[Full-Disclosure] Block notification / bounce mails (as in DDOS)

Koen koen4security at hotmail.com
Thu Apr 1 16:04:34 BST 2004


Luke Norman wrote:
>>
>> What do you all suggest to this 'seemingly' DDOS-attack (allthough not 
>> intended as a DOS)?
>>
> Set up a server-side bayesian filter to block all e-mails containing 
> certain words (such as 'address not found' or similar). I'd be very 
> suprised if there isn't a filter like this already available if you 
> google it. Have a look at the 'fighting useless notification mails' 
> thread from a few days ago, which is a related topic

This would be an option if the mailserver is still capable of handling all or 
some of the mail. As the question was raised, this is not the case. The 
'theoratical' situation is that my mailserver is as dead as a doornail (not 
really crashed but out of oxygen..network-bandwidth).

Thanks anyway for the response (and yes, the thread on fighting.... is indeed 
very helpful for the case where I have some 'spare' bandwidth)

Koen






Full-Disclosure is hosted and sponsored by Secunia.