OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
mailbombing (2)

From: Frank Bonnet (f.bonnetesiee.fr)
Date: Thu Apr 03 2008 - 05:50:59 CDT


Hello

I wrote an email about mailbombing few days ago
it still continues and now I have few error messages
like the following , the address is the one which is
mailbombed, I have substitued xxx to the real login

Out: 220 mail.esiee.fr ESMTP
  In: EHLO mx1.pair.com
  Out: 250-mail.esiee.fr
  Out: 250-PIPELINING
  Out: 250-SIZE 10240000
  Out: 250-ETRN
  Out: 250-ENHANCEDSTATUSCODES
  Out: 250-8BITMIME
  Out: 250 DSN
  In: MAIL FROM:<> SIZE=4818
  Out: 250 2.1.0 Ok
  In: RCPT TO:<xxxesiee.fr>
  Out: 250 2.1.5 Ok
  In: DATA
  Out: 354 End data with <CR><LF>.<CR><LF>
  Out: 451 4.3.0 Error: queue file write error
  In: QUIT
  Out: 221 2.0.0 Bye

I have now an access file that return "5.1.1 user unknown"
as quoted by Wiese hoping this will lighten a bit my server.

Note : the sending server is never the same, the attack is distributed
so filtering is an utopy.

Thanks for any idea.