Roger,
Saturday, December 21, 2002 you wrote:
RH> I am the one recommending BlackIce.
I didn't mean to not recommend it either. It has helped. It just
hasn't helped as much as we'd hoped.
RH> and for dictionary attacks you can limit total SMTP errors using:
RH> smtp.error.count=10
RH> smtp.error.interval=120
Yes, we have that setting too.
My hypothesis is that the reports don't come back to blackice
until the connection is finally closed. So when we have one of
these attackers hold the connection open for several hundred
rcpt-to attempts black ice doesn't know until afterwards. It then
does block the ip but not until we've had several hundred
attempts. Actually I think the most I've seen was 4,000+
rcpt-to's.
And by blocking the ip at the transport layer (which it apparently
does) it does seem to prevent the attacking program from switching
to the backup mx.
The dictionary attacks for us continue to be as much or more
problem than the spam.
Terry Fritts
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/