<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>Xblog: Mail DDOS</title>
    <link>http://xblog.xman.org/articles/2008/03/25/mail-ddos</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description>hey, if it has a capital X in it, it has to be great!</description>
    <item>
      <title>Mail DDOS</title>
      <description>&lt;p&gt;It appears as though I am experiencing an e-mail based DDOS. As near as I can tell, thousands if not millions of messages addressed to jslopez@xman.org are bouncing around the Internets as I write this. I have no idea &lt;em&gt;why&lt;/em&gt; this e-mail address was selected (AFAIK, this address has never been a valid address). Furthermore, the DATA segment of the e-mails appears to be empty. Greylist rejects seem to cause many of the &lt;strikeout&gt;bots&lt;/strikeout&gt;MTA&amp;#8217;s to immediately attempt another delivery.&lt;/p&gt;

&lt;p&gt;The net effect of all this was to completely tie up my mail server and for the most part prevent any mail delivery. I&amp;#8217;ve now tweaked the server a bit so I do eventually get mail, but it is still rather grim. So far, I&amp;#8217;m killing connections to clients after two errors, I&amp;#8217;ve trimmed my accept queue depth, and dramatically increased the number of simultaneous connections I will process. The overall effect has been pretty taxing on my mail server, and I still see significant delays in delivery times, so I&amp;#8217;m all ears to any brilliant suggestions on how to address this problem.&lt;/p&gt;

&lt;p&gt;If you are a mail admin and are wondering why your queues are backed up with tons of jslopez@xman.org e-mail, please, please kill it. I suspect thought that most of my mail is coming from bots, so I&amp;#8217;ll probably need to start adding immediate filtering at connect time that drops suspected bots.&lt;/p&gt;

&lt;p&gt;Is this happening to anyone else?&lt;/p&gt;</description>
      <pubDate>Tue, 25 Mar 2008 03:25:00 -0700</pubDate>
      <guid isPermaLink="false">urn:uuid:2398720c-7e71-4af2-9a3e-44e1eedae9cd</guid>
      <author>Christopher Smith</author>
      <link>http://xblog.xman.org/articles/2008/03/25/mail-ddos</link>
      <category>Security</category>
      <category>spam</category>
      <category>jslopez</category>
      <category>xman.org</category>
      <category>ddos</category>
      <category>smtp</category>
      <category>mail</category>
    </item>
  </channel>
</rss>
