Index: [Article Count Order] [Thread]

Date:  Sat, 19 Jan 2008 07:59:54 +1000 (EST)
From:  User Ernie <ernie (at mark) info.eis.net.au>
Subject:  [coba-e:11740] POP3 DOS attack
To:  coba-e (at mark) bluequartz.org
Message-Id:  <200801182159.m0ILxs6M059843 (at mark) info.eis.net.au>
X-Mail-Count: 11740

Over the last few days there has been several POP3 attacks on our BQ(Nuonce0  mail
servers whereby a huge number of POP3 connections are established, I presume
it's a dictionary attack of some sort. The effects are serious, on 3 servers
clients couldn't log in with POP3 any more even though Dovecot was respoding
when I telnet to port 110, they all got autentication errors,a reboot was required. 
Another machine ceased working altogether and had to be powercycled. I assume 
it ran out of swap but it's hard to tell as the sceen blanking had kicked 
in on the console.

How can I protect the server against these POP3 attacks taking out POP
logins?

How can I turn off the screen blanking to enable console messages.

- Ernie.