Building an open relay trap

I just began building an open relay trap. At the moment the configuration exists of a Debian machine running postfix. The following configuration changes have been made to make it look like it relays while it actually doesn't:


  • mynetworks = 0.0.0.0/0 (obviously to make it accept everything)
  • relayhost = 127.0.0.1 (to make it relay to it self)
  • inet_interfaces = $external_ip (only the external ip so that localhost will give connection refused, the external ip is hidden to make the spamtrap work)


That's a quite easy setup for an open relay trap. Anybody that has improvements may provide them :) 15:05: Our first victim has entered the spam trap! It's ip adres is 211.229.108.122 which looks terribly Korean. Abuse sent! Let's wait for our next target :)

21:42: Hello Amanda Nini, You are our second contestant in the find your open relay! 219.80.161.115 is your IP, and scanning for open relays it sure is! Ofcourse you are now on our RBL!

Actually I'm turning this openrelay trap into a blacklist collecting machine. The information I gather from this box will be used for the dnsbl.unnet.nl blacklist. Remember: The blacklist can and will be also used to block hosts that we do not want on our mailservers! So use this blacklist on your own risk! The entries are still manually added but next week (when I'm back from Low Lands I'll be updating it to do so automatically).
aha, cliff turning to blacklists ?

Melvin - 19 August '04 - 12:54


Name:  
Remember personal info?

Email:
URL:
Comment:Emoticons / Textile

  ( Register your username / Log in )

Notify: Yes, send me email when someone replies.  

Small print: All html tags except <b> and <i> will be removed from your comment. You can make links by just typing the url or mail-address.