Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

HELP! DOS on SMTP Virtual Server Sessions/Connection Attempts

Status
Not open for further replies.
Feb 7, 2005
58
US
We are getting tons of coennections from obvious spam and i am not relaying. How can i prevent this. I have all the filters on IMF etc.. I have been adding some of the ip that show up more in the logs to the connection filter to dent them, but still getting these. I tried limiting the connections and the time-out, but thought that would hurt good mail, as the spam would not allow the good mail connections. Also all connections are bogus usernames, i.e. "l6xsdsg".

2011-03-13 00:00:01 190.4.214.231 l6xsdsg SMTPSVC1 MYMAILSERVER 10.10.10.10 0 HELO - +l6xsdsg 250 0 50 12 2391 SMTP - - - -
2011-03-13 00:00:01 190.4.214.231 l6xsdsg SMTPSVC1 MYMAILSERVER 10.10.10.10 0 MAIL - +FROM:+<marvaforbesfj@woodrivers.co.nz> 250 0 55 43 0 SMTP - - - -
2011-03-13 00:00:03 190.4.214.231 l6xsdsg SMTPSVC1 MYMAILSERVER 10.10.10.10 0 RCPT - +TO:+<user1@mydomain.com> 0 0 55 38 266 SMTP - - - -
2011-03-13 00:00:04 190.4.214.231 l6xsdsg SMTPSVC1 MYMAILSERVER 10.10.10.10 0 QUIT - l6xsdsg 240 6984 55 38 1531 SMTP - - - -
2011-03-13 00:00:04 95.37.219.36 d75ted3 SMTPSVC1 MYMAILSERVER 10.10.10.10 0 HELO - +d75ted3 250 0 49 12 2313 SMTP - - - -
2011-03-13 00:00:05 95.37.219.36 d75ted3 SMTPSVC1 MYMAILSERVER 10.10.10.10 0 MAIL - +FROM:+<mmcCulloughek@foto1.com.ec> 250 0 51 39 0 SMTP - - - -
2011-03-13 00:00:05 95.37.219.36 d75ted3 SMTPSVC1 MYMAILSERVER 10.10.10.10 0 RCPT - +TO:+<user3@mydomain.com> 0 0 54 36 156 SMTP - - - -
2011-03-13 00:00:05 79.149.29.157 3rm8bt3 SMTPSVC1 MYMAILSERVER 10.10.10.10 0 HELO - +3rm8bt3 250 0 50 12 2328 SMTP - - - -
2011-03-13 00:00:05 95.37.219.36 d75ted3 SMTPSVC1 MYMAILSERVER 10.10.10.10 0 QUIT - d75ted3 240 6375 54 36 563 SMTP - - - -
2011-03-13 00:00:07 81.181.16.62 01k0mi0 SMTPSVC1 MYMAILSERVER 10.10.10.10 0 HELO - +01k0mi0 250 0 49 12 2391 SMTP - - - -
2011-03-13 00:00:07 79.149.29.157 3rm8bt3 SMTPSVC1 MYMAILSERVER 10.10.10.10 0 MAIL - +FROM:+<tboswell_ov@unic-skien.no> 250 0 50 38 0 SMTP - - - -
2011-03-13 00:00:07 81.181.16.62 01k0mi0 SMTPSVC1 MYMAILSERVER 10.10.10.10 0 MAIL - +FROM:+<whitneylockhart_ji@chibanet.or.jp> 250 0 58 46 0 SMTP - - - -
2011-03-13 00:00:07 190.84.254.91 ik14f72 SMTPSVC1 MYMAILSERVER 10.10.10.10 0 HELO - +ik14f72 250 0 50 12 2328 SMTP - - - -
2011-03-13 00:00:07 186.114.94.34 - SMTPSVC1 MYMAILSERVER 10.10.10.10 0 QUIT - - 240 20453 179 4 20453 SMTP - - - -
2011-03-13 00:00:07 190.84.254.91 ik14f72 SMTPSVC1 MYMAILSERVER 10.10.10.10 0 MAIL - +FROM:+<p_dillon_md@zzdats.lv> 250 0 46 34 0 SMTP - - - -
2011-03-13 00:00:07 173.213.35.244 lb1.ledgedelivery.info SMTPSVC1 MYMAILSERVER 10.10.10.10 0 HELO - +lb1.ledgedelivery.info 250 0 51 27 234 SMTP - - - -
2011-03-13 00:00:07 81.181.16.62 01k0mi0 SMTPSVC1 MYMAILSERVER 10.10.10.10 0 RCPT - +TO:+<user2@mydomain.com> 0 0 54 36 172 SMTP - - - -
2011-03-13 00:00:07 173.213.35.244 lb1.ledgedelivery.info SMTPSVC1 MYMAILSERVER 10.10.10.10 0 MAIL - +FROM:<intelligibleness11@ledgedelivery.info> 250 0 62 49 15 SMTP - - - -
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top