It's easy to track down the users who are locked out, but it's not easy finding out who's doing it-- the web messaging log doesn't seem to include any details about login failures. POP and IMAP do, but the attack is coming in via web messaging.
the web messaging logs don't log the IP of the remote HTTP client?
If you can find the IP, are they from one IP or many IPs? the remote IP would be the strongest piece of evidence.
Len
_____________________________________________________________________ http://IMGate.MEIway.com : free anti-spam gateway, runs on 1000's of sites
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
