>We're considering the IMGate system and was wondering how does the software
>actually know that a possible dictionary attack is taking place?

Right now (IMGate "advanced" is always "in progress"), IMGate checks every 
minute for the number of IMGate rejects (for whatever reason) per ip, and 
above a certain threshold, instead of IMGate continuing to reject at SMTP 
level, it firewalls that ip at tcp/ip level.  Blocking at ip level is more 
efficient that rejecting at SMTP level.

The other attack is when messages get past IMGate (not rejected because not 
in RBL, ACL, etc, etc) to the mailbox server(s) where they are bounced as 
"user unknown".   Above a certain number of bounces per unit of time, 
IMGate will ACL/block that ip at SMTP level, and then if the SOB keeps it 
up with rejects, it get escalated to tcp/ip firewalling as above.

Len

>   We do
>operate various list and corporate mailings.  Does the IMGate software just
>block ip's that tries too many AUTH attempts?

IMGate doesn't have the user+password info, so SMTP AUTH isn't 
available.  I've never heard of a spammer trying to crack passwords with 
SMTP AUTH.  That's way too hard compared to all the other ready channels 
for doing their deliveries.

If SMTP AUTH password cracking is a persistant problem for you, then it's 
pretty easy to script a detector for that and block the ip at 
IMail.  likewise with POP3 password attacks

Len


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to