spamming through the firewall

This is a discussion on spamming through the firewall within the alt.comp.mail.postfix forums, part of the Mail Servers and Related category; Hello, since some time my postfix notices following spam: Jan 30 09:40:08 orion postfix/smtpd[24622]: connect from ...


Go Back   Usenet Forums > Mail Servers and Related > alt.comp.mail.postfix

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 01-30-2006
Zbigniew Lisiecki
 
Posts: n/a
Default spamming through the firewall

Hello,
since some time my postfix notices following spam:

Jan 30 09:40:08 orion postfix/smtpd[24622]: connect from
63-253-146-115.ip.mcleodusa.net[63.253.146.115]
Jan 30 09:40:08 orion postfix/smtpd[24622]: NOQUEUE: reject: RCPT from
63-253-146-115.ip.mcleodusa.net[63.253.146.115]: 450
<gw1.office.wwdl.net.>: Helo command rejected: Host not found;
from=<51600@newsletter.wwdl.net> to=<my address> proto=ESMTP
helo=<gw1.office.wwdl.net.>
....
Jan 30 09:45:08 orion postfix/smtpd[24622]: timeout after RSET from
63-253-146-115.ip.mcleodusa.net[63.253.146.115]
Jan 30 09:45:08 orion postfix/smtpd[24622]: disconnect from
63-253-146-115.ip.mcleodusa.net[63.253.146.115]

the amount forced me to add the iptables rule seen with -L option:

DROP all -- anywhere 63.252.0.0/14

but the spam still appears !
can the spammer change it's IP ?
the mail is rejected, but the spammer seams to occupy the connection.
is it possible, that he enters with another IP and than later on
his target IP 63.253.146.115 won't pass through the firewall, which
causes the timeout ?

what can be done in such case ?

regards, zbyszek
--
http://zbyszek.evot.org
Reply With Quote
  #2 (permalink)  
Old 01-30-2006
Zbigniew Lisiecki
 
Posts: n/a
Default Solution: spamming through the firewall

>
> DROP all -- anywhere 63.252.0.0/14
>

I had an error in the firewall,
iptables rule order war wrong

z
--
http://zbyszek.evot.org
Reply With Quote
  #3 (permalink)  
Old 01-30-2006
Greg Hackney
 
Posts: n/a
Default Re: spamming through the firewall

Zbigniew Lisiecki wrote:

> reject: RCPT from 63-253-146-115.ip.mcleodusa.net[63.253.146.115]:
> 450 <gw1.office.wwdl.net.>: Helo command rejected: Host not found;
> the mail is rejected, but the spammer seams to occupy the connection



It's not actually "rejecting" the email. It's sending them a 450 "try again later" code.


Try sending them a 554 rejection code, then maybe there wouldn't be so many
connections (retries) from them.

--
Greg
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 01:13 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0