SOBER-I

Alan Cragg - Lists acragg-lists at CTF.COM
Tue Nov 23 19:12:05 GMT 2004


Hello All,

First time poster many time reader.

Since Friday I am getting flooded with e-mails infected with Sober-I
virus. They all seem to be from one source and they are relaying through
our secondary Mail Server (Our ISP supplies the secondary).

It seems the one user can bring our server to its knees and the inbound
queue just backs up.
As a remedy I have to reject e-mails from the secondary server using the
access file in sendmail.

Does anyone know of a better way to block this without having to block
our secondary mail server?
Is it a performance tuning issue? We are using MailScanner 4.35.11 and
Sophos AV, not SAVI, and SA 3.0.1.

The machine is running Redhat 8.0 and is a XEON 2.4GHz CPU with 1GB RAM.
Connection is only a T1.

Thanks for any assistance,

Alan Cragg


CONFIDENTIALITY NOTICE. 
The information contained in this communication is confidential and/or 
proprietary business or technical data. If you are not the intended 
recipient, you are hereby notified that any use, dissemination, copying 
or distribution of this communication is strictly prohibited. If you  
have received this communication in error, please immediately notify us by 
telephone (604) 472-2300, or electronically by return message, and 
delete or destroy all copies.

------------------------ MailScanner list ------------------------
To unsubscribe, email jiscmail at jiscmail.ac.uk with the words:
'leave mailscanner' in the body of the email.
Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and
the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html).

Support MailScanner development - buy the book off the website!




More information about the MailScanner mailing list