rejecting botnets with sendmail
Res
res at ausics.net
Wed Nov 1 22:30:27 GMT 2006
On Wed, 1 Nov 2006, Denis Beauchemin wrote:
> DAve a écrit :
>> Denis Beauchemin wrote:
>>> Andoni Auzmendi a écrit :
>>>> Experiencing the recent increase in spam from botnets, is there a way to
>>>> reject (or discard) connections coming from servers containing their ip
>>>> address within the hostname? I can see lots of connections from
>>>> broadband or dialup addresses. Some of them even bypass greylilst as
>>>> they resend the messages several times. We use Sendmail here and I guess
>>>> there must be a milter which is capable of doing that.
>>>>
>>>> Andoni Auzmendi
>>>>
>>> Andoni,
>>>
>>> This saved us:
>>> FEATURE(`dnsbl',`safe.dnsbl.sorbs.net',`"554 Rejected " $&{client_addr} "
>>> found in safe.dnsbl.sorbs.net"')dnl
>>
>> What list is this? I don't see it on the sorbs.net website.
>
> Dave,
>
> It's an aggregate of:
its equivelant to just using "dnsbl.sorbs.net"
>
--
Cheers
Res
"Just a world that we all must share, it's not enough just to stand and
stare, is it only a dream that there'll be no more turning away" - Floyd
More information about the MailScanner
mailing list