SOBER-I

Ugo Bellavance ugob at CAMO-ROUTE.COM
Tue Nov 23 19:49:37 GMT 2004


    [ The following text is in the "ISO-8859-1" character set. ]
    [ Your display is set for the "US-ASCII" character set.  ]
    [ Some characters may be displayed incorrectly. ]

Alan Cragg - Lists wrote:
> Hello All,
>
> First time poster many time reader.
>
> Since Friday I am getting flooded with e-mails infected with Sober-I
> virus. They all seem to be from one source and they are relaying through
> our secondary Mail Server (Our ISP supplies the secondary).
>
> It seems the one user can bring our server to its knees and the inbound
> queue just backs up.
> As a remedy I have to reject e-mails from the secondary server using the
> access file in sendmail.
>
> Does anyone know of a better way to block this without having to block
> our secondary mail server?
> Is it a performance tuning issue? We are using MailScanner 4.35.11 and
> Sophos AV, not SAVI, and SA 3.0.1.
>
> The machine is running Redhat 8.0 and is a XEON 2.4GHz CPU with 1GB RAM.
> Connection is only a T1.
>
> Thanks for any assistance,

You'd be better off removing your secondary MX from the DNS records,
since you may loose mail this way and you are using your ISP's for
nothing.  Maybe your ISP could do something about it.

For your real problem, I don't really have an idea, sorry :(.

------------------------ MailScanner list ------------------------
To unsubscribe, email jiscmail at jiscmail.ac.uk with the words:
'leave mailscanner' in the body of the email.
Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and
the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html).

Support MailScanner development - buy the book off the website!




More information about the MailScanner mailing list