Hi all smart Domino gurus!
Today I have seen a new way to try to find users/email addresses through smtp. Well it is new for me.
This morning someone started to bombard a clients domino server with smtp connections with random email addresses. Every time it is around 50 different addresses, all within 1 second, before they disconnect and rest for about 5 minutes. Then they come back with 50 new addresses within a second but this time from a completely different smtp server. And so it have been all day.
I have seen this behaviour before but then it is usually a couple of emails and most of the time from the same server so that it is possible to block in different ways.
The server is properly configured, at least from what I can see, so this isn't really a problem, except that the log get stuffed, but I wonder if there is a way to stop connecting servers from doing this?
It should be possible as we (I mean the server) can see that one connecting server try to deliver a lot of mails to recipients that obviously don't exist on the server so it would be possible to catch this event and mitigate it somehow.
OK, I am in deep water now since I don't have enough knowledge to really be able to say that IS possible but the information is there. Maybe a setting on the server where you define how many addresses is allowed before the server drop the session. In my dreams that is.
How do you handle this? Do you even bother because of more urgent things or have you come up with a smart solution?
The environment is Domino 14 FP3 running on CentOS Stream 9. And yes I have set up Fail2Ban but that doesn't help in this case since I only can catch the IP when the server connects and disconnects and next time it is from a completely different server/ip.
Thanks
/Jonas
Sweden