[Exim] Dictionary Scans - HOWTO

Top Page
Delete this message
Reply to this message
Author: ODHIAMBO G. Washington
Date:  
To: exim-users
Subject: [Exim] Dictionary Scans - HOWTO
After a few days leave, everything has evaporated, so I seriously need
some help. I have looked at the archives examples and used the following
acl to try and keep away dictionary scans but it doesn't seem to work:

drop   message     =  *** Dict scan!. Too many bad recipients, $rcpt_fail_count out of $rcpt_count
           condition   = ${if > {${eval:$rcpt_fail_count}}{2}{yes}{no}}
           delay       = ${eval: ($rcpt_fail_count + 1) * 1}m
           log_message = Dictionary attack



I've placed this right after the callout acl.


All help welcome.


-Wash

--
Odhiambo Washington   <wash@???>  "The box said 'Requires
Wananchi Online Ltd.  www.wananchi.com      Windows 95, NT, or better,'
Tel: +254 2 313985-9  +254 2 313922         so I installed FreeBSD."
GSM: +254 72 743223   +254 733 744121       This sig is McQ!  :-)



"To err is human, to forgive, beyond the scope of the Operating System"