First I am not affiliated in any way with the producers of the tool listed below, just a user that got "Bounce Bombed" to its knees during the past weeks, and could not find any other practical solution to stop the attack.
If you are on the wrong end of one of these attacks you know how destructive it can be. It can bring down your server to a halt beacuse is a form of DDOS attack. I recommend you configure DNSBL on your email servers to query: "ips.backscatterer.org" ASAP.
See Backscatterer.org for more information. In may case it just stopped the attack on its tracks, and they also seem to test (not sure) any IP addresses submitted for this vulnerability, so it really works, and it's FAST.
As you may well know, "Bounce Bombs" (aka: backscatter) is a technique used by spammers and/or email harvesters, to take advantage of poorly configured email servers and virus scanners by including the email addresses of the victims (YOUR EMAIL ADDRESSES), as the return address on the emails they send, thus causing an enormous amount of bounced emails back to your servers when the (poorly configured) system fails to direct the emails to valid users.
Simply put "poorly configured" systems in this case, means email servers and virus scanners set to reject ALL invalid emails back to the forged return addresses. To configure email servers and virus scanners not behave this way is as simple as having them DROP invalid emails, and to never bounce or soft-bounce.
Yes you may say this (rejecting) is the standard protocol, and you are doing nothing wrong by issuing rejects, BUT that comes from a time when the email systems worked on the assumption that this feature will never be abused as it is these day.
Hope someone will find this information useful, and please forgive my ignorance, or lack of technicality of some of the terms used.
