>  Even if the issue is one of robots, do we really think that is is 
> a malicious attack that is targeting IMAIL users?  One or two 
> perhaps, but so many people??

Let's drop the "malicious attack" phrase (uh, for now), but, due to 
an apparent epidemic covering both imail 5 and 6, I think we need to 
understand the effect on spurious, non-user visits to Imail HTTP server.

We know Imail's HTTP is not like a "normal" dumb HTTP page server in 
that Imail is an cgi applicatation that uses HTTP that spawns a 
session/proces and maintains connection state for each user, with a 
default capacity of up to 500 simultaneous sessions, IIRC.

So if a lot of intial, defaut page requests for webmail.domain.com:80 
hit in a short time (contest: how few PERL lines does it take to 
write such DoS script?) and webmail only displayed the login page (a 
robot or DoS attack couldn't get past that), then that could be a lot 
sessions spawned in a short period just to show the login page.

and each login page session stays alive for 12 minutes? or does that 
timer start after successful login?

 >Maybe more usual  robot action is the catalyst? However, I would bet on a
>genuine ipswitch bug.

so, which is simpler: robot or bug?  vbg

Now, does anybody understand why I really want Imail 7 to allow us 
the option to move iwebmsg.exe to satellite machines so we can keep 
the very scaleable "users' mailbox server" to just 
POP/IMAP/SMTP?  This would really help scale up the compute-expensive 
web messaging product without compromising the mailbox server's 
scaleability and reliability.

Len

Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Reply via email to