Re: Mail DoS from Bellsouth

From: /dev/null (dev'0x2e'null@BeginThread.com)
Date: 08/22/02


From: "/dev/null" <dev'0x2e'null@BeginThread.com>
Date: Thu, 22 Aug 2002 16:55:04 GMT

I know you've said you've tried contacting them in many different forms,
just to check, have you tried the two contact addresses and phone numbers in
their whois: (?)

<whois>
Registrant:
Bell South Intellectual Property Corporation (BELLSOUTH-DOM)
   824 Market Street Suite 510
   Wilmington
   DE,19801
   US

   Domain Name: BELLSOUTH.NET

   Administrative Contact:
      Admin, Domain (AD11661-OR) hostmaster@BELLSOUTH.NET
      Bellsouth.net
      1100 Ashwood Parkway
      Atlanta, GA 30338
      USA
      (770) 522-4000
      Fax- (770) 522-6050
   Technical Contact:
      Hostmaster (HOS260-ORG) hostmaster@BELLSOUTH.NET
      BellSouth.net
      28 Perimeter Center East BLDG 30
      Atlanta, GA 30346
      US
      (770) 522-6300
      Fax- - (770) 522-4002

   Record expires on 07-Mar-2010.
   Record created on 06-Mar-1995.
   Database last updated on 22-Aug-2002 12:38:58 EDT.
</whois>

I have a question for you. If you decide to "go to the authorities" because
of Bellsouth's lack of response, who would you call? (I'd like to know in
case I need to call them some day).

I know when you're in the middle of the battle it's hard to keep your cool
and be stratigic, so I offer this viewpoint to help. Ultimately I see two
routes to take if you can't get any response.

1. Open up to Bellsouth and let them "get this off their chest". If you
route the email to internal servers your servers may generate "No such user"
emails back to Bellsouth, intensifying the war. So it may be good to set up
a dummy MTA (as suggested by others) to just suck in this junk and dump it.

2. Continue to block them and wait it out. Eventually enough retry
failures will cause Bellsouth's servers to dump the email as undeliverable
to you. Which may generated messages back to their postmaster and they can
be made (painfully) aware of the problem. Imagine showing up for work on
Friday and having several thousand rejection notices in your postmaster
box...

Of course if this is an on-going problem, i.e. whoever spoofed your domain
as the "from" address on these bogus emails continues to generate these
emails, eventually you'll have to get hold of someone who can make it stop.
I'd say a written letter from an attorney seeking damages would be a good
show-stopper to send them.

Another thought, they may already be aware of the problem and have blocked
any in-bound emails from your domain and are just waiting for this junk to
clear out of their mail system, so if you send them email they may not even
be getting it...

/dev/null



Relevant Pages

  • Re: Reading Exchange 2003 SMTP Logs / Expected emails dont always arrive
    ... and it has nothing to do with Exchange itself (have spent a week on Exchange ... The issue appears to be as a result of an advanced option on our servers NIC ... As soon as I disabled the option, the emails from ... attachments, but I have checked the 'Message Delivery Option' defaults ...
    (microsoft.public.exchange.connectivity)
  • Re: Reading Exchange 2003 SMTP Logs / Expected emails dont always arrive
    ... directly to it bypassing the ISPs relay servers? ... I would say that the vast majority of emails get to us. ... aware of issues with emails which have no attachments (I have sent myself ... Do any other senders from other companies report any issues sending email ...
    (microsoft.public.exchange.connectivity)
  • Re: There needs to be an international policy
    ... knocking it out circulation in the internet; futher more you wait for these ... >>number of emails going out from a certain IP, domain or host over a period ... >>If these countries had their IP addresses banned on the Internet then 90% ... >>concerted effort to shut down their spamming servers, say after 2 years, ...
    (microsoft.public.security)
  • Re: [Full-disclosure] Brute force attack - need your advice
    ... have a lot of unusual brute force attack on the servers recently. ... guessing that it could be because of my emails to the list? ... and whatever flies through your network is just random noise. ...
    (Full-Disclosure)
  • Re: Evolution throwing away emails for one of my accounts ?
    ... directly and checked and there are over a dozen emails sitting in the ... account that haven't shown up in Evolution. ... that can get messy if servers do something unpredictable. ... Clients not downloading what it thinks are ...
    (Fedora)

Quantcast