Weekly spam summary on September 2nd, 2006September 2, 2006
Our SMTP frontend survived all this week without problems, which was something of an accomplishment this week. Because this week, we:
Yes, that is not a typo; this week we had a lot of SMTP connections, although none of the other numbers are up much compared to last week. It's not a continuation of the spam storm from last Saturday either, as the per-day numbers show:
Kernel level packet filtering top ten: Host/Mask Packets Bytes 213.4.149.12 10704 557K 216.64.54.146 4490 216K 61.128.0.0/10 3609 190K 218.0.0.0/11 2976 145K 204.13.82.45 2405 144K 212.216.176.0/24 2367 119K 219.128.0.0/12 2330 116K 217.224.0.0/13 2226 107K 66.112.87.66 2215 106K 212.175.13.129 2114 127K The overall volume is down from last week, with only one entry really sticking out.
Connection time rejection stats:
38665 total
18228 dynamic IP
15060 bad or no reverse DNS
2176 class bl-cbl
1381 class bl-sbl
547 class bl-dsbl
280 class bl-njabl
251 class bl-sdul
159 class bl-spews
84 class bl-ordb
Oddly, despite the huge connection volume there is no real growth in these stats compared to last week. I don't have any explanation for this. Six of the top 30 most rejected IP addresses were rejected 100 times
or more, with the leader being 200.216.54.234 (197 times, rejected for
having no reverse DNS). 15 of the top 30 are currently in the CBL,
six are currently in Somewhat to my surprise only one of those two is our non-friends at Cutting Edge Media (this week reporting in from 208.32.133.155). The other is 213.154.92.143, which is part of SBL21128, which is a /23 listing that is (to quote the listing) '419 scam sources in Senegal'. For extra displeasure, this listing was created November 14th, 2004. Hotmail's stats this week are an improvement over last week:
And the final numbers:
There were four people who sent 100 or more bad The most popular bad username to send stuff to continues to be
' Written on 02 September 2006.
|
These are my WanderingThoughts GettingAround This is part of CSpace, and is written by ChrisSiebenmann. * * * Atom feeds are available; see the bottom of most pages. Categories: links, linux, programming, python, snark, solaris, spam, sysadmin, tech, unix, web |