

I'm running xmail 1.27 on RHEL5.5


The SMTP logs are showing a single AUTH=EFAIL:TYPE=LOGIN every hour at xx:00

It is coming from the same PC I believe, although IP changes, the ISP and
area indicated by the rDNS suggests it is the same PC.

Most mail clients attempt POP3 more than once an hour, so I'm suspicious.


The logs don't indicate the username in the login attempt.


Is there any way to report on the username that is being used in the

If nothing else I can contact the user.  

However if it is a low speed dictionary attack, I'd like to be able to
identify that and take some action.


Any ideas?


Rob  :-)

xmail mailing list

Reply via email to