At 11:17 AM 6/27/2003 -0400, Chris Lewis wrote:
Have you considering the possibility that they are checking for RMX/rDNS compliance?Bill Thorson wrote:The SMTP "channel" is unbelievably dirty.ASRG Group, I've been working on smtp server software and have noticed something very strange. We seem to have many connections made, mostly at night, who connect to port 25 and then disconnect right after the 220 Server Ready message. I was believing that I had a bug in my software but now I am wondering if this is a bot of some type. Do spammers run bots to search for and create lists of mail servers to attack? Is this what I'm seeing?
On our spamtrap, we see machines making _thousands_ of transactions that consist of only:
HELO somevalue
QUIT