamailservers.com 09:21 00:14
SMTPD(6B9E0124) [64.29.144.72] MAIL From:<> 09:21 00:14 SMTPD(6B9E0124)
[64.29.144.72] RCPT To:<[EMAIL PROTECTED]> 09:21 00:14
SMTPD(6B9E0124) [64.29.144.72] ERR mdchildcare.org invalid user
<[EMAIL PROTECTED] 09:21 00:14 SMTPD(6BB80124) [10.0.0.109] connect
206.190.36.133 port 20018 09:21 00:14 SMTPD(6BB80124) [206.190.36.133]
HELO mta137.mail.re2.yahoo.com 09:21 00:14 SMTPD(6BB80124)
[206.190.36.133] MAIL FROM:<> 09:21 00:14 SMTPD(6BB80124)
[206.190.36.133] RCPT TO:<[EMAIL PROTECTED]> 09:21 00:14
SMTPD(6BB80124) [206.190.36.133] ERR mdchildcare.org invalid user
<[EMAIL PROTECTED]

---
[This E-mail was scanned for viruses by Declude Virus
(http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To unsubscribe,
just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.
---
----------
PLEASE NOTE : Florida has a very broad public records law. Most written
communications to or from City officials regarding City business are
public records available to the public and media upon request. Your
E-mail communications may be subject to public disclosure.
PLEASE NOTE : Florida has a very broad public records law. Most written communications 
to or from City officials regarding City business are public records available to the 
public and media upon request. Your E-mail communications may be subject to public 
disclosure.
---

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to