rejecting botnets with sendmail

Res res at ausics.net
Wed Nov 1 22:30:27 GMT 2006


On Wed, 1 Nov 2006, Denis Beauchemin wrote:

> DAve a écrit :
>> Denis Beauchemin wrote:
>>> Andoni Auzmendi a écrit :
>>>> Experiencing the recent increase in spam from botnets, is there a way to
>>>> reject (or discard) connections coming from servers containing their ip
>>>> address within the hostname? I can see lots of connections from
>>>> broadband or dialup addresses. Some of them even bypass greylilst as
>>>> they resend the messages several times. We use Sendmail here and I guess
>>>> there must be a milter which is capable of doing that.
>>>> 
>>>> Andoni Auzmendi
>>>> 
>>> Andoni,
>>> 
>>> This saved us:
>>> FEATURE(`dnsbl',`safe.dnsbl.sorbs.net',`"554 Rejected " $&{client_addr} " 
>>> found in safe.dnsbl.sorbs.net"')dnl
>> 
>> What list is this? I don't see it on the sorbs.net website.
>
> Dave,
>
> It's an aggregate of:

its equivelant to just using  "dnsbl.sorbs.net"

>

-- 
Cheers
Res

"Just a world that we all must share, it's not enough just to stand and
stare, is it only a dream that there'll be no more turning away" - Floyd



More information about the MailScanner mailing list