What to do if ISP rejects Abuse Reports?
![](https://secure.gravatar.com/avatar/8d6f86b0863aaa259b2aee7fa4868edd.jpg?s=120&d=mm&r=g)
Hello, my systems get attacked from several IPs from Georgia (Countrycode=GE, RIR=RIPE). My Abuse Reports to the abuse address (ib@caucasus.net) of the responsible ISP for the attacker IPs (caucasus.net) just bounce: #ID: <SCC9B> #Mail From: <security@mutluit.com> #Rcpt To: <ib@caucasus.net> #Server: <mail.caucasus.net> [62.168.168.131] # #[<02>] The reason of the delivery failure was: # #550 5.7.1 <security@mutluit.com>: Sender address rejected: Blocked by postmaster What to do in this case?
![](https://secure.gravatar.com/avatar/9e6e91b4d19ab46d2283dee26d7d5f60.jpg?s=120&d=mm&r=g)
On 14/Jan/12 14:19, U.Mutlu wrote:
my systems get attacked from several IPs from Georgia (Countrycode=GE, RIR=RIPE). My Abuse Reports to the abuse address (ib@caucasus.net) of the responsible ISP for the attacker IPs (caucasus.net) just bounce:
#ID: <SCC9B> #Mail From: <security@mutluit.com> #Rcpt To: <ib@caucasus.net> #Server: <mail.caucasus.net> [62.168.168.131]
Only found it on http://www.backscatterer.org/?ip=62.168.168.131
#[<02>] The reason of the delivery failure was: # #550 5.7.1 <security@mutluit.com>: Sender address rejected: Blocked by postmaster
What to do in this case?
What I do is to ban the offending IP address for some months, using a firewall filter. I try to notify that I do so to <postmaster> at that address if it listens on port 25, or to any *-c of that network. Is this the recommended procedure?
participants (2)
-
Alessandro Vesely
-
U.Mutlu