SmarterMail allowing login attempts from denied countries to fake out attackers?
Problem reported by ß - Today at 5:57 PM
Submitted
After an update from 9652 to 9693, I'm now getting many IDS brute force login attempts from countries that are specifically denied. My login denial list is all but USA.

Support says that SmarterMail lets some attempts through to "fake out" the attackers. Is this true? If so, what percentage? How does SmarterMail decide which attempts to fake out since not all of the attempts are getting faked out? Frankly, I think its a bug, but did I miss this new "feature?"

The reason that attackers from those countries are not just blocked outright is to waste their time and not make them aware that they can't log in because they are country-blocked. If an attacker did successfully guess a user's login credentials, SmarterMail would not indicate anything different, so the attacker can simply assume that the username and password combination they tried was incorrect.
Tim Uzzanti Replied
Employee Post
I think there is some confusion.

There’s nothing random about our blocking mechanism by country. It’s implemented just before authentication, which means the IP address is connected and transferring commands until we reject it. If you’re seeing this IP in sessions lists at times, that is why. Keep in mind, some of this block is also configurable at the domain level, and another reason it needs to go through parts of the system. The other thing is, in 9693, reporting for this is much more detailed so you have more visibility.  
Tim Uzzanti
CEO
SmarterTools Inc.

Reply to Thread

Enter the verification text