﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Ipswitch Forums / Messaging / IMail Server  / Minutes To Deny Access not honored / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>Ipswitch Forums</description><link>http://forums.ipswitch.com/</link><webMaster>forums@ipswitch.com</webMaster><lastBuildDate>Mon, 01 Dec 2008 21:07:47 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: Minutes To Deny Access not honored</title><link>http://forums.ipswitch.com/Topic44792-10-1.aspx</link><description>Okay, it's now confirmed. The Dictionary Attack feature in V10 is totally broken.&lt;/P&gt;&lt;P&gt;Through systematic testing (turning off all features, and then turning on ONE at a time) I found (and reported to IPswitch as bug) that these settings:&lt;/P&gt;&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;FONT color=#000000&gt;Max Invalid Recipients Per Session:  3 &lt;BR&gt;Soft Error Limits:  0 &lt;BR&gt;Hard Error Limit:  0 &lt;BR&gt;Minutes To Deny Access:  5 &lt;BR&gt;Error Delay Seconds:  10&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT color=#000000&gt; &lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;FONT color=#000000&gt;Auto-Deny Hack Attempts: On&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;a) will disconnect after 3 bad recipients (that's the ONLY thing that works)&lt;BR&gt;b) will NOT add the IP address to the "deny access" list&lt;BR&gt;c) I can't confirm that the 10 second delay works, because IPswitch has yet to figure out how to add seconds to the LOG files. I have a few pages full of log entries per minute...&lt;/P&gt;&lt;P&gt;IF you turn on "Soft Error Limits", and set it to any value (let's say 5), then it:&lt;/P&gt;&lt;P&gt;a) will report log a different error after the FIRST bad recipient&lt;BR&gt;b) will immediately add the IP address to the PERMANENT deny list&lt;BR&gt;c) will NOT remove the IP address after 5 minutes (or ANY amount of time)&lt;BR&gt;d) will do that EVEN if you configure minutes to "0".&lt;/P&gt;&lt;P&gt;The net effect is, that anyone who EVER sends email to ONE bad email address is banned from your server forever - which does a nice job in reducing your mail volume to next to nothing VERY quickly. &lt;/P&gt;&lt;P&gt;Basically - with Version 10, IMail is fully vulnerable to dictionary attacks because it's key defense (a controlled, time-limited block of suspect IP addresses) is NO LONGER FUNCTIONAL.&lt;/P&gt;&lt;P&gt;Although they originally kept claiming that they couldn't reproduce it with my settings, I finally peppered them with enough log files that they are now acknowledging the situation and working on fixing this. THEY are recommending that in the meantime we should all run WITHOUT dictionary attack defenses being turned on!&lt;/P&gt;&lt;P&gt;Best Regards,&lt;BR&gt;Andy</description><pubDate>Thu, 26 Jun 2008 10:46:54 GMT</pubDate><dc:creator>Andy Schmidt</dc:creator></item><item><title>Minutes To Deny Access not honored</title><link>http://forums.ipswitch.com/Topic44792-10-1.aspx</link><description>running the latest Imail version, 10.00&lt;br&gt;&lt;br&gt;Several clients have called saying they can receive email, but they can't send out email. (all their PCs typically appear as the same IP address via their firewall or router.)  After investigating, we find that their IP address got into the Control Access list for various reasons (like they set up a new workstation and forgot to set "my smtp server requires authentication."  Therefore, that one mistake causes all of their users on that shared IP to be denied access.&lt;br&gt;&lt;br&gt;That's fine, but the problem is that even if they correct their problem, they remain in the Control Access list forever.&lt;br&gt;&lt;br&gt;After going through this with several clients, I cleared the Control Access list.  Later, I checked the log for a new "max errors exceeded" event so I could monitor how long the blocked address stayed in the control access list.  Below are relevant log entries.&lt;br&gt;&lt;br&gt;06:19 12:35 SMTPD(8ac6019300000c9c) [189.156.142.216] max errors exceeded, address will be denied future connections for 5 minutes&lt;br&gt;06:19 12:47 SMTPD(8d9d01be00001536) Denied access from 189.156.142.216&lt;br&gt;&lt;br&gt;It seems that the “Minutes To Deny Access” is not honored in Dictionary Attack Settings.  The above IP address should have been removed after 5 minutes according to my settings.  The "denied access" is already 12 minutes later...&lt;br&gt;&lt;br&gt;My settings are:&lt;br&gt;&lt;br&gt;Dictionary Attack Settings&lt;br&gt;Max Invalid Recipients Per Session: 3&lt;br&gt;Soft Error Limits: 3&lt;br&gt;Hard Error Limit: 2&lt;br&gt;Minutes To Deny Access: 5&lt;br&gt;Error Delay Seconds: 10&lt;br&gt;&lt;br&gt;Am I missing something?  Anyone else experiencing this?&lt;br&gt;&lt;br&gt;Best Regards&lt;br&gt;Mike Higgins&lt;br&gt;&lt;br&gt;H&amp;M Systems Software, Inc.&lt;br&gt;600 East Crescent Avenue, Suite 203&lt;br&gt;Upper Saddle River, NJ 07458-1846&lt;br&gt;&lt;br&gt;Phone:  +1 201 934-3414 x14 (Business)&lt;br&gt;Fax:    +1 201 934-9206&lt;br&gt;&lt;br&gt;http://www.HM-Software.com/ &lt;br&gt;&lt;br&gt;</description><pubDate>Fri, 20 Jun 2008 06:44:16 GMT</pubDate><dc:creator>Mike Higgins</dc:creator></item></channel></rss>