Thanks for responding. I should have been clearer-- that's what I get for being in a hurry.
Yes, the IPs are logged in the web messaging log... but we have a ton of web messaging users. What I need is a way to identify the lines in the log that relate to login attempts for a given user account-- then I'll be able to zero-in on the offender's IP. Unfortunately, it seems that usernames & login successes/failures aren't in the web logs. I see requests for login.cgi, etc. but that doesn't help me if there were 10,000 in the last couple days-- I have no way of seeing "failures" and no way of identifying failures for the users who I know are being attacked. Hope that helps! ;-) ---------- Original Message ---------------------------------- From: Len Conrad <[EMAIL PROTECTED]> Reply-To: [EMAIL PROTECTED] Date: Tue, 12 Oct 2004 11:48:59 -0500 >It's easy to track down the users who are locked out, but it's not easy >finding out who's doing it-- the web messaging log doesn't seem to include >any details about login failures. POP and IMAP do, but the attack is >coming in via web messaging. the web messaging logs don't log the IP of the remote HTTP client? If you can find the IP, are they from one IP or many IPs? the remote IP would be the strongest piece of evidence. Len _____________________________________________________________________ http://IMGate.MEIway.com : free anti-spam gateway, runs on 1000's of sites To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/ To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
