I'm new to this mailinglist so I don't know if this has already been
proposed...
Have you considered to implement the tests done by the BotNet plugin of
SpamAssassin?
http://people.ucsc.edu/~jrudd/spamassassin/Botnet-0.7.tar
It try to identify the botnets by looking at the DNS information of the
last relay. It appears to me (and many others on SpamAssassin
mailinglist) to be VERY effective. It gives some false positives so it's
not a good idea to use for blacklisting, but it is very good for
greylisting.
Thanks.
--
___________________________________________________
__
|- giannici@...
|ederico Giannici http://www.neomedia.it
___________________________________________________Message
BotNet plugin
2006-12-25 by Federico Giannici
Attachments
- No local attachments were found for this message.