I have enclosed sample log file entries for one specific IP that it
appears someone was using with a name dictionary to try to determine
valid user accounts on domains that we host.
This is very common these days, and is simply called a "dictionary attack."

I am interpreting this right as what is going on?
Yes.

Is there any way to stop this? Such as perhaps if someone generated more than X SMTP ERR
entries in a N minute period they will get blocked for while?
There isn't any easy way to stop it.

One option is to use a "nobody" alias, so all the addresses will appear valid. The advantage to this is that they won't know which addresses are good and which are bad. The disadvantage is that if the spammer is dumb (and I haven't heard of too many smart spammers), they will think all the addresses are good, and you may end up with lots of spam being sent to non-existent accounts in the future.

Someone on this list was working on a script to automatically detect this and add the IPs to the SMTP Control Access file, but I'm not sure what the status of that is. Also, someone on the list has suggested using BlackIce Server (but I think it requires special settings to detect dictionary attacks). A search of the archive for "dictionary attack" should provide some more details.

-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches both viruses and vulnerabilities in E-mail, with no annual licensing fees.

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to