ietf-asrg
[Top] [All Lists]

Re: [Asrg] SMTP server connections that disconnect right away

2003-06-27 20:26:48
Yakov Shafranovich wrote:

At 11:17 AM 6/27/2003 -0400, Chris Lewis wrote:

Bill Thorson wrote:

ASRG Group,
I've been working on smtp server software and have
noticed something very strange.  We seem to have many
connections made, mostly at night, who connect to
port 25 and then disconnect right after the
220 Server Ready message.   I was believing that I
had a bug in my software but now I am wondering if
this is a bot of some type.   Do spammers run bots
to search for and create lists of mail servers to
attack?  Is this what I'm seeing?


The SMTP "channel" is unbelievably dirty.

On our spamtrap, we see machines making _thousands_ of transactions that consist of only:
        HELO somevalue
        QUIT


Have you considering the possibility that they are checking for RMX/rDNS compliance?

Thanks for all the great ideas.  It looks like I'm not alone with these
types of unusual connections.

What is RMX/rDNS?

Bill




_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg