How do I stop this???

Gerry Doris gdoris at ROGERS.COM
Sat Mar 27 20:46:42 GMT 2004


On Sat, 27 Mar 2004, Ugo Bellavance wrote:

> >-----Message d'origine-----
> >De : Gerry Doris [mailto:gdoris at ROGERS.COM]
> >Envoyé : 27 mars, 2004 13:37
> >À : MAILSCANNER at JISCMAIL.AC.UK
> >Objet : Re: How do I stop this???
> >
> >
> >On Sat, 27 Mar 2004, Stephen Swaney wrote:
> >
> >> Gerry,
> >>
> >> What was the entry you put in your access maps.
> >>
> >> Did you  remake the access.db after changing the access map?
> >>
> >> Steve
> >
> >I've ended up putting all of the following lines in /etc/mail/access
> >
> >spinfinder.com                  DISCARD
> >64.227.180.130                  DISCARD
> >dayzersagency?@spinfinder.com   DISCARD
> >
> >and then running
> >
> >makemap hash access < access
> 
> Are you sure your db is named access?  mine is called accessdb

Yes, my access database file is called access.db.  That's what it is 
called in sendmail.mc and it works for the other addresses that I've put 
in it.

I'm curious as to the best way to stop such a problem.  I believe what I'm
experiencing is the result of a misconfig and I've sent a message to the
postmaster of the domain.  However, how would you prevent a DoS attack if
someone tried to fire off as many messages as possible from multiple
systems using non-printable characters in the sending address.  It seems
like there isn't a way to avoid sendmail trying to process the email and
generating error messages.

Gerry




More information about the MailScanner mailing list