[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] POP3 Scanning



> >   Recently we have seen an increase in POP3 scanning.  The
> > robot will open a POP3 connection and try to login as some
> > user.  When the server says, "No such user here", it
> > continues until it finds a valid email account.  I call this
> > trolling for valid mailboxes.  I'm sure there is a more
> > techie term for it.
>
> It's called a dictionary attack.
>
> >
> > Anyway, has anyone found a good, solid way to prevent these
> > people from doing this?  Even if we could prevent the "No
> > such user" response for invalid mailboxes, it would at least
> > render their activities as useless.
>
> Looks like some people have come up with methods to block this.
>

you could also setup snort and drop the people trying for a period of time..

Zeffie
Cobalt RaQ System Administration, Maintenance and Repairs.
http://www.zeffie.com/how_to_contact_zeffie.html 734.454.9117
http://www.zeffie.com/ Home of the Worlds Largest Collection of RaQ rpms
Advanced Cobalt Security, Firewall, Snort, AntiSpam, AntiVirus, etc. GUI's