Solved

Windows 2003 Server - I have people attempting to break into my email server - what is my proper response?

Posted on 2008-09-29
8
259 Views
Last Modified: 2012-05-05
I've checked my email server logs, and I'm getting a lot of attempts to break in via brute-force + dictionary attacks.

I know the IP's that are doing it - is there an easy way for me to A) Block these IPs B) Automatically detect and block new ones in the future without affecting my email clients

Thanks
0
Comment
Question by:hamlin11
  • 4
  • 3
8 Comments
 
LVL 18

Assisted Solution

by:flyingsky
flyingsky earned 450 total points
ID: 22599523
are the attackes coming from outside or inside?
If they are outside, you can use your firewall to block that IP.
If it's from inside, you need to find out what's wrong with that machine (or that user).
0
 

Author Comment

by:hamlin11
ID: 22599664
It's not from the local machine - it's from an external IP address -- possibly in the same server farm but probably outside of it.


0
 
LVL 18

Assisted Solution

by:flyingsky
flyingsky earned 450 total points
ID: 22599697
can you block any traffic from that IP on your firewall?
0
DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.

 
LVL 5

Assisted Solution

by:NutrientMS
NutrientMS earned 50 total points
ID: 22599701
Yes, as flyingsky said, use your firewall to block that IP address.  What user account are they trying to brute force?  If it is the administrator account make sure you have a very strong password for it (which is best practice anyway)
0
 

Author Comment

by:hamlin11
ID: 22599788
They're trying a variety of logins & passwords on a specific domain.

I'll block the IP on my firewall - do you think I should add an IP-Filter on the server itself or should I configure the hardware firewall outside my server?

Thanks for the tips
0
 
LVL 18

Assisted Solution

by:flyingsky
flyingsky earned 450 total points
ID: 22599843
I would recommend another piece of equipment other than your server itself.
0
 

Author Comment

by:hamlin11
ID: 22599882
Ok, I'll configure the hardware firewall.

Do you have any comments on the second part of my question -- Is there some way to either alert me via email when a cracker is trying to get in - or auto-block an IP that tries to access too much?

Thanks

P.S., my email server software does not have this functionality
0
 
LVL 18

Accepted Solution

by:
flyingsky earned 450 total points
ID: 22599897
Apparently you need some kind of Log analyzer software for this.
0

Featured Post

Secure Your Active Directory - April 20, 2017

Active Directory plays a critical role in your company’s IT infrastructure and keeping it secure in today’s hacker-infested world is a must.
Microsoft published 300+ pages of guidance, but who has the time, money, and resources to implement? Register now to find an easier way.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Welcome to my series of short tips on migrations. Whilst based on Microsoft migrations the same principles can be applied to any type of migration. My first tip is around source server preparation. No migration is an easy migration, there is a…
Encryption for Business Encryption (https://en.wikipedia.org/wiki/Encryption) ensures the safety of our data when sending emails. In most cases, to read an encrypted email you must enter a secret key that will enable you to decrypt the email. T…
In an interesting question (https://www.experts-exchange.com/questions/29008360/) here at Experts Exchange, a member asked how to split a single image into multiple images. The primary usage for this is to place many photographs on a flatbed scanner…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question