From Newsgroup: news.admin.peering
A recurring flood is currently targeting /alt.privacy.anon-server/ and
appears to be exploiting open or unauthenticated Mail-to-News and NNTP injection paths.
The campaign initially used PGP-armored messages through a local
Mail-to-News gateway. After that pattern was filtered, it continued with cleartext messages. It later moved to an external Mail-to-News gateway
and reached other servers through normal NNTP transit.
Operators of open NNTP and Mail-to-News services should consider:
- rate limits per account, injection path and target group;
- strict daily limits for anonymous gateways;
- Cleanfeed flood_groups with PHR enabled;
- phr_aggressive when no useful NNTP-Posting-Host is available;
- PHN limits for repeated posting-host activity;
- applying Path rules through bad_paths, not bad_hosts, when the
relevant evidence is a Path component;
- retaining narrow campaign signatures only as secondary, temporary
protection;
- sharing timestamps, Message-IDs and complete Paths with the relevant
gateway operators.
Gab Virebent aka Gabx
---
https://news.tcpreset.net
--- Digital Signature --- Z6HuD2rnTwU7/+5Mf7SF1Ac7Jrd2fzXnT2bNqDToFALeShHCHISlAly8De8AySC1LWi0JDe6ctpL3actza9HBQ==
--- Synchronet 3.22a-Linux NewsLink 1.2