[Mimedefang] Rejecting Mails for More Than 3 Unknown Users

imacat imacat at mail.imacat.idv.tw
Wed Mar 28 05:15:21 EST 2007


On Tue, 27 Mar 2007 14:35:50 +0100
"Paul Murphy" <Paul.Murphy at argentadiscovery.com> wrote:
> I do it all in MIMEDefang because I want to record the sender and IP
> address into a database with all of my other status information so I
> can report on the prevalence of this sort of attack, and also because
> I want to be able to take action based on persistent dictionary
> attacks, such as firewalling the sending IP address for some time...

    This sounds interesting, but terrible.  We are already suffering
from high server load for garbage (we wound rather like to suffer from
high server load for real business or friend mails.)  Now we are talking
about running a database server for them! :p  My boss will kill me.

    I suppose mail log analysis is quite enough for me.  I can know how
many mails are delivered per day, how many attempts are made per day,
whether some anti-spam approach works, which domain and hosts are
spamming, the most spammed user ranking, by grepping the mail log files,
or by read and parse it with a perl script.  I cannot think of any other
use for that.

    Unless we are in anti-spam business, of course.

-- 
imacat ^_*'
imacat at mail.imacat.idv.tw
PGP Key: http://www.imacat.idv.tw/me/pgpkey.txt

Tavern IMACAT's http://www.imacat.idv.tw/
Woman's Voice http://www.wov.idv.tw/
TLUG List Manager http://www.linux.org.tw/mailman/listinfo/tlug
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 187 bytes
Desc: not available
Url : http://lists.roaringpenguin.com/pipermail/mimedefang/attachments/20070328/b04b57c3/attachment.bin


More information about the MIMEDefang mailing list