Re: Work-in-progress: trickle attack defense

2011-01-27 Thread Victor Duchovni
On Thu, Jan 27, 2011 at 12:04:26PM -0500, Randy Ramsdell wrote: >> 300s for each line as in: mail from: blah ---> 300s? > > What I am getting at here is that the attack will still succeed if using it > for DOS. I am not trying trivialize this work, but understand how this will > stop an attack v

Re: Work-in-progress: trickle attack defense

2011-01-27 Thread Randy Ramsdell
Randy Ramsdell wrote: Wietse Venema wrote: I added the following entry to the wip.html file on the Postfix website. Wietse Trickle attack defense The postscreen daemon, available with Postfix 2.8 and later, already implements time limits to receive one complete SMTP command line. Postscre

Re: Work-in-progress: trickle attack defense

2011-01-27 Thread Randy Ramsdell
Wietse Venema wrote: I added the following entry to the wip.html file on the Postfix website. Wietse Trickle attack defense The postscreen daemon, available with Postfix 2.8 and later, already implements time limits to receive one complete SMTP command line. Postscreen uses a default t