Spam Filter ISP Support Forum

  New Posts New Posts RSS Feed - Like to collect all "IP Limbo/Blacklist c
  FAQ FAQ  Forum Search   Register Register  Login Login

Like to collect all "IP Limbo/Blacklist c

 Post Reply Post Reply
Author
samsung View Drop Down
Newbie
Newbie


Joined: 26 October 2006
Status: Offline
Points: 3
Post Options Post Options   Thanks (0) Thanks(0)   Quote samsung Quote  Post ReplyReply Direct Link To This Post Topic: Like to collect all "IP Limbo/Blacklist c
    Posted: 09 November 2006 at 5:56pm

Hi there,

Yes - i like to collect in real time all Limbo IPs "IP cache Blacklist" into a text file as spamfilter is running. Anyone doing this?  if it is not simple, then is there a way to do it offline from logs?

my second question:  how can i filter IPs based on keywords that RDNS of IP reports? I mean, how can i RegEX any IP number of sender server which has a PTR string with *.dhcp.* or *.dynamic.* and so on... 

lastly,  I get a lot of IPs in limbo cache, but they very very seldom ever go over 3 strike. So figure spammer is smarter. Can i safely lower the block IP threshold in limo list?  is anyone using two or one??

Any help is much appreciated. Many Thanks

S.

Back to Top
LogSat View Drop Down
Admin Group
Admin Group
Avatar

Joined: 25 January 2005
Location: United States
Status: Offline
Points: 4104
Post Options Post Options   Thanks (0) Thanks(0)   Quote LogSat Quote  Post ReplyReply Direct Link To This Post Posted: 14 November 2006 at 12:27am
samsung,

The IP cache blacklist is stored in memory only, and can't be retrieved. You can however, as you probably already know, display its content in the "Statistics" tab in SpamFilter.

Unfortunately even the 2nd question will have a negative answer. SpamFilter does not perform any filtering on the RDNS of an IP.

We'd recommend againsta lowering the cahce limit, as the risk in blocking legitimate emails would be too high.
Roberto Franceschetti

LogSat Software

Spam Filter ISP
Back to Top
dcook View Drop Down
Senior Member
Senior Member
Avatar

Joined: 31 January 2005
Location: United States
Status: Offline
Points: 174
Post Options Post Options   Thanks (0) Thanks(0)   Quote dcook Quote  Post ReplyReply Direct Link To This Post Posted: 14 November 2006 at 4:18pm

Let me throw an idea into the frey ... we have done quite a bit of experimenting with the IP Cache values.  We struck upon:

IPCacheLimboCountTrigger=6
;
IPCacheLimboTimeTrigger=1
;
IPCacheBlacklistDuration=30

This has worked well at protecting the Spamfilter with the periodic email phishing attacks we get.  The low time trigger makes it quick to respond to abuse. The 30 minute time period allows for retries of valid email.  If the spammer is persistant then they simply end up blacklisted a minute after the duration has expired.

Anybody else try this? 

Dwight
www.vividmix.com
Back to Top
mbrusl View Drop Down
Groupie
Groupie
Avatar

Joined: 05 December 2005
Location: Thunder Bay Ont
Status: Offline
Points: 61
Post Options Post Options   Thanks (0) Thanks(0)   Quote mbrusl Quote  Post ReplyReply Direct Link To This Post Posted: 01 July 2007 at 7:39pm
Originally posted by LogSat LogSat wrote:

samsung,

The IP cache blacklist is stored in memory only, and can't be retrieved. You can however, as you probably already know, display its content in the "Statistics" tab in SpamFilter.


Roberto,

Would you consider entertaining the thought of allowing the option to write to a log file?  As most of us have a good reason on why we want to have this information.


Back to Top
atifghaffar View Drop Down
Senior Member
Senior Member
Avatar

Joined: 31 May 2006
Location: Switzerland
Status: Offline
Points: 104
Post Options Post Options   Thanks (0) Thanks(0)   Quote atifghaffar Quote  Post ReplyReply Direct Link To This Post Posted: 04 August 2007 at 6:23pm
Roberto,

I would also like access to this information so that this information can be sent to the firewall and it blocks the access completely instead of managing this information on each spamfilter node.

Even better if SFE can write this info in the db.




best regards

Atif
Back to Top
 Post Reply Post Reply
  Share Topic   

Forum Jump Forum Permissions View Drop Down



This page was generated in 0.129 seconds.