Webfoundry
Verified User
It seems many servers suffer problems for exim2 attacks by multiple ip's from the same machine-name "ylmf-pc".
Normally originating from DUL/Dynamic addressing ranges, this is a high impact attack, which simply connects to a mail server, issues a HELO/EHLO of ylmf-pc, and then exits the connections.
While not actually generating any email or spam, it can consume mail processes, or even be a DOS if enough connections come in.
Interestingly, it is not exclusive to DUL networks, we also see it originating from certain hosting/co-location facilities.
Blocking IP's is not really the sollution, as they might vary from day to day.
Does anyone know an sollution that will block these, based on machine-name, rather than IP ?
Normally originating from DUL/Dynamic addressing ranges, this is a high impact attack, which simply connects to a mail server, issues a HELO/EHLO of ylmf-pc, and then exits the connections.
While not actually generating any email or spam, it can consume mail processes, or even be a DOS if enough connections come in.
Interestingly, it is not exclusive to DUL networks, we also see it originating from certain hosting/co-location facilities.
Blocking IP's is not really the sollution, as they might vary from day to day.
Does anyone know an sollution that will block these, based on machine-name, rather than IP ?