OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Blocking mail from upstream IP address

From: /dev/rob0 (rob0gmx.co.uk)
Date: Thu Jul 28 2005 - 23:09:56 CDT


jd wrote:
> A Road Runner user has been bombarding our mail server with a directory
> style attack. The messages originate from 70.60.206.234 and are being
> sent by one of Road Runner's mail servers (24.25.9.103).
>
> What would be the best strategy to block messages server-wide originating
> from 70.60.206.234?

IMO:
smtpd_client_restrictions = reject_rbl_client sbl-xbl.spamhaus.org

See:
http://rbls.org/?q=70.60.206.234
http://www.postfix.org/docs.html
http://jimsun.linxnet.com/misc/postfix-anti-UCE.txt
http://www.postfix.org/SMTPD_ACCESS_README.html
--
     mail to this address is discarded unless "/dev/rob0"
     or "not-spam" is in Subject: header