CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 937
Comments: 25
block bottom
spacer spacer

SMTP DDoS

 
Post new topic   Reply to topic       All -> FavForums -> DDoS [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
leblancp

Cadet
Cadet


Joined: May 08, 2008
Posts: 1
Location: France

PostPosted: Thu May 08, 2008 10:42 am    Post subject: SMTP DDoS
Reply with quote

I hope I'm posting in the proper forum, as I never seen of that sort of attack before.

Starting about two weeks ago, I have been receiving around 15000 emails per day all sent to non existing addresses.

My usual level of spam is around 1000 per day domainwide.
What makes me think of an attack is that all these messages are send to a small list of 15/20 unique email addresses coming from an average 200/300 distinct IP addresses.

These email addresses do not resemble existing or discarded addresses. They do not resemble variations on existing or discarded addresses. The email addresses look like random letters, nothing like a dictionary attack. So I do not think it's 'regular' spam as it has no chance of being delivered.

The IP addresses are geographically scattered all over the internet.

I do not know the contents of the message as they are rejected by my smtp server.

My current thinking is that they
1) try to swamp my server by getting them to send a ton of bounce messages or
2) try to use my server for a backscatter attack.

I'm not sure what to do:
Firewall/blacklisting does not seem appropriate as the IP addresses change everyday.
The number of email per IP seems too low to trigger a reasonable IDS rule.

Anyone seen something like that before ?

Pierre.

Back to top
View users profile Send private message
trobbins

SIRT Handler
Premium Member

Joined: Feb 19, 2007
Posts: 1166
Location: USA
Premium

PostPosted: Mon May 12, 2008 9:26 pm    Post subject:
Reply with quote

If the domain of the recipient address is not one of yours, they may be trying to relay through your server. (possibly an attempt to get you black listed?)

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2668

Premium

PostPosted: Mon May 12, 2008 10:13 pm    Post subject:
Reply with quote

Are your servers bouncing these messages? If they are being sent to nonexistent addresses, you should be discarding them rather than bouncing them to a forged return address.

If they are being sent to a small number of non-existent addresses, you could create a user with one of those addresses long enough to collect some samples and see what is going on, then delete that address again.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> DDoS All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer