store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Sun May 19, 2013 3:11 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 5 posts ] 
Author Message
 Post subject: An annoying spammer - can I block their IPs in ASL
Unread postPosted: Tue Aug 19, 2008 8:12 pm 
Offline
Forum Regular
Forum Regular

Joined: Thu Jan 17, 2008 5:48 pm
Posts: 124
I have been getting a number of "failure notices" in my mail queue and my amateur sleuthing via DNS report found this particular spammer has two NS servers as well as a bank of mail servers. My thought was to blacklist the NS IPs, however, that did not work. My next step is to blacklist their mail server IPs but there are a number of them so what would be nice is to just blacklist the entire block that corresponds to their mail server IPs (208.76.251.38 thru 208.76.251.50). I see that blocking a range of IPs was requested for ASL 2.0 but I could not find any reference so I just added 208.76.251 to my ASL blacklist hoping it will take care of the range.

So I guess my first question is am I thinking about this correctly? and secondly is their a better way?

Thanks much


Top
 Profile  
 
 Post subject:
Unread postPosted: Wed Aug 20, 2008 8:27 am 
Offline
Forum Regular
Forum Regular

Joined: Mon Apr 10, 2006 12:55 pm
Posts: 656
I would highly suggest you turn off email responses for bad email addresses. It's a lot of overhead for something that is typically 99% spam anyways. A clogged mail queue doesn't do you any good.


Top
 Profile  
 
 Post subject:
Unread postPosted: Wed Aug 20, 2008 8:58 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7418
Location: earth
Agreed, thats a great step. Also check out the zen.spamhaus.org RBL, and greylisting.


Top
 Profile  
 
 Post subject:
Unread postPosted: Wed Aug 20, 2008 11:53 am 
Offline
Forum Regular
Forum Regular

Joined: Thu Jan 17, 2008 5:48 pm
Posts: 124
Gents:

Thanks for the reply. However, I have read this forum extensively for similar issues and employed all of the recommendations (at least the simple ones) to prevent failure notices stuck in the queue. Of course I have set Plesk to reject all non-existent email. I am also using qmail-scanner and ART spamassassin. The IP addresses for this particular spammer are not listed in the spamhaus RBL.

One thing that I did notice in the email header is that the spam gets an SPF Pass which baffles me. I have checked my spf record several times and it seems ok, but maybe not.

Thanks again


Top
 Profile  
 
 Post subject:
Unread postPosted: Wed Aug 20, 2008 12:17 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7418
Location: earth
The spammers are smart enough to create SPF and DKIM records these days, so dont put to much effort into investigating that part.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 5 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group