jonn
Verified User
the server is getting hammered all day for weeks by multiple ip's with the noticeable 192.168.2.33 ip along side each.
Probably been seen before, though here is the example of one anyway.
I'm wondering is it okay to use exim to block sender_helo_name 192.168.2.33 to identify as a bad bot and reject. Or is that a bad idea.
I assuming I would add the ip to /etc/virtual/bad_sender_hosts_ip
Cheers beers.
Probably been seen before, though here is the example of one anyway.
Code:
1356232501000978.188.150.50anna1exim12012-12-23 04:14:37 login authenticator failed for ([192.168.2.33]) [78.188.150.50]: 535 Incorrect authentication data (set_id=anna)
I assuming I would add the ip to /etc/virtual/bad_sender_hosts_ip
Cheers beers.