Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


aw

aw

286 posts

Ultimate Geek


#15636 1-Sep-2007 08:09
Send private message

Hi all,

I've got a wee problem here.

A primary school I work for has become a victim of a bit of a DoS attack, where a spammer somewhere is sending massive amounts of spam with seemingly all of them having something_random@this_school.school.nz as the FROM address.
(replace this_school with the domain name of the primary school affected)

As a result the mailserver is getting bombarded with bounce messages - about one every 3-5 seconds. It started at 4:50pm last night and is still going as I type, it hasn't let off at all.

They're on a rather expensive wireless connection so I've been able to deflect the attack to my own server at home by shutting down the school's mail server for now - mine's their backup MX.

I've put a few lines in my script that processes messages for spaminess and viruses to dump the message without wasting CPU if it happens to have an empty sender addy in the envelope (as per a bounce message) and has the school's domain name anywhere in the message.

I've also just now set up a hard SPF record - "v=spf1 ip4:school's.public.IP.address -all", and am hoping this'll slow down this flood in case the spammer is still at it.

Does anyone have any further ideas as to what I can do stem this flood of bounce messages? Or do I just have to ride the storm now? Occasionally in there *is* a legitimate message.

Any ideas appreciated! I'd like to get on top of this before Xnet kill my account - lotsa incoming connections from lotsa different hosts, it does look dodgy!

Thanks everyone,

Andrew

PS: PM me if you want specifics like the school's domain which I've omitted here - I'd be interested if anyone's noticed much spam purporting to be from our domain.

PPS: Looking at the messages themselves (contained in the bounces), they appear to be coming from a botnet. They're definitely not coming from the school itself.

Create new topic
freitasm
BDFL - Memuneh
79295 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

#84763 1-Sep-2007 09:12
Send private message

Not much more you can do, seeing that the senders of these NDR are completely out of your control.,,




Please support Geekzone by subscribing, or using one of our referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSync 




LennonNZ
2459 posts

Uber Geek

ID Verified
Trusted

  #84766 1-Sep-2007 09:24
Send private message

there are a few methods you can use if you are running an open source mail server such as exim/sendmail/whatever

you can use BATV for example which will not accept any bounces which didn't come from your mail server

Thanks


freitasm
BDFL - Memuneh
79295 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

#84768 1-Sep-2007 09:28
Send private message

But that's pretty much it - the e-mails will still arrive on the server anyway and be processed - only delivery will not happen. So the connection is still used and bandwidth consumed...




Please support Geekzone by subscribing, or using one of our referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSync 




numfarr
329 posts

Ultimate Geek


  #84769 1-Sep-2007 09:34
Send private message

 Move their mail to Google Apps maybe? I don't know if the Education Edition is available to non-US schools but the standard free one will do for email. You can still pick up mail using POP3 clients. While the current problem you have will pass eventually this sort of problem, and the volume of spam in general, is only going to worse.

LennonNZ
2459 posts

Uber Geek

ID Verified
Trusted

  #84770 1-Sep-2007 09:57
Send private message

numfarr: Move their mail to Google Apps maybe? I don't know if the Education Edition is available to non-US schools but the standard free one will do for email. You can still pick up mail using POP3 clients. While the current problem you have will pass eventually this sort of problem, and the volume of spam in general, is only going to worse.



It will reject at the rcpt to. For example below and you won't get 99% of the data and reduce the amount of data getting in. Also the SPF record will help only a little bit.

220 welcome
helo hotnet.com
250 welcome
mail from:<>
250 OK
rcpt to:<realuser@yourschool.school.nz>
550 Message rejected.




aw

aw

286 posts

Ultimate Geek


  #84781 1-Sep-2007 11:16
Send private message

This domain handles about 40 mailboxes. I don't think moving it to Gmail right now will be worth it, by the time it's all set up this may be over anyway.

So far the script mods I made have eliminated 99% of the load overhead that goes with fully scanning a message every three seconds, and I'm watching my Xnet cap and the data level isn't so bad - as I type, since midnight it's dropped roughly 4,550 bounces of about 4,700 messages total (of which only about 30 or so are legit), data cap since midnight is only 40MB. I'm thankful it's not PDF or GIF spam!

I'm gonna google to see if it's possible to make qmail reject senders at the envelope as per your example Lennon - thanks for the idea.

This stuff really makes you angry tho! Anyone else had something like this?


Thanks everyone for your input btw  :)



barf
643 posts

Ultimate Geek


  #84786 1-Sep-2007 12:23

hi aw, same thing happened to a customer of mine, in this case the attack seemed to happen after the spammer detected a catch-all email domain. disabling the catch-all caused the non-deliverable messages to be rejected because they were addressed to non-existant mailboxes, unfortunately some were faked from real mailboxes and there wasn't much I could do about that.

I highly reccomend greylisting (I use it with postfix), this has solved spam problems (<5 per month per mailbox) for many of my customers, is free and reduces the load on spam checking software.




Sniffing the glue holding the Internet together

 
 
 

Move to New Zealand's best fibre broadband service (affiliate link). Free setup code: R587125ERQ6VE. Note that to use Quic Broadband you must be comfortable with configuring your own router.
exportgoldman
1202 posts

Uber Geek

Trusted

#84803 1-Sep-2007 16:13
Send private message


We had this same thing happen to one of our clients, they were using Exchange server, so we turned off the option to recieve the whole message before bouncing it back if it was a non-existant user. You usually have this switched on to stop address list harvesting.

Not too much more you can do apart from bagging it at your server, and doing processing then sending to the school.

We were doing a few GB a day in messages when the attack happened to our client. Fun




Tyler - Parnell Geek - iPhone 3G - Lenovo X301 - Kaseya - Great Western Steak House, these are some of my favourite things.

LennonNZ
2459 posts

Uber Geek

ID Verified
Trusted

  #84804 1-Sep-2007 16:23
Send private message



I'm gonna google to see if it's possible to make qmail reject senders at the envelope as per your example Lennon - thanks for the idea.




BATV involves alot more really.. (Don't reject all <> as it is really bad)

What it involves is encoding the MFROM when sending from your mails server so if you get a bounce back it will bounce back to the encoded MFROM (so the bounce actually is from something you sent). If you didn't send the message the message will bounce back to the normal email address and then you know it didn't come from you.

Better you look it up on google what its about as there are some good examples around for a number of MTA's.

This is only 1 example of spam protection.

there are many other ways of reducing spam.. For example the Orcon mail servers (which I look after) there are at least 30 different tests done even before it gets to the anti spam checks.

Thanks
Craig


Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.