It seems our system is being attacked by somebody/something trying to brute force a couple of our accounts. I'd like to find the IP of the person so I can block them, but I look at the IP in the audits.log file and it shows up as our mail servers external IP address. Here is a line
Same basic thing is showing in the mailbox.log file. I'm not sure where else to look to see who is connecting. I'm hoping somebody can guide me to the proper log file. Thanks!Code:[btpool0-94] [ip=xxx.xxx.xxx.xxx;] security - cmd=Auth; account=bogus@domain.com; protocol=soap; error=authentication failed for bogus, invalid password;


LinkBack URL
About LinkBacks


