non terminating smtp connects / denial of service - any comments?

Kai Gallasch <[email protected]> Mon, 18 Jul 2005 12:54:20 +0200
Newsgroups gmane.mail.spam.dsbl.general
Message-ID <[email protected]>
Hi.

In the last week I have a problems with my mailservers (qmail). The  
problem is, that I see a lot of smtp connects that glue all available  
qmail-smtpd instances because they do not terminate on their own. For  
example one mailhost has a preset to handle up to 20 parallel smtp- 
connects of incoming smtp-sessions. In qmail the default timeout for  
such dead smtp-sessions is about 20 minutes so when I look further I  
see around 80% of all qmail-smtpd instances glued up by this smtp- 
sessions waiting for their timeout!

All in all this has the effect that the monitoring mechanism of my  
mailservers shows a lot "smtp unavailable" - damn!

What has this got to do with dsbl? Well - All this problematic smtp  
sessions seem to originate from badly written smtp engines of  
spambots, zombies, malware..

I temporarily found a workaround to decrease the smtp-timeout down to  
4-8 minutes *and* activating DUL/Dynamic-Netranges RBLs - too bad  
this had to be, but I don't know how to solve the problem by other  
means.. Of course I could increase the number of qmail-smtpd  
instances waiting for incoming deliveries - but this could in peak  
times bring down the servers completely due to resource exhaustion..

Any ideas? Is this some kind of new malware running amok?

Of course one could write a script that automatically firewalls  
source IPs from smtp-sessions that timeout - but really.. ?!


-K.


-

  I think now is a good time to remind people that the war on  
terrorism could not have prevented this.
You cannot bring about peace with war.

  -- "Six Bomb Blasts Around Central London"
    http://politics.slashdot.org/comments.pl?sid=155111&cid=13001795


----------------------------------------------
This message was sent to the opt-in DSBL list.
If you do not want to receive DSBL messages,
please send mail to [email protected].