Roger,

Saturday, December 21, 2002 you wrote:
RH> I  am the one recommending BlackIce.

    I didn't mean to not recommend it either.  It has helped.  It just
    hasn't helped as much as we'd hoped.

RH> and for dictionary attacks you can limit total SMTP errors using:
RH> smtp.error.count=10
RH> smtp.error.interval=120

    Yes, we have that setting too.
    
    My hypothesis is that the reports don't come back to blackice
    until the connection is finally closed.  So when we have one of
    these attackers hold the connection open for several hundred
    rcpt-to attempts black ice doesn't know until afterwards.  It then
    does block the ip but not until we've had several hundred
    attempts.  Actually I think the most I've seen was 4,000+
    rcpt-to's.

    And by blocking the ip at the transport layer (which it apparently
    does) it does seem to prevent the attacking program from switching
    to the backup mx.

    The dictionary attacks for us continue to be as much or more
    problem than the spam.

    
Terry Fritts


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to