Logout

Alt-N Discussion Groups > MDaemon Discussion Groups > MDaemon Configuration > Archive > Account Hijack Detection no works

 [F] Alt-N Discussion Groups  / MDaemon Discussion Groups  / MDaemon Configuration  / Archive  /

Account Hijack Detection no works

[m.capanni@grifonline.it]
m.capanni@grifo…
Newbie
Newbie
Posts: 59

MDaemon
SecurityPlus
WebAdmin
m.capanni@grifonline.it - 03:50am, Jan 2 2020

Hello everyone,

I have an Mdaemon server version 14.5.7 installed on a Windows server.
I configured the Hijack Detection feature so that accounts can't send more than 150 messages in 30 minutes, with account lockout if the limit is exceeded.
I realized, however, that sometimes it behaves not as I should expect, I report below the last log where it is clearly seen that in the last 30 minutes only 77 messages were sent from the account smtp.acme@blabla.com and yet the it blocked.
Why do you think this happens?

Thank you,

best

Max

Attachments:

log.txt (16 KB)


  All MessagesOldest ItemsOlder ItemsNewer ItemsNewest Items

David C - Jan 16, 2020 1:09 pm (#1 Total: 1)  

 

Photo of Author
David C
Guru
Guru
Posts: 1434
Hello,

When you say that the message is blocked, are you saying that the email message is being refused because the account is frozen?

Two MDaemon features are capable of freezing accounts:
  • Dynamic Screen
  • Hijack Detection

    How did you determine which of the two features was causing the account in question to be frozen?

    Did your "postmaster" alias receive an email notification of the account being frozen?

    If so, which of the two features above was responsible for the freezing of the account?



    Regarding the Hijack Detection feature:

    From the "Help" file for MDaemon v14.5.x:



    Freeze accounts when limit is reached

    Check this box if you wish to freeze accounts that attempt to send more than the allowable number of messages. When this happens, the server sends a 552 error, the connection is dropped, and the account is immediately frozen. The frozen account will no longer be able send mail or check its mail, but MDaemon will still accept incoming mail for the account. Finally, when the account is frozen an email is then sent to the postmaster about the account. If the postmaster wishes to re-enable the account that he can simply reply to the message.



    Regarding the Dynamic Screening feature:

    From the "Help" file for MDaemon v14.5.x:

    Freeze accounts

    Check this box if you wish to freeze accounts that fail the designated number of authentication attempts in a single day.

    Email postmaster

    Check this box if you wish to send an email to the postmaster whenever an account fails the designated number of authentication attempts in a single day.



    More information is needed to troubleshoot your issue.

    Please submit an email support request for further assistance.
  • http://www.altn.com/Support/RequestSupport/

    With your email support request, please provide the following:

    The email address of the MDaemon account that was frozen and the date/time at which it was frozen.

    Please compress all requested files and folders into the same .ZIP file and attach that .ZIP file to a reply to this email message.

    If your "postmaster" alias received an email notification of the account being frozen, please provide a copy of the MDaemon .MSG file from your server (default mail folder location: "\MDaemon\Users\<DOMAIN_NAME>\<USER_NAME>\")

    A screen shot of your Hijack Detection settings

    A screen shot of your Dynamic Screen settings

    A copy of the following MDaemon log files from folder "\MDaemon\Logs\" covering the time period during which the account was frozen:
  • DynScrn-yyyy-mm-dd.log (This log file might not be present in that older version of MDaemon)
  • MDaemon-yyyy-mm-dd-all.log
  • MDaemon-yyyy-mm-dd-Screening.log
  • MDaemon-yyyy-mm-dd-SMTP-(in).log
  • MDaemon-yyyy-mm-dd-System.log

    Again, please compress all requested files and folders into the same .ZIP file and attach that .ZIP file to a reply to this email message.

  • [Last Editor: David C, Jan 16, 2020 1:11 pm. Total Edits: 1]



      All MessagesOldest ItemsOlder ItemsNewer ItemsNewest Items



     Content:

    Read New | Search

     Guest:

    Email to Admin



    You are visiting as a Guest user.