PHWinfo banniere

Titres
PORTAIL ANNUAIRE ARTICLES COMPARATEUR HÉBERGEURS DEVIS FORUMS RÉDUCTEUR D'URL
Précédent   PHWinfo > Forums Hébergement > Forum Logiciels d'hébergement > comp.mail.sendmail > dnsbl rejections hanging on cmd read
S'inscrire FAQ Membres Recherche Messages du jour Marquer les forums comme lus
comp.mail.sendmail Configuring and using the BSD sendmail agent.

dnsbl rejections hanging on cmd read

Réponse
 
LinkBack Outils de la discussion
Vieux 06/09/2007, 05h39   #1
Bill
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut dnsbl rejections hanging on cmd read

I have a sendmail server handling inbound/outbound e-mail for several
hundred mailboxes. It's been running with several dns blacklists for a
couple of years. Aside from occasional issues with the dns lists being
unavailable, it's worked quite well.

Over the past few weeks, I've noticed a rapidly increasing number of
connections such as this lingering around on the system:

sendmail: server [122.252.205.69] cmd read


maillog entries for this IP show that it is repeatedly trying and being
rejected by a dns blacklist. Curious as to why I hadn't seen much of
this before, I sniffed the TCP traffic and found that the remote host is
simply running MAIL-FROM/RCPT-TO repeatedly, despite the rejection
messages. When this is multiplied over dozens of hosts connected, it
results in lots of extra sendmail processes consuming resources.


Any suggestions about how to alleviate this? One option I thought of is
to disconnect immediately upon dnsbl rejection, but that is probably
counter-productive as the remote host would most likely just connect
again. Nonetheless, how could I accomplish that using standard
sendmail.cf entries for dnsbls?

Other thoughts? Most appear to be zombie hosts, so it's unlikely that
any firewall implementations would much.


Thanks,

-Bill
  Réponse avec citation
Vieux 06/09/2007, 18h21   #2
Thomas Schulz
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: dnsbl rejections hanging on cmd read

In article <13dv14carm027b1@corp.supernews.com>, Bill <bill@pitz.net> wrote:
>I have a sendmail server handling inbound/outbound e-mail for several
>hundred mailboxes. It's been running with several dns blacklists for a
>couple of years. Aside from occasional issues with the dns lists being
>unavailable, it's worked quite well.
>
>Over the past few weeks, I've noticed a rapidly increasing number of
>connections such as this lingering around on the system:
>
>sendmail: server [122.252.205.69] cmd read
>
>
>maillog entries for this IP show that it is repeatedly trying and being
>rejected by a dns blacklist. Curious as to why I hadn't seen much of
>this before, I sniffed the TCP traffic and found that the remote host is
>simply running MAIL-FROM/RCPT-TO repeatedly, despite the rejection
>messages. When this is multiplied over dozens of hosts connected, it
>results in lots of extra sendmail processes consuming resources.
>
>
>Any suggestions about how to alleviate this? One option I thought of is
>to disconnect immediately upon dnsbl rejection, but that is probably
>counter-productive as the remote host would most likely just connect
>again. Nonetheless, how could I accomplish that using standard
>sendmail.cf entries for dnsbls?
>
>Other thoughts? Most appear to be zombie hosts, so it's unlikely that
>any firewall implementations would much.
>
>
>Thanks,
>
>-Bill


There was a patch posted to this newsgroup last February that implemented
a BadRcptShutdown option. This kills the connection after too many bad
RCPT-TO commands are issued. Check the archives of this group and see if
you can find it. If not, I could post it again.
--
Tom Schulz
schulz@adi.com
  Réponse avec citation
Vieux 09/09/2007, 19h22   #3
Bill
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: dnsbl rejections hanging on cmd read

Thomas Schulz wrote:
> There was a patch posted to this newsgroup last February that implemented
> a BadRcptShutdown option. This kills the connection after too many bad
> RCPT-TO commands are issued. Check the archives of this group and see if
> you can find it. If not, I could post it again.


Thanks - I found it, and applied it. Seems to be working well.


Regards,

-Bill
  Réponse avec citation
Réponse


Outils de la discussion

Règles de messages
Vous ne pouvez pas créer de nouvelles discussions
Vous ne pouvez pas envoyer des réponses
Vous ne pouvez pas envoyer des pièces jointes
Vous ne pouvez pas modifier vos messages

Les balises BB sont activées : oui
Les smileys sont activés : oui
La balise [IMG] est activée : oui
Le code HTML peut être employé : non
Trackbacks are oui
Pingbacks are oui
Refbacks are oui


Fuseau horaire GMT +1. Il est actuellement 02h13.


Édité par : vBulletin® version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 RC5 Tous droits réservés.
Version française #16 par l'association vBulletin francophone
PHWinfo est un site Éducation Sans Frontières ©2000-2008
Ad Management by RedTyger
©Tous droits réservés par les parties respectives
Page generated in 0,09886 seconds with 11 queries