<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="http://syndication.webwiz.co.uk/rss_namespace/">
 <channel>
  <title>Spam Filter ISP Forums : spambot attack &amp; max incomming reached</title>
  <link>https://www.logsat.com/spamfilter/forums/</link>
  <description><![CDATA[This is an XML content feed of; Spam Filter ISP Forums : Spam Filter ISP Support : spambot attack &amp; max incomming reached]]></description>
  <pubDate>Mon, 10 Aug 2026 03:58:38 +0000</pubDate>
  <lastBuildDate>Fri, 15 Oct 2010 16:31:11 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 11.04</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://www.logsat.com/spamfilter/forums/RSS_post_feed.asp?TID=6881</WebWizForums:feedURL>
  <image>
   <title><![CDATA[Spam Filter ISP Forums]]></title>
   <url>https://www.logsat.com/spamfilter/forums/forum_images/web_wiz_forums.png</url>
   <link>https://www.logsat.com/spamfilter/forums/</link>
  </image>
  <item>
   <title><![CDATA[spambot attack &amp; max incomming reached : If the zipped logfile is smaller...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6881&amp;PID=13833&amp;title=spambot-attack-max-incomming-reached#13833</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 6881<br /><strong>Posted:</strong> 15 October 2010 at 4:31pm<br /><br />If the zipped logfile is smaller than 8MB, you can simply email it to us at support at logsat dot com. If not, I'll be sending you a PM shortly with our FTP info to upload the file. Please also let us know the to/from email addresses that are getting the NDR (a copy of the NDR would also help). If you happen to know the IP of the remote server, that will help to of course.]]>
   </description>
   <pubDate>Fri, 15 Oct 2010 16:31:11 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6881&amp;PID=13833&amp;title=spambot-attack-max-incomming-reached#13833</guid>
  </item> 
  <item>
   <title><![CDATA[spambot attack &amp; max incomming reached : I have been monitoring a bit more...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6881&amp;PID=13832&amp;title=spambot-attack-max-incomming-reached#13832</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=1311">Pierre</a><br /><strong>Subject:</strong> 6881<br /><strong>Posted:</strong> 15 October 2010 at 11:48am<br /><br /><P>I have been monitoring a bit more and I can see that the spambot attacks are more frequently and also last longer. So I assume that legitimate mail does not get an NDR on the first connection attempt, but later one, when it gives up. But strange that they never fail over to one of the other&nbsp;MX servers. Those are not busy at all at that time.</P><DIV>It would be great if you could take a look at f.e. yesterdays log file. How do I send it over?</DIV><span style="font-size:10px"><br /><br />Edited by Pierre - 15 October 2010 at 11:49am</span>]]>
   </description>
   <pubDate>Fri, 15 Oct 2010 11:48:57 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6881&amp;PID=13832&amp;title=spambot-attack-max-incomming-reached#13832</guid>
  </item> 
  <item>
   <title><![CDATA[spambot attack &amp; max incomming reached : Pierre,That is odd (the NDR)....]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6881&amp;PID=13828&amp;title=spambot-attack-max-incomming-reached#13828</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 6881<br /><strong>Posted:</strong> 14 October 2010 at 7:49pm<br /><br />Pierre,<div><br></div><div>That is odd (the NDR). When the max connection limit is reached, SpamFilter abruptly terminates the connection, sending a "421 Too many connections on the server" error first. This should cause the remote SMTP server to retry sending the email for a reasonable number of times, absolutely not to send back an NDR to the sender right away. If they send an NDR without retrying at least a few times (the RFC 5321 does not specify a minimum threshold), they're violating RFC. Furthermore, in the retry, they should be attempting to connect to your secondary MX records if present.</div><div>If you have a specific sender for which you experience this behavior, you may want to let them know of the problem. If there's multiple such cases with multiple senders, are you certain that they are indeed not trying to connect to the secondaries (or retrying to send the email thru SpamFilter at a later time)? We'd be happy to examine SpamFilter's activity logfile for you if you'd like to look for abnormalities.</div>]]>
   </description>
   <pubDate>Thu, 14 Oct 2010 19:49:27 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6881&amp;PID=13828&amp;title=spambot-attack-max-incomming-reached#13828</guid>
  </item> 
  <item>
   <title><![CDATA[spambot attack &amp; max incomming reached : We have 3 relay servers we use...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6881&amp;PID=13827&amp;title=spambot-attack-max-incomming-reached#13827</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=1311">Pierre</a><br /><strong>Subject:</strong> 6881<br /><strong>Posted:</strong> 14 October 2010 at 10:31am<br /><br /><P style="MARGIN: 0cm 0cm 0pt" ="Ms&#111;normal"><SPAN lang=EN-US style="mso-ansi-: EN-US"><FONT size=3><FONT face="Times New Roman">We have 3 relay servers we use for incomming and outgoing mail.<?: prefix = o ns = "urn:schemas-microsoft-com:office:office" /><O:P></O:P></FONT></FONT></SPAN></P><P style="MARGIN: 0cm 0cm 0pt" ="Ms&#111;normal"><SPAN lang=EN-US style="mso-ansi-: EN-US"><FONT size=3><FONT face="Times New Roman">From time to time one of them is under attack by spambots and then the max number of concurrent incomming smtp connections (currently set at 50) is reached. <O:P></O:P></FONT></FONT></SPAN></P><P style="MARGIN: 0cm 0cm 0pt" ="Ms&#111;normal"><SPAN lang=EN-US style="mso-ansi-: EN-US"><FONT size=3><FONT face="Times New Roman">What then happens is that new connection attempts are accepted, but dropped immediately and therefore that legitimate new connection attempts get a "smtp connection error" NDR.<O:P></O:P></FONT></FONT></SPAN></P><P style="MARGIN: 0cm 0cm 0pt" ="Ms&#111;normal"><SPAN lang=EN-US style="mso-ansi-: EN-US"><FONT size=3><FONT face="Times New Roman">I would think that ones the max concurrend incoming connections are reached, logsat would refuse any new connection and that legitimate connection attempts would then fail over to a secondary relay server based on the mx config.<O:P></O:P></FONT></FONT></SPAN></P><P style="MARGIN: 0cm 0cm 0pt" ="Ms&#111;normal"><SPAN lang=EN-US style="mso-ansi-: EN-US"><FONT size=3><FONT face="Times New Roman">Is there a way to configure logsat to stop handling incoming request once the max is reached or is there another way to solve this issue?<O:P></O:P></FONT></FONT></SPAN></P><span style="font-size:10px"><br /><br />Edited by Pierre - 15 October 2010 at 11:42am</span>]]>
   </description>
   <pubDate>Thu, 14 Oct 2010 10:31:59 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6881&amp;PID=13827&amp;title=spambot-attack-max-incomming-reached#13827</guid>
  </item> 
 </channel>
</rss>