As I posted earlier, we were getting bogged down by the request listed below. I searched the archives and found that others experienced similar attacks, generating huge log files, etc. I have since checked off Auto deny possible hack attempts and that seems to have stopped the attack. My question is: Did this in fact stop the attack? Or was it coincidental? What was actually happening? I'm new at this mail admin stuff and realize that I had better learn some of the basics regarding how mail servers interact with each other. Any help is appreciated, whether it's in the form of replies or the name of some good reference materials. 08:07 20:32 SMTP-(0000010E) Connect datasilk.com [209.196.45.55:25] (2) 08:07 20:32 SMTP-(0000010E) 220 X1 NT-ESMTP Server mail.datasilk.com (IMail 7.00 4091-1) 08:07 20:32 SMTP-(0000010E) >EHLO marlinfirearms.com 08:07 20:32 SMTP-(0000010E) 250-mail.datasilk.com says hello 08:07 20:32 SMTP-(0000010E) 250-SIZE 0 08:07 20:32 SMTP-(0000010E) 250-8BITMIME 08:07 20:32 SMTP-(0000010E) 250-DSN 08:07 20:32 SMTP-(0000010E) 250-ETRN 08:07 20:32 SMTP-(0000010E) 250-AUTH LOGIN CRAM-MD5 08:07 20:32 SMTP-(0000010E) 250-AUTH=LOGIN 08:07 20:32 SMTP-(0000010E) 250 EXPN 08:07 20:32 SMTP-(0000010E) >MAIL FROM:<> 08:07 20:32 SMTP-(0000010E) 501 bogus mail from 08:07 20:32 SMTP-(0000010E) ERR undeliverable 501 bogus mail from 08:07 20:32 SMTP-(0000010E) SMTP_DELIV_FAILED 08:07 20:32 SMTP-(0000010E) >QUIT 08:07 20:32 SMTP-(0000010E) 221 Goodbye Ed Chabot The Marlin Firearms Company 100 Kenna Drive North Haven, CT 06473 (203)985-3254 Please visit http://www.ipswitch.com/support/mailing-lists.html to be removed from this list. An Archive of this list is available at: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
