Features > SMTP Services > Dictionary Attacks Dictionary AttacksSpammers don't just send email to addresses they know, but also make up addresses on the off-chance that they exist. This may seem hard work, but with modern broadband connections (usually someone else's - inadvertantly running an open relay), and a dictionary of names, they can send messages to every imaginable address at your domain. Mailtraq detects and blocks dictionary attacks.
The SMTP service limits IP addresses to 10 "mailbox not found" errors per 30 minutes.
This functionality is always enabled; there is no configuration required.
QUOTE:
My Mailtraq server got hit by a POP3 dictionary attack this morning. 41,903 connection attempts in 12 minutes, and all but the first 10 were denied after MTQ determined it was being attacked. End result: one huge log file, one phone call to the IT department of a certain Canadian institute of higher education, but most importantly, one completely unperturbed mail server.
Update:
2.12.2.2372 May 29 2008
Updated Dictionary Attack Manager to prevent repeated log entries (over 50 attacks).
Prevents dictionary attacks on SMTP, POP3, IMAP and FTP. Firewall denials contribute to dictionary attack counters.
|