On Mon, 2010-06-07 at 17:29 -0700, Brian Dunning wrote: > I'm currently geotargeting all the IPs in the log, and focusing on the hits > from Russia (the majority of these apache@ spams seem to be Russian). I've > got a much shorter list of scripts to look at now. Hopefully I'll find some > that just use mail() with no scrubbing.
I wouldn't bother wasting your time on that to be honest, as spam could just as easily come from zombie machines, which could be scattered all over the globe. This sort of distributed attacking seems to be more and more commonplace these days. Thanks, Ash http://www.ashleysheridan.co.uk