Hi!
What I have been doing is dropping routes to the, more then likely, virused/trojaned boxes. But need a better solution which is less dependant on my seeing it happening and will just kill it.
I know this isn't the best place to ask this but I figured we have all suffered these attacks and though you all might know of something or be using something that will work.
What patterns are you getting in, and what mailer are you using, if its exim it would be most likely simple, most of the times just one regexp. But please post the patterns so we know what it looks like.
Are they open proxy's? Please check some IPs on www.dsbl.org that you are getting in.
Bye, Raymond.