On 30/12/2019 23:12, Benny Pedersen wrote:
> Viktor Dukhovni skrev den 2019-12-30 23:46:
>
>>> Dec 30 23:26:09 mail postfix/postscreen[16020]: CONNECT from
>>> [182.99.42.88]:49546 to [192.168.2.66]:25
>>> Dec 30 23:26:10 mail postfix/postscreen[16020]: PREGREET 14 after
>>> 0.26 from [182.99.42.88]:49546: EHLO ylmf-pc\r\n
>
> https://blog.sys4.de/abwehr-des-botnets-pushdo-cutwail-ehlo-ylmf-pc-mit-iptables-string-recent-smtp-de.html
>
>
> to remove noice in log files
>
> # cat shorewall-rules
> ?SECTION ESTABLISHED
> DROP net $FW tcp 25;;-m string --algo bm --string "EHLO ylmf-pc"
Thank you.

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to