DNSBL List relay.Osirusoft.com suddenly lists entire internet

From: Vaughan, Thomas (Thomas.Vaughan_at_ROSWELLPARK.ORG)
Date: 08/28/03

  • Next message: Memet Anwar: "hfnetFU is gone, now it is MbsaFU"
    Date:         Thu, 28 Aug 2003 09:54:53 -0400


      I am not sure this belongs here but it was an issue for us. In using Symantec's Mail Security for SPAM and AV scanning we implemented the DNSBL function. Worked great until the evening 8/26. Turns out that all of our Exchange server thought everyone was spam site including each other. Turns out that the list manager was under DDoS instead of just shutting down he turned the list against the all IP addresses. This demonstrates that even those you trust can shut down your services in ways you would least expect it.


    Reply from SPAMCOP when I asked them what they knew about the situation.
    Hi Thomas,

    Because of ongoing problems with DDoS against Osirusoft, as well as many
    other anti-spam sites including SpamCop, Spamhaus and monkeys.com, Joe had
    to pull the plug as he just didn't have the time or resources to battle
    back. Unfortunately he did something really stupid, in that he listed the
    entire Internet along with a text message of "Stop using Osirusoft.com".

    This means that anyone still using Osirusoft is bouncing/tagging/devnulling
    all mail coming into their systems. Why Joe chose this route no one is
    really sure, but it has lead to a lot of pissed of people and a lot of

    Follow his advice, stop using Osirusoft.

    SpamCop Deputy

    Whatever Happened to Octopus?

    LEGATO RepliStor, formerly known as Octopus, delivers breakthrough
    replication performance that's 5X faster than the competition in an
    independent head-to-head test. Learn how RepliStor uses patented,
    asynchronous, real-time replication, to deliver disaster recovery, data
    distribution and consolidated backups. It is the first replication solution
    to achieve Windows 2003 certification. Get the performance report now.



  • Next message: Memet Anwar: "hfnetFU is gone, now it is MbsaFU"