Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 08-17-2007, 07:44 AM
Intermediate Member
 
Posts: 19
Default Avoiding Brutal Force Attacks

Hello everybody!

I tried brutal force attack in my own server. I was outside the private network. I got a very good attack rate though. The avarage was 22tries/sec. I also tried the same attack in several different servers. I.E. Hotmail and other free ones. All of them blocked my IP address after trying a few times. It seems to be the best kind of protection, although I don't know where this protection is made.

Another server I tryed the attack offered a low rate of attaks per second (less than 2/sec). It complicates the attack but it is still possible.

I know that a good password policy is a huge issue to be considered, but it's hard get the users to understand it. When they have a strong password, they write it down and leave the note beside their computer. :S

Yet, Zimbra offers the option of blocking the account after X failed loggins for Y time. If this issue is enabled, someone can keep blooking some account on purpose (terrorism).


What would be the best way to prevend this kind of attack? How do the free servers block the ip address?


Thanks in advance.

Tilinho
Reply With Quote
  #2 (permalink)  
Old 08-17-2007, 09:29 PM
Former Zimbran
 
Posts: 5,606
Default

All account logins are logged to /opt/zimbra/log/audit.log
We log IP as well.
You can use that to block an IP or IP range at your firewall.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.