I  am the one recommending BlackIce. It has a simple INI configuration
file. Here are what the settings are like:

On the blackice.ini config file you can use he following parameters to
limit abnormal URL requests:

http.urllimit.count=300
http.urllimit.interval=50

and for dictionary attacks you can limit total SMTP errors using:

smtp.error.count=10
smtp.error.interval=120

if 10 errors in 120 seconds then block connection...

This  works very well and the software also protects agains many major
attacks automatically in a similar fashion. We wouldn't run IIS or
Imail without it.

http://www.iss.net/products_services/enterprise_protection/rsserver/protector_server.php

--
Roger Heath
[EMAIL PROTECTED]
www.rleeheath.com


----- Copy of Original Message(s): -----


>>I have enclosed sample log file entries for one specific IP that it
>>appears someone was using with a name dictionary to try to determine
>>valid user accounts on domains that we host.

R> This is very common these days, and is simply called a "dictionary attack."

>>I am interpreting this right as what is going on?

R> Yes.

>>Is there any way to stop this?  Such as perhaps if someone generated more 
>>than X SMTP ERR
>>entries in a N minute period they will get blocked for while?

R> There isn't any easy way to stop it.

R> One option is to use a "nobody" alias, so all the addresses will appear 
R> valid.  The advantage to this is that they won't know which addresses are 
R> good and which are bad.  The disadvantage is that if the spammer is dumb 
R> (and I haven't heard of too many smart spammers), they will think all the 
R> addresses are good, and you may end up with lots of spam being sent to 
R> non-existent accounts in the future.

R> Someone on this list was working on a script to automatically detect this 
R> and add the IPs to the SMTP Control Access file, but I'm not sure what the 
R> status of that is.  Also, someone on the list has suggested using BlackIce 
R> Server (but I think it requires special settings to detect dictionary 
R> attacks).  A search of the archive for "dictionary attack" should provide 
R> some more details.

R>                                                     -Scott
R> ---
R> Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
R> Declude Virus: Catches both viruses and vulnerabilities in E-mail, with no 
R> annual licensing fees.

R> ---
R> [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]


R> To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
R> List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
R> Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
R> --
R> ActivatorMail(tm) ver.082302 Scanned for all viruses by 
R> www.activatormail.com intelligent anti-virus anti-spam service

--
ActivatorMail(tm) ver.082302 Scanned for all viruses by 
www.activatormail.com intelligent anti-virus anti-spam service


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to