wlanboy
Content Contributer
Do you think abuse@provider does work?
My log watcher daemon is sending me one or two emails a day (since yesterday a lot more) about detected "attacks". I ignore that as long as there is no pattern.
But these incident are just the top of the iceberg if I look to my mailserver. Fail2ban is quite active and on saturday after breakfast I am seinding abuse mails (with attached logs) to the providers.
If I look to the responses:
My log watcher daemon is sending me one or two emails a day (since yesterday a lot more) about detected "attacks". I ignore that as long as there is no pattern.
But these incident are just the top of the iceberg if I look to my mailserver. Fail2ban is quite active and on saturday after breakfast I am seinding abuse mails (with attached logs) to the providers.
If I look to the responses:
- 10% no response but ip is not showing up in my logs
- 30% start a dispute, asking for additional information
- 10% forward the response of their client .. always something like "cancled my customer will not happen again..."
- 50% just do nothing