Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


How do you control Spamming on your VPS nodes?
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

How do you control Spamming on your VPS nodes?

TazTaz Member
edited June 2012 in General

I use iptables to limit hourly mail sending on certain port, what else can you do to limit/monitor spam on your nodes?

Comments

  • FranciscoFrancisco Top Host, Host Rep, Veteran
    edited June 2012

    @NinjaHawk said: I use iptables to limit hourly mail sending on certain port, what else can you do to limit/monitor spam on your nodes?

    Don't accept every order that comes in when it's obviously bad. I tell the same joke to my friend that works for a DC and they have tons of chinese customers sign up:

    " If the person is connecting from China, gives a Florida billing address and a UK credit card, you're going to have a b4d t1m3"

    Actually do verification and you'll keep the problem starters mostly out. It's very rare that a spammer gets past Aldyric, we have more cases of a server getting compromised than a user signup and starts railing spam.

    Francisco

    Thanked by 2Aldryic klikli
  • TazTaz Member
    edited June 2012

    @Francisco So far, in last 2 year ( Yes, We have been around 3+ years, Just re branding whole business and changing models), We never had a single charge back nor Spammer, Guess was a bit lucky or because we used to target highend clients (full managed) instead LET user base. This is the first for us trying to get a slice of LET so Just doing obvious researches.

    --
    Wish everyone used harzem's fraud record. Could save some time :D

  • TazTaz Member

    Any special Instruction/ Noob Friendly Advice for OVZ/KVM provider?

  • FranciscoFrancisco Top Host, Host Rep, Veteran
    edited June 2012

    @NinjaHawk said: @Francisco So far, in last 2 year ( Yes, We have been around 3+ years, Just re branding whole business and changing models), We never had a single charge back nor Spammer, Guess was a bit lucky or because we used to target highend clients (full managed) instead LET user base.

    On our Frantech brand we rarely had spammers, I don't think we had any infact. With the spammers we have had, they didn't even chargeback nor dispute the box getting TOS'd. They simply saw it as 'I paid $3.50 to spam hardcore for 2 days'. The IP got BL'd within 2 days and we acted on it within 8 hours.

    There is a few big spam rings that follow the LEB RSS and actually order vm's off every single person that signs up. Sometimes the boxes are used for spam, sometimes it's just a new C&C box. How do we know? We caught the guy doing it and after getting a court order were able to dump their SQL database (as requested by the authorities) and got something like 60 VM's all TOS'd in one go.

    Francisco

  • TazTaz Member

    Wowwww. That's Deep Bro.
    Any suggestion Assuming (Fact?) @Aldyric is helluva lot better than me or any of my staffs?

  • FranciscoFrancisco Top Host, Host Rep, Veteran

    @NinjaHawk said: Any suggestion Assuming (Fact?) @Aldyric is helluva lot better than me or any of my staffs?

    @Aldyric gives tid bits all over but i'm sure he can give you some (maybe in private) to keep in mind :)

    Francisco

  • TazTaz Member

    O the mighty @Aldyric can I get some tips on my private Live Webcam chat :P (Pm can work as well)

  • @NinjaHawk - sure :P I'm about to wrap things up at the office here; once I get to the house and grab some chow I'll shoot ya a PM :P

  • TazTaz Member

    @Aldryic -> Love you man. (No Homo).

  • Waiting for Spamhaus/Spamcop/Abuse notifications... then terminate :)

  • VictorVictor Member

    @William said: Waiting for Spamhaus/Spamcop/Abuse notifications... then terminate :)

    +1, we don't terminate unless we've received complaints/evidence. We usually just suspend when we notice suspicious activities on VMs, and if the client doesn't reply within a period of time after a notice has been sent out, we terminate them. :)

  • Yea, it's not like spamhaus lists the whole /20 at the first offence anyway - I dont see a reason to block on traffic patterns or similar (traffic sniffing, for whatever reason (even traffic monitoring), is barely legal here) - just drop the VPS, message spamhaus, problem solved :)

  • CoreyCorey Member

    @Victor we used to take that approach but legit clients don't like that very much.

Sign In or Register to comment.