![]() |
|
|||||||
| Network / Server Status Please check often for network / Server updates here! |
![]() |
|
|
Thread Tools | Display Modes |
|
#16
|
|||||||||||
|
|||||||||||
|
Status report? Is there anyone available to post a quick reply as to where we are at with the issue? My clients have been without e-mail for an entire day and my frustration level with not having an acceptable answer for them is growing.
|
|
#17
|
|||||||||||
|
|||||||||||
|
About the attack
Today's problems with mail7 were due to a DDoS attack against the mail services (actually only port 25) on that machine.
Being that the attack is generating valid TCP connections, and sending valid (in TCP terms) data it is *very* hard to mitigate. Being that its not a standard synflood, the syn proxy methods had little avail. I am seeing over 2000 uniq IP connections per second. I estimate the machines in this botnet to be well over 40K, since my state table stays between 30K-40K all the time. Trust we are doing everything possible to get through this attack. |
|
#18
|
|||||||||||
|
|||||||||||
|
No doubt there and thanks for the update, is this going to be resolved by the morning?
|
|
#19
|
|||||||||||
|
|||||||||||
|
Finally someone responds... That's all we ask.
Thank you Aaron. |
|
#20
|
|||||||||||
|
|||||||||||
|
Thanks Aaron! Good luck.
|
|
#21
|
||||||||||||
|
||||||||||||
|
The attack seems to have dropped off. If anyone has problems sending AND receiving, please submit a ticket containing the public IP for the problematic computer.
|
|
#22
|
|||||||||||
|
|||||||||||
|
FYI: accourding to tech support mail7 and mail8 is having the same issue again
|
|
#23
|
|||||||||||
|
|||||||||||
|
Hey Folks,
Get into the habit of using port 2525 for outgoing SMTP to our servers. We have reached the point that larger ISP's reach with incomming SMTP. (Meaning a majority of incomming traffic from non UNIX hosts is spam, virii, etc). Its very simple for me to filter out traffic using passive OS fingerprinting. This was the major breakthrough last night in the attack. So use port 2525 from now on at least on Mail7. Now you if happen to run *BSD, Linux, Solaris, etc you will not have a problem on port 25 ![]() |
|
#24
|
|||||||||||
|
|||||||||||
|
So... Just to be clear...
Aaron, so the only thing we should do on our end right now to help out is to start switching any OUTGOING smtp connections of us or our clients to 2525, instead of 25, correct?
Three questions: 1) Only for mail7, or for any vortech mail servers? 2) No changes to incoming at all? 3) Will this change affect any of the php/asp mail scripts on web sites we have on your boxes, or are they fine? Thank you very much for attention to this matter. It was a doozy, but I know its been your #1 priority to remedy, and I very much appreciate that. -Dustin |
|
#25
|
|||||||||||
|
|||||||||||
|
Just for 7 for now.
No changed for incomming. Scripts go though another mail server all together, no they will not be affected. |
|
#26
|
|||||||||||
|
|||||||||||
|
Here's a long shot.... is there any way in H-Sphere to see which clients are using Mail7? Or do I have to open up each account to see what mail server they are on?
Thanks, Dustin |
|
#27
|
|||||||||||
|
|||||||||||
|
Use a site like dnsreport.com to look at the MX record. Or use dig, nslookup, etc on a UNIX like OS.
|
|
#28
|
|||||||||||
|
|||||||||||
|
sorry, I meant was there a report in H-sphere that would list all of the client accounts by their mail server, thereby allowing me to not have to look at each individual domain in hsphere, dnslookup, etc.
With 60-70 sites to look and see if they're on mail7, it gets tedious. (of course, I'm doing now what I should have done a long time ago, and making a full database of that info on my end) -Dustin |
|
#29
|
|||||||||||
|
|||||||||||
|
You can click the account ID, then click mail info from the CP.
|
|
#30
|
|||||||||||
|
|||||||||||
|
Are we down again?
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| 1.30.06 - Mail7 | aaron | Network / Server Status | 11 | 02-01-2006 12:31 AM |
| Mail7 2PM 10/07/2005 | dvanburen | Network / Server Status | 3 | 10-07-2005 02:40 PM |
| spamGuard Mail - Mail7 and unix - unix14 | admin | News and Announcements | 45 | 03-23-2005 12:50 PM |
| New Mail Server mail7.hsphere.cc | admin | News and Announcements | 6 | 12-30-2004 11:52 PM |