OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: smart anti flood tools
From: Bennett Todd (betrahul.net)
Date: Wed Feb 02 2000 - 08:22:53 CST


2000-02-02-08:15:51 KS:
> Didn't somebody show his pop before smtp solution that was
> watching the logs and maintain the db? Maybe it could be
> modified? Was that on this list?

Don't know which one you were thinking of, there have been many.

I've got a short and simple pop-before-smtp, that works with
unmodified uw-pop3d/imapd and postfix. Mine is written in a very
little bit of perl, using a handful of modules from CPAN to do all
the hard work.

I'll be glad to send you a copy.

However, there's a tricky bit to doing the proposed modification;
that's coming up with the algorithm. I had to ponder a bit when
writing my daemon, and chat with a friend, before I got the data
structures right to simply handle the "grace period" cleaning.
Coming up with a simple, correct, and efficient data structure for
identifying email floods as you're watching a logfile will be the
bulk of the work.

In fact, if you can tell me what data structure and algorithm you
think will work, I'll be happy to modify my daemon to implement it
for you.

-Bennett


  • application/pgp-signature attachment: stored