[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [vps-mail] Email dictionary attacks - what would you do?



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Mon, 28 Feb 2005 12:01:29 -0700, Scott Wiersdorf <scottw@xxxxxxxxxxxx>
wrote:

> Putting addresses in the access list is probably a waste of your
> personal time; unless you notice an inordinate amount (>1000) of
> connections from any particular host, I wouldn't bother with it.

Is there any hope of the kernel hackers at Verio patching the TCP/IP stack
so that individual jails on a physical machine can add firewall rules in
order to block access to their port 25 from chosen IP ranges?

Blocking access from known dialup/dsl/cable zones would decrease bandwidth
use, server load and admin stress while blocking no legitimate mail.

This is on my home linux machine serving 2 main domains with 2 users:

root@mail:/var/log# grep FIREWALLED notice | grep "^Feb 28" | wc
   1706   40939  340396

And there are still 4 hours to go...

Oh, and while writing the past line:

root@mail:/var/log# grep FIREWALLED notice | grep "^Feb 28" | wc
   1720   41275  343196

- -- 
G. Stewart - gstewart@xxxxxxxxxxx

There are three types of people in this world:
 - Those who can count
 - Those who can't
                    -- Walter Dnes in NANAE, 2003-JUL-26.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (FreeBSD)

iD8DBQFCI21/K5oiGLo9AcYRAh/AAJ0cZuxBtpScJeXoxYqSegsn3DZ3oQCgj5sV
za0o0nhEBI/OY0CxhDDp2FQ=
=id4Y
-----END PGP SIGNATURE-----

======================================================================
This is <vps-mail@xxxxxxxxxxxx>       <http://www.perlcode.org/lists/>
Before posting a question, please search the archives (see above URL).


Main Index | Thread Index
Match: Format: Sort by:
Search: