>We're considering the IMGate system and was wondering how does the software >actually know that a possible dictionary attack is taking place?
Right now (IMGate "advanced" is always "in progress"), IMGate checks every minute for the number of IMGate rejects (for whatever reason) per ip, and above a certain threshold, instead of IMGate continuing to reject at SMTP level, it firewalls that ip at tcp/ip level. Blocking at ip level is more efficient that rejecting at SMTP level. The other attack is when messages get past IMGate (not rejected because not in RBL, ACL, etc, etc) to the mailbox server(s) where they are bounced as "user unknown". Above a certain number of bounces per unit of time, IMGate will ACL/block that ip at SMTP level, and then if the SOB keeps it up with rejects, it get escalated to tcp/ip firewalling as above. Len > We do >operate various list and corporate mailings. Does the IMGate software just >block ip's that tries too many AUTH attempts? IMGate doesn't have the user+password info, so SMTP AUTH isn't available. I've never heard of a spammer trying to crack passwords with SMTP AUTH. That's way too hard compared to all the other ready channels for doing their deliveries. If SMTP AUTH password cracking is a persistant problem for you, then it's pretty easy to script a detector for that and block the ip at IMail. likewise with POP3 password attacks Len To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
