> Even if the issue is one of robots, do we really think that is is
> a malicious attack that is targeting IMAIL users? One or two
> perhaps, but so many people??
Let's drop the "malicious attack" phrase (uh, for now), but, due to
an apparent epidemic covering both imail 5 and 6, I think we need to
understand the effect on spurious, non-user visits to Imail HTTP server.
We know Imail's HTTP is not like a "normal" dumb HTTP page server in
that Imail is an cgi applicatation that uses HTTP that spawns a
session/proces and maintains connection state for each user, with a
default capacity of up to 500 simultaneous sessions, IIRC.
So if a lot of intial, defaut page requests for webmail.domain.com:80
hit in a short time (contest: how few PERL lines does it take to
write such DoS script?) and webmail only displayed the login page (a
robot or DoS attack couldn't get past that), then that could be a lot
sessions spawned in a short period just to show the login page.
and each login page session stays alive for 12 minutes? or does that
timer start after successful login?
>Maybe more usual robot action is the catalyst? However, I would bet on a
>genuine ipswitch bug.
so, which is simpler: robot or bug? vbg
Now, does anybody understand why I really want Imail 7 to allow us
the option to move iwebmsg.exe to satellite machines so we can keep
the very scaleable "users' mailbox server" to just
POP/IMAP/SMTP? This would really help scale up the compute-expensive
web messaging product without compromising the mailbox server's
scaleability and reliability.
Len
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/