[rbldnsd] IPs not getting filtered ??
Michael Tokarev
mjt at tls.msk.ru
Mon Sep 26 22:01:28 MSD 2005
Sebastiaan Tigchelaar wrote:
> Hi,
>
> I noticed today that a number of spams originated from IPs withing
> ranges that are blocked.
> The 2 beneath is what I have open atm.
> These (and other) spams arrived after a restart of RBLDNSD and even a
> reboot of the machine.
>
> Could this be a bug?
Sure it could be.. but unfortunately, even if it's a bug, I can't reproduce
it here... ;)
> 222.183.73.197 CHINA 222.176-183
>
>> From the China datafile:
>
> :127.0.0.2:Uh oh, an RBL said that $ is from an unwanted user/ISP/area.
> <..>
> 222.160-163
> 222.176-183 <==
> 222.208-223
> 222.32-63
> 222.76-79
> 222.92-95
So, what does
host 197.73.183.222.your.zone.name
say?
[]
> I also tried to enable logging, but no luck so far yet.
No luck in what? You can't enable logging? Are you sure
your mailserver do query your nameserver?
> Using /etc/sysconf/rbldnsd
>
> RBLDNSD="dsbl -r/var/lib/rbldns/ -b 10.2.1.101/530 \
> ips.blocked.rbl:ip4set:metadata,clients,arcor,auna-es,bellsouth,blueyonder,bt-uk,charter,club-internet,comcast,gaoland,hansenet,interbusiness,ntlworld,proxad,roadrunner,shawcomm,t-dialin,telefonica,telepac-portugal,tpnet-polen,ttnet-turkije,verizon,wanadoo-es-fr,zuid-amerika,land-china,land-japan,land-taiwan,land-korea,hatemails,unknowns,pre-process
> \
> hosts.blocked.rbl:dnset:hosts \
> -l +/var/lib/rbldns/log/rbl-log \
> -s /var/lib/rbldns/stats/rbl-stats \
> "
That looks pretty ok.
/mjt
More information about the rbldnsd
mailing list