Oh wow. I've seen this before. I can't remember the name, something like an 'inadvertent reflective DDOS attack'.
Here's whats happening. A spammer is sending you emails to known bad addresses at your domain, with the real intended address forged as the return address. Your machine will faithfully 'return' the 'poorly' addressed email to the 'sender', in effect reflecting the spam off of you.. The last time I saw this, I couldn't block the offending IP's ( over 2k of them ), and filtering was such a huge load on the machine ( over 500k a month, and climbing ), the only option left was changing domain names or co-locating a beefier Declude box upstream... Changing domain names was cheaper. Karl Drugge -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Stan Buck Sent: Tuesday, September 21, 2004 11:50 AM To: [EMAIL PROTECTED] Subject: [Declude.Virus] Attack? For three days now we've been getting these emails addressed to random strings every few minutes. IPs keep changing. Sometimes one mail per IP, sometimes several. What is this? Zombie computers? Forged IPs? And how many hits are you going to get with random strings? 09:21 00:00 SMTPD(54FA0120) [10.0.0.109] connect 216.167.161.91 port 34112 09:21 00:00 SMTPD(54FA0120) [216.167.161.91] EHLO pop3.nts-online.net 09:21 00:00 SMTPD(54FA0120) [216.167.161.91] MAIL FROM:<> 09:21 00:00 SMTPD(54FA0120) [216.167.161.91] RCPT TO:<[EMAIL PROTECTED]> 09:21 00:00 SMTPD(54FA0120) [216.167.161.91] ERR mdchildcare.org invalid user <[EMAIL PROTECTED] 09:21 00:01 SMTPD(56180120) [10.0.0.109] connect 131.103.218.79 port 20368 09:21 00:01 SMTPD(56180120) [131.103.218.79] HELO mail15a.boca15-verio.com 09:21 00:01 SMTPD(56180120) [131.103.218.79] MAIL FROM:<> 09:21 00:01 SMTPD(56180120) [131.103.218.79] RCPT TO:<[EMAIL PROTECTED]> 09:21 00:01 SMTPD(56180120) [131.103.218.79] ERR mdchildcare.org invalid user <[EMAIL PROTECTED] 09:21 00:14 SMTPD(6B9E0124) [10.0.0.109] connect 64.29.144.72 port 49234 09:21 00:14 SMTPD(6B9E0124) [64.29.144.72] EHLO mx305.megamailservers.com 09:21 00:14 SMTPD(6B9E0124) [64.29.144.72] MAIL From:<> 09:21 00:14 SMTPD(6B9E0124) [64.29.144.72] RCPT To:<[EMAIL PROTECTED]> 09:21 00:14 SMTPD(6B9E0124) [64.29.144.72] ERR mdchildcare.org invalid user <[EMAIL PROTECTED] 09:21 00:14 SMTPD(6BB80124) [10.0.0.109] connect 206.190.36.133 port 20018 09:21 00:14 SMTPD(6BB80124) [206.190.36.133] HELO mta137.mail.re2.yahoo.com 09:21 00:14 SMTPD(6BB80124) [206.190.36.133] MAIL FROM:<> 09:21 00:14 SMTPD(6BB80124) [206.190.36.133] RCPT TO:<[EMAIL PROTECTED]> 09:21 00:14 SMTPD(6BB80124) [206.190.36.133] ERR mdchildcare.org invalid user <[EMAIL PROTECTED] --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com. --- ---------- PLEASE NOTE : Florida has a very broad public records law. Most written communications to or from City officials regarding City business are public records available to the public and media upon request. Your E-mail communications may be subject to public disclosure. PLEASE NOTE : Florida has a very broad public records law. Most written communications to or from City officials regarding City business are public records available to the public and media upon request. Your E-mail communications may be subject to public disclosure. --- --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.
