Christian, awesome catch.

I did know the web administration log, but I was in fact looking at the WEB 
CALENDARING web administration log.  No wonder I didn't see login failures for the 
affected accounts.  I had missed the extra "1" in the filename-- it'd be nice if 
Ipswitch made the naming convention a little more intuitive, wouldn't it?

I have identified the offender's IP and will be blocking him entirely at the firewall. 
 It was just one person on a static cable connection.

Thanks again Christian, Sandy and Len!





---------- Original Message ----------------------------------
From: "Christian Lawson" <[EMAIL PROTECTED]>
Reply-To: [EMAIL PROTECTED]
Date:  Tue, 12 Oct 2004 13:27:55 -0400

Are you checking the W1 logs or the W2 logs?  Logon failures from the W1 log appear as:

20041012 132232 Auth Error Failed Authentication - [EMAIL PROTECTED] 
IP.Address.Of.Browser Tries:1 SuspendFlag:0
SuspendTimes:0.

Obviously, the Tries, SuspendFlag, and SuspendTimes values will change.

The 'W1YYMMDD' log is the Web Messaging Administration log (logons/logoffs, password 
changes, AUTH failures, etc).
The 'W2YYMMDD' log is the raw activity log.

Neither of these should be confused with the W11YYMMDD and the W21YYMMDD logs which 
are used by Web Calendaring and the Monitor
service.

Have a good one,
Christian 

-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Spaminator
Sent: Tuesday, October 12, 2004 1:01 PM
To: [EMAIL PROTECTED]
Subject: Re: [IMail Forum] Web Messaging Security

Thanks for responding.  I should have been clearer-- that's what I get for being in a 
hurry.

Yes, the IPs are logged in the web messaging log... but we have a ton of web messaging 
users.  What I need is a way to identify the
lines in the log that relate to login attempts for a given user account-- then I'll be 
able to zero-in on the offender's IP.
Unfortunately, it seems that usernames & login successes/failures aren't in the web 
logs.  I see requests for login.cgi, etc. but
that doesn't help me if there were 10,000 in the last couple days-- I have no way of 
seeing "failures" and no way of identifying
failures for the users who I know are being attacked.

Hope that helps!  ;-)





---------- Original Message ----------------------------------
From: Len Conrad <[EMAIL PROTECTED]>
Reply-To: [EMAIL PROTECTED]
Date:  Tue, 12 Oct 2004 11:48:59 -0500


>It's easy to track down the users who are locked out, but it's not easy 
>finding out who's doing it-- the web messaging log doesn't seem to include 
>any details about login failures.  POP and IMAP do, but the attack is 
>coming in via web messaging.

the web messaging logs don't log the IP of the remote HTTP client?

If you can find the IP, are they from one IP or many IPs?  the remote IP 
would be the strongest piece of evidence.

Len


_____________________________________________________________________
http://IMGate.MEIway.com : free anti-spam gateway, runs on 1000's of sites


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

 



 
                   

To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

 



 
                   

To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to