Go Back   Defender Hosting Forums > PowerVPS Virtual Private Servers > Linux VPS - Security and Tuning

Linux VPS - Security and Tuning Security and Tuning Discussion for Linux Virtual Private Servers based on Virtuozzo by SWsoft

Reply
 
Thread Tools Display Modes

  #1  
Old 07-03-2005, 09:55 AM
mikelbeck
Guest
 
Posts: n/a
Default Block E-Mail Sender

There's a guy who's been sending me hundreds of e-mails - it looks like he's infected with W32.Mytob.H@mm. I don't know who this person is, all I have is the IP address the e-mails are coming from.

What's the best way to block these e-mails automatically? With APF? With exim?
Reply With Quote

  #2  
Old 07-03-2005, 12:28 PM
Fred Fred is offline
Senior Member
 
Join Date: Jun 2005
Posts: 601
Fred is on a distinguished road
Default

I'm not sure what is better to use between a ban in exim or a ban in apf.

A ban in exim means he will still connect to your server everytime he wants to send the mail, but exim will block it... That means exim will have to work to block it and use ressource...

I do recommend ( but i'm not a pro ) to use apf...
i think using the deny_hosts.rules file for your apf config is the best. Just add the IP at the end of the file...
Don't forget to restart apf...
Reply With Quote

  #3  
Old 07-03-2005, 12:57 PM
mikelbeck
Guest
 
Posts: n/a
Default

Quote:
Originally Posted by Fred
I'm not sure what is better to use between a ban in exim or a ban in apf.

A ban in exim means he will still connect to your server everytime he wants to send the mail, but exim will block it... That means exim will have to work to block it and use ressource...

I do recommend ( but i'm not a pro ) to use apf...
i think using the deny_hosts.rules file for your apf config is the best. Just add the IP at the end of the file...
Don't forget to restart apf...
I blocked it using apf. Thanks for the info.
Reply With Quote

  #4  
Old 10-18-2007, 09:22 AM
shadowcat shadowcat is offline
Senior Member
 
Join Date: Jul 2005
Posts: 315
shadowcat is on a distinguished road
Default Re: Block E-Mail Sender

Can anyone point me in the right direction to do this please?

Many thanks.
Reply With Quote

  #5  
Old 10-18-2007, 09:52 AM
Robert's Avatar
Robert Robert is offline
Staff
 
Join Date: Mar 2005
Posts: 974
Robert has much to be proud ofRobert has much to be proud ofRobert has much to be proud ofRobert has much to be proud ofRobert has much to be proud ofRobert has much to be proud ofRobert has much to be proud ofRobert has much to be proud of
Default Re: Block E-Mail Sender

You can edit the /etc/apf/deny_hosts.rules file via SSH to include the IP you want to block.

Make sure to list only one IP per line. Anything that has a "#" at the start of it is a comment and is there only for documentation purposes for you. So while it can be helpful to add a line to describe why the IP is there, it's not required.
__________________
Rob Yates
Senior Systems Administrator
PowerVPS / Defender Hosting
Defender Technologies Group, LLC.
Reply With Quote

  #6  
Old 10-20-2007, 01:35 PM
shadowcat shadowcat is offline
Senior Member
 
Join Date: Jul 2005
Posts: 315
shadowcat is on a distinguished road
Default Re: Block E-Mail Sender

Thanks very much indeed Robert.

Best regards.
Reply With Quote

  #7  
Old 10-27-2007, 09:53 AM
mbrando mbrando is offline
Senior Member
 
Join Date: Jun 2005
Posts: 111
mbrando is on a distinguished road
Default Re: Block E-Mail Sender

Hi,

Instead of editing the /etc/apf/deny_hosts.rules file and restarting APF. You should do this:

/etc/apf/apf -d xxx.xxx.xxx.xxx {comment}

in a terminal window. Example:

/etc/apf/apf -d 123.456.789.123 {ADMIN: email flood}

This will deny all connection to the listed IP and put a comment in the rules file so you know why it is in there. If you are using BFD to auto block offending hosts you should clear this file monthly or quarterly.

Mike
__________________
Mike Brandonisio
http://www.jikometrix.net
------------------------------
Web Hosting
Database Applications
e-Commerce
------------------------------
JIKOmetrix - Reliable web hosting
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Outlook Express/Mail Clients not sending/receiving mail on CPanel systems DavidP Linux VPS - cPanel 1 05-22-2006 12:57 AM
exim: Always set the Sender: header... ? CyClone Linux VPS - cPanel 4 01-22-2006 05:36 AM
IP Block on DirectAdmin? cparodi The Lounge 3 12-10-2005 02:10 PM
Run my own mail server software in addition to Plesk stooley Pre-Sales Questions 1 11-28-2005 12:52 PM
Mail delivery and Keeping the APF host deny rules clean mbrando Linux VPS - General 0 10-04-2005 10:26 PM



All times are GMT -4. The time now is 04:25 AM.


vBulletin skin developed by: eXtremepixels
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright Defender Technologies Group, LLC 2006