Man, they'll try anything to hack your system...

Ben Scott dragonhawk at gmail.com
Fri Jan 27 13:14:00 EST 2006


  In the vein of "Strange things seen on the Internet", I'm noticing a
few domains have MXes pointing to hosts with addresses in RFC-1918
private IP address space.  I noticed this because our mail server was
trying to send DSN bounce messages to the domains, and so was trying
to connect to some hosts with bogon IP addresses.  Our firewall caught
it and dropped it, and since it was from our server, it was
highlighted in a log report.

  Anyone else seen this?  Is it just net.stupidity on the part of some
mail server operators somewhere, or are spammers/attackers trying
something new?

-- Ben



More information about the gnhlug-discuss mailing list