Search found 7 matches
- Thu Sep 14, 2023 2:36 pm
- Forum: Error Reports and Issues
- Topic: SMTP security - Multiple RCPT not being blocked
- Replies: 5
- Views: 22892
Re: SMTP security - Multiple RCPT not being blocked
This has gone very quiet after I answered the initial query. Meanwhile my server is still being interrogated for valid mailbox addresses using multiple repeated RCPT commands. Those addresses are then being dictionary-attacked for authentication, and the real user getting locked out (I've had to tur...
- Tue Aug 29, 2023 7:09 pm
- Forum: Error Reports and Issues
- Topic: SMTP security - Multiple RCPT not being blocked
- Replies: 5
- Views: 22892
Re: SMTP security - Multiple RCPT not being blocked
...sorry for repeat comments - more info... I notice that the bot is also attempting domains which are not hosted on the server and these attract a 503 no relay without authentication allowed error. Any type of invalid RCPT tried repeatedly during the same conversation really should trigger abuse de...
- Tue Aug 29, 2023 3:40 pm
- Forum: Error Reports and Issues
- Topic: SMTP security - Multiple RCPT not being blocked
- Replies: 5
- Views: 22892
Re: SMTP security - Multiple RCPT not being blocked
...and they are trying a dictionary attack on the mailbox name for valid domains hosted on the server. So not relaying - the error is "mailbox unavailable or not local". Here's a complete log line with the valid domain changed to foo.com: -- 08/29/23 00:44:48 SMTP-IN E33A6E7BFAE044CFBA493E92EDEBB8E0...
- Tue Aug 29, 2023 3:34 pm
- Forum: Error Reports and Issues
- Topic: SMTP security - Multiple RCPT not being blocked
- Replies: 5
- Views: 22892
Re: SMTP security - Multiple RCPT not being blocked
The server is returning a 550 which should count...
- Mon Aug 28, 2023 9:54 pm
- Forum: Error Reports and Issues
- Topic: SMTP security - Multiple RCPT not being blocked
- Replies: 5
- Views: 22892
SMTP security - Multiple RCPT not being blocked
I have Security settings for SMTP service set so that just 5 bad commands should drop the connection. But my server is being attached by a dictionary attack to discover valid addresses, with multiple RCPT TO commands being tried until one works. And the connection is not being dropped as it ought to...
- Tue Dec 27, 2022 12:37 pm
- Forum: General
- Topic: Where was 10.43 announced??
- Replies: 0
- Views: 8980
Where was 10.43 announced??
FAO MailEnable Please can you ensure that announcements – for instance new versions - are properly published on your website and via the software Management Console. Latest announcement I can see (in the Pro product) is about 10.42. We found out about 10.43 accidentally! :-( This is also by way of a...
- Fri Mar 18, 2022 9:58 am
- Forum: MailEnable Professional Edition
- Topic: Quarantine view and the Destination column?
- Replies: 5
- Views: 16875
Re: Quarantine view and the Destination column?
This is a few years old, and it is clearly a bug which still prevails in 10.38 Is the clear up rate for these things really so poor? Why? I came on here to see if there was any chance of admin web access to the quarantine folder, but if even this kind of simple thing doesn’t get fixed, then requests...