>What do others on this list do to eliminate the harvesting of email
>addresses? Recently we have seen in our logs several attempts to harest
>email addresses on our servers. We have take action as soon as we discover
>the incident, but are there other methods that we could be using?
I set up up client with IMGate, doing about 5 million msgs/month.
Before I got off the job, he was attacked a harvestor was using SMTP
command pipelining which we had turned off by default at IMGate. The
5000 msgs/hour were blocked at IMgate.
A lot of these harvesters run from cable and DSL ip's, that are in
DUL database, also rejected by IMgate.
By putting the list of known Imail users on IMGate, IMGate will
reject the 99% of harvesting msgs that are to unknown users.
"Reject" is not "bounce". Rejects are not let into IMGate, so they
don't muck up IMGate mailq with bounces.
Another IMGate tactic is tarpitting where after a definable number of
errors per session, IMGate will increase its SMTP response time, so
the other end (if they are waiting for responses at all) gets slowed
down. ie, like when you send mail to Yahoo, :)))) and it sucks up
one of your SMTP sessions for 5 minutes to send a tiny msg.
Finally, the manual interventions you've taken at IMail, can be taken
at IMgate level, too.
The message is that the DoS is moved to IMGate, so IMail, and the
users, doen't feel a thing.
Len
http://MenAndMice.com/DNS-training Austin,TX: 23,24- Apr; SFO,CA; 7,8
May
http://BIND8NT.MEIway.com : ISC BIND 8.2.3 "NT3" for NT4 & W2K
http://IMGate.MEIway.com : Build free, hi-perf, anti-abuse mail gateways
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/