|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
From: JD Bronson (jbronson
sixcompanies.com)
Date: Tue Jan 01 2008 - 16:22:53 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
I am looking for any advice on how to mitigate an attack.
I appear to be under attack from IPs all over the world attempting
to send email to one of my domains with all invalid usernames:
For example:
1 Laa
sixcompanies.com (<>)
1 Leitnerkkiwh
sixcompanies.com (<>)
1 lemerand
sixcompanies.com (<>)
1 Linas
sixcompanies.com (<>)
1 Littleflower
sixcompanies.com (<>)
1 Lounekmmhvp
sixcompanies.com (<>)
1 isabelle.lundquist
sixcompanies.com (<>)
1 merloptlq
sixcompanies.com (<>)
1 Mikhail-Rowen
sixcompanies.com (<>)
1 Miu_Connolly
sixcompanies.com (<>)
1 Natorywa
sixcompanies.com (<>)
(tons and tons of these)
..I run 'pf' and configured it to track IPs and connection attempts
and its working very well (starts to blackhole abusive IPs) but
postfix still can run out of max processes and refuse legit requests.
Other than using pf and the connection controls within postfix, is
there anything else I could/should be doing or just ride this out?
it has been all day so far...
-JD
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]