Dave’s spam attack

From Scripting News, Dave’s followup to a post about suddenly getting 1000’s of copies of the same message:

“Postscript: I hadn’t opened any of the emails, I just did, and saw that he’s marching through all four-letter combinations of email addresses at one of the domains I own. I turned off email forwarding, hopefully that should cause all the emails to bounce. Post-postcript: It did.)”

I watched something similar happen on our Postini setup. At first I let Postini process all email addressed to our domain. We got anywhere from 15-18 thousand messages per week. I changed it to drop (not bounce, just drop) all email not addressed to an actual, existing account or alias, and that dropped down to 2-3 thousand per week. The rest had been addressed to accounts that haven’t existed for years, or were hitting random name combinations in hopes of finding an actual account. Insane.

Similar Posts

  • Live, partially

    I just went public with part of the intranet site. I pointed people to the webcalendar subdirectory and gave an explanation of the conference room calendar and how to use it to book a conference room. We’ll see what sort of feedback I get. (I’ll be keeping an eye on access.log to see who actually…

  • More snow

    Woke up to more snow today, and yet another slippery drive into downtown. I did make it safely though! Even got here early. 🙂 Now pardon me while I get off to Monday morning staff meeting and then I’ll be in the wiring closet looking at that switch problem. Maybe that won’t be so bad…

  • SP2

    I bit the bullet and installed SP2 over lunch today, since I had to work through my lunch hour anyway. (Long story) Everything went well, and nothing really came across as “broken” in any major way. I had to re-enable the Messenger Service, since I do use “net send” across our internal network quite often….

  • It’s baaaack

    Remember back over a month ago when we were having telephone issues, and after going through our equipment vendor and the telephone company for days, back and forth, they finally declared it fixed at about 8PM on a Friday night? (After calling me at midnight the night before to tell me that they think they…

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Find out more about Webmentions.)