[25860] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: ARIN whois

daemon@ATHENA.MIT.EDU (Forrest W. Christian)
Mon Nov 22 00:26:12 1999

Date: Sun, 21 Nov 1999 22:16:39 -0700 (MST)
From: "Forrest W. Christian" <forrestc@iMach.com>
To: Kai Schlichting <kai@pac-rim.net>
Cc: nanog@merit.edu
In-Reply-To: <4.2.1.19991121230855.00cef8d0@mail.speedus.net>
Message-ID: <Pine.BSF.3.96.991121221114.20965A-100000@workhorse.iMach.com>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Errors-To: owner-nanog-outgoing@merit.edu


On Sun, 21 Nov 1999, Kai Schlichting wrote:

> THEY WILL FIND YOUR RELAYS ON THEIR OWN, AND THEY WILL ABUSE THEM, NO
> MATTER HOW LOUD YOU SCREAM.

In transition to a new mail server (with a new address), I installed a
plug-gateway on the old server to redirect mail.

Unfortunately, plugd hides the ip address of the sender, and since I trust
my netblocks, all of the ip addresses on the old server became "spam relay
entry points".

It took the spammers 96 hours to find 3 of the addresses on that box and
for us to be listed in orbs.  I figured I would have at least had a week
or two to figure out a better way.

I ended up staying up all night getting transparent proxying to work right
on the new server and making it work with a cisco route-map.

- Forrest W. Christian (forrestc@imach.com) KD7EHZ
----------------------------------------------------------------------
iMach, Ltd., P.O. Box 5749, Helena, MT 59604      http://www.imach.com
Solutions for your high-tech problems.                  (406)-442-6648
----------------------------------------------------------------------



home help back first fref pref prev next nref lref last post