Forum Moderators: phranque

Message Too Old, No Replies

Email DOS attack on your account detected?

         

smokeybarnable

11:58 pm on Mar 2, 2010 (gmt 0)

10+ Year Member



So my isp recently informed me that an email DOS attack on my domain was detected. They have "changed the MX record for your domain name to point to a device that is designed to mitigate such attacks. The MX record tells the global DNS system which server is in charge of handling e-mails for your domain name. In this case, all incoming e-mails will be routed to the anti-spam/DoS device, which will mitigate the attack and forward all legit e-mail back to your shared hosting server. This will allow you to receive all valid e-mails while the attack is ongoing."

Today when I asked if the attack was still going on they provided me with this information:

"We have checked the status of the Email DDoS attack and it seems that it is still ongoing. For the last 20 hours there are more than 12 000 MX requests."

# cat /var/log/named/queries.log | grep mydomain.com | grep MX | wc -l
12385

My question is why would my tiny ecommerce site be targeted for such an attack? Could this be a competitor? I did block the entire country of china last week. Could this even be an attempt of my isp to sell me their "spam killer" service?

Any advice appreciated.

piatkow

9:24 am on Mar 3, 2010 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



First guess, the attack is not specifically on your account and they have done this with their entire customer base.

JS_Harris

12:00 pm on Mar 3, 2010 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Second guess, as quickly as it started it will stop. The spammer or DOS attacker will ultimately be identified and blocked or swap out new email addresses to spam with, possibly both.

tangor

12:09 pm on Mar 3, 2010 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Sad thing is that many shared hosts still have open relay in their mail servers... and this has been a problem for the last decade or so. Not your problem... theirs... but you get the hit.

JD_Gonzales

2:11 am on Mar 4, 2010 (gmt 0)

10+ Year Member



Tangor is right. Its not your problem smokeybarnable ;)I am wishing it will be fine later. :)