I am the one recommending BlackIce. It has a simple INI configuration file. Here are what the settings are like:
On the blackice.ini config file you can use he following parameters to limit abnormal URL requests: http.urllimit.count=300 http.urllimit.interval=50 and for dictionary attacks you can limit total SMTP errors using: smtp.error.count=10 smtp.error.interval=120 if 10 errors in 120 seconds then block connection... This works very well and the software also protects agains many major attacks automatically in a similar fashion. We wouldn't run IIS or Imail without it. http://www.iss.net/products_services/enterprise_protection/rsserver/protector_server.php -- Roger Heath [EMAIL PROTECTED] www.rleeheath.com ----- Copy of Original Message(s): ----- >>I have enclosed sample log file entries for one specific IP that it >>appears someone was using with a name dictionary to try to determine >>valid user accounts on domains that we host. R> This is very common these days, and is simply called a "dictionary attack." >>I am interpreting this right as what is going on? R> Yes. >>Is there any way to stop this? Such as perhaps if someone generated more >>than X SMTP ERR >>entries in a N minute period they will get blocked for while? R> There isn't any easy way to stop it. R> One option is to use a "nobody" alias, so all the addresses will appear R> valid. The advantage to this is that they won't know which addresses are R> good and which are bad. The disadvantage is that if the spammer is dumb R> (and I haven't heard of too many smart spammers), they will think all the R> addresses are good, and you may end up with lots of spam being sent to R> non-existent accounts in the future. R> Someone on this list was working on a script to automatically detect this R> and add the IPs to the SMTP Control Access file, but I'm not sure what the R> status of that is. Also, someone on the list has suggested using BlackIce R> Server (but I think it requires special settings to detect dictionary R> attacks). A search of the archive for "dictionary attack" should provide R> some more details. R> -Scott R> --- R> Declude JunkMail: The advanced anti-spam solution for IMail mailservers. R> Declude Virus: Catches both viruses and vulnerabilities in E-mail, with no R> annual licensing fees. R> --- R> [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] R> To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html R> List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ R> Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/ R> -- R> ActivatorMail(tm) ver.082302 Scanned for all viruses by R> www.activatormail.com intelligent anti-virus anti-spam service -- ActivatorMail(tm) ver.082302 Scanned for all viruses by www.activatormail.com intelligent anti-virus anti-spam service To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
