RJM62
Touchdown! Greaser!
- Joined
- Jun 15, 2007
- Messages
- 13,157
- Location
- Upstate New York
- Display Name
Display name:
Geek on the Hill
...all from Taiwan, all bearing spoofed Yahoo addresses, and all aimed at my server. Why? I have no idea. I have no open relays or other vulnerabilities that I know of, nor can the hosting company find any.
Apparently, however, the attempts actually started before I took possession of the IP addresses last week, and have been increasing steadily. I hadn't noticed because the machine has plenty of resources and was running pretty well.
Today, however, it reached a crescendo; and the server was so busy sending bounce messages (using 105 percent of CPU capacity and almost 2 GB of RAM) that services started crashing on both the master and the slave servers.
I tweaked a few settings in Exim, blocked the IP range, and disabled bouncing, and things settled down. What an annoyance, though.
-Rich
Apparently, however, the attempts actually started before I took possession of the IP addresses last week, and have been increasing steadily. I hadn't noticed because the machine has plenty of resources and was running pretty well.
Today, however, it reached a crescendo; and the server was so busy sending bounce messages (using 105 percent of CPU capacity and almost 2 GB of RAM) that services started crashing on both the master and the slave servers.
I tweaked a few settings in Exim, blocked the IP range, and disabled bouncing, and things settled down. What an annoyance, though.
-Rich