Return-Path: Received: from mail.technospider.com ([24.227.122.2] verified) by mail.stalker.com (CommuniGate Pro SMTP 5.2c5b) with ESMTP id 42475953 for SIMS@mail.stalker.com; Mon, 21 Jan 2008 07:00:30 -0800 Received-SPF: none receiver=mail.stalker.com; client-ip=24.227.122.2; envelope-from=david@technospider.com Received: from localhost (localhost [127.0.0.1]) by mail.technospider.com (Postfix) with ESMTP id 27F9D6FBE78F for ; Mon, 21 Jan 2008 09:59:16 -0500 (EST) Received: from mail.technospider.com ([127.0.0.1]) by localhost (strflt.technospider.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 06563-04 for ; Mon, 21 Jan 2008 09:58:57 -0500 (EST) Received: from [192.168.1.221] (rrcs-67-78-170-98.se.biz.rr.com [67.78.170.98]) by mail.technospider.com (Postfix) with ESMTP id 577E06FBE766 for ; Mon, 21 Jan 2008 09:58:47 -0500 (EST) Mime-Version: 1.0 (Apple Message framework v753) In-Reply-To: References: Content-Type: text/plain; charset=US-ASCII; delsp=yes; format=flowed Message-Id: <39E2195C-8209-4DF6-BC01-1D92E1906A5B@technospider.com> Content-Transfer-Encoding: 7bit From: David Muszynski Subject: Re: How to blacklist a client IP? Date: Mon, 21 Jan 2008 09:58:50 -0500 To: "SIMS Discussions" X-Mailer: Apple Mail (2.753) X-Virus-Scanned: by amavisd-new at technospider.com X-Spam-Status: No, hits=-2.87 tagged_above=-999 required=5 tests=AWL, BAYES_00 X-Spam-Level: On Jan 21, 2008, at 9:52 AM, Alan Summerfield wrote: > Hi, > > it's a few years since I had anything to do with the SIMS mailing list > but it's good to see that it's still active. > > I'm back as I have a problem with a "client" at 71.140.125.37 who has > since last night, been trying to get into the accounts by going > through > hundreds of username/password combinations. Here's a log extract: > > 11:14:21 0 SYSTEM Account {consult} Resources open failed. Error > Code=-43 > 11:14:21 1 POP {consult} is not open: password(eagle) is wrong. > Connection from [71.140.125.37:14341] > > I've put 71.140.125.37 in the "Blacklisted Adresses" of the SMTP > control > panel, to no effect. > > What else can I do? Usernames beginning with "C" are being tried at > the > moment and I suspect it won't stop until it's reached "Z"... > > Alan Summerfield > > Have you tried blacklisting the IP at your border device? -- Thanks, David http://www.FloridaPets.org 321.961.5281