<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="http://syndication.webwiz.co.uk/rss_namespace/">
 <channel>
  <title>Spam Filter ISP Forums : SMTPAUTH HACKED</title>
  <link>https://www.logsat.com/spamfilter/forums/</link>
  <description><![CDATA[This is an XML content feed of; Spam Filter ISP Forums : Spam Filter ISP Support : SMTPAUTH HACKED]]></description>
  <pubDate>Wed, 10 Jun 2026 14:37:00 +0000</pubDate>
  <lastBuildDate>Wed, 07 May 2014 17:24:44 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 11.04</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://www.logsat.com/spamfilter/forums/RSS_post_feed.asp?TID=7077</WebWizForums:feedURL>
  <image>
   <title><![CDATA[Spam Filter ISP Forums]]></title>
   <url>https://www.logsat.com/spamfilter/forums/forum_images/web_wiz_forums.png</url>
   <link>https://www.logsat.com/spamfilter/forums/</link>
  </image>
  <item>
   <title><![CDATA[SMTPAUTH HACKED : Would be good to have some limits...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7077&amp;PID=14603&amp;title=smtpauth-hacked#14603</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=102">WebGuyz</a><br /><strong>Subject:</strong> 7077<br /><strong>Posted:</strong> 07 May 2014 at 5:24pm<br /><br />Would be good to have some limits but doesn't help a lot if it starts at 2am and you wake up to find yahoo.com and gmail.com will no longer accept emails from you because of the thousands of spams that been pushed.<br /><br />Been working on a more automated solution since a lot of these attacks occur in the wee hours of the morning.<br /><br />Have a vb script that runs continuously in a loop with a 60 second delay. It reads in the SFI log file and uses Dictionary component to keep track of IP's and Senders addresses and number of emails sent.<br /><br />If a user sends more then 150 emails in 1 minute we read in the password file and remove the authenticated email address.<br /><br />We then use MS firewall CLI commands in our script to block that IP immediately. These 2 steps nip the spamming in the bud. if a valid customer happens to send more then 150 emails in 1 minute then we just apologize and unblock his IP and add his email address back in the password file.<br /><br />The speed in which spammers can pump out spam is incredible and manual methods are too slow. <br /><br />if you could find a way to automatically limit an IP when it get detected sending thousands of emails in a short period then the world would beat a path to your door  :-)]]>
   </description>
   <pubDate>Wed, 07 May 2014 17:24:44 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7077&amp;PID=14603&amp;title=smtpauth-hacked#14603</guid>
  </item> 
  <item>
   <title><![CDATA[SMTPAUTH HACKED : You can see what sessions are...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7077&amp;PID=14602&amp;title=smtpauth-hacked#14602</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 7077<br /><strong>Posted:</strong> 07 May 2014 at 5:01pm<br /><br />You can see what sessions are active from the "Connections" tab in SpamFilter. From there clicking on the "X" on the last column ("Kill") will disconnect that session immediately.<div><br></div><div>There are currently no parameters to limit the number of emails an authenticated user can send. You have a very valid argument for adding an option to impose a limit - we'll work on this shortly.</div><div><br></div><div>FYI if you don't see entries in the "Connections" tab make sure the "Disable Conns Grid" option under the main Settings-Configuration tab is not checked.</div>]]>
   </description>
   <pubDate>Wed, 07 May 2014 17:01:49 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7077&amp;PID=14602&amp;title=smtpauth-hacked#14602</guid>
  </item> 
  <item>
   <title><![CDATA[SMTPAUTH HACKED : Is there any way to kill a session...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7077&amp;PID=14601&amp;title=smtpauth-hacked#14601</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=102">WebGuyz</a><br /><strong>Subject:</strong> 7077<br /><strong>Posted:</strong> 07 May 2014 at 7:30am<br /><br />Is there any way to kill a session short of restarting SFI?  What settings in global options would force these type spam attacks to have to authenticate more often.<br /><br />We monitor the SFI log and if we see anyone sending more then 100 emails in 2 minutes we remove that email address from the auth password file, but in a case like this a lot of spam would still would get thru. We need to have them try to authenticate more frequently so they would stopped.<br /><br /><br /><br />]]>
   </description>
   <pubDate>Wed, 07 May 2014 07:30:37 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7077&amp;PID=14601&amp;title=smtpauth-hacked#14601</guid>
  </item> 
  <item>
   <title><![CDATA[SMTPAUTH HACKED : No issues had been found. A user...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7077&amp;PID=14598&amp;title=smtpauth-hacked#14598</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 7077<br /><strong>Posted:</strong> 05 May 2014 at 12:30pm<br /><br />No issues had been found. A user appeared to have their SMTP password compromised, and a spammer was using that account to relay email. They kept an open/connected SMTP session which was using to send the spam. Deleting the user from the Unix passed file will prevent the user from performing further SMTP AUTH logins, but the <i>current</i>&nbsp;SMTP session is not disconnected, so they kept spamming for a while. There were also tens of thousands of emails in the SpamFilter queue, so the outbound traffic actually continued (emptying the queue) even after the spammer was unable to login any further.]]>
   </description>
   <pubDate>Mon, 05 May 2014 12:30:57 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7077&amp;PID=14598&amp;title=smtpauth-hacked#14598</guid>
  </item> 
  <item>
   <title><![CDATA[SMTPAUTH HACKED : Was there any resolution to this....]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7077&amp;PID=14597&amp;title=smtpauth-hacked#14597</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=102">WebGuyz</a><br /><strong>Subject:</strong> 7077<br /><strong>Posted:</strong> 05 May 2014 at 11:44am<br /><br />Was there any resolution to this. We use Unix SMTP Auth and are interested if there is any problem with it.]]>
   </description>
   <pubDate>Mon, 05 May 2014 11:44:36 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7077&amp;PID=14597&amp;title=smtpauth-hacked#14597</guid>
  </item> 
  <item>
   <title><![CDATA[SMTPAUTH HACKED : Sure - I had sent you a private...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7077&amp;PID=14582&amp;title=smtpauth-hacked#14582</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 7077<br /><strong>Posted:</strong> 02 April 2014 at 12:30pm<br /><br />Sure - I had sent you a private message on the forum a few days ago with the password and URL for our cloud area. I just re-sent it to you. If you check your profile here on the form account you should be able to see the PM notifications.]]>
   </description>
   <pubDate>Wed, 02 Apr 2014 12:30:26 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7077&amp;PID=14582&amp;title=smtpauth-hacked#14582</guid>
  </item> 
  <item>
   <title><![CDATA[SMTPAUTH HACKED : Sorry,the file dimension is too...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7077&amp;PID=14581&amp;title=smtpauth-hacked#14581</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=833">alfaproject</a><br /><strong>Subject:</strong> 7077<br /><strong>Posted:</strong> 02 April 2014 at 11:29am<br /><br />Sorry,<div><br></div><div>the file dimension is too big to send you by email.</div><div><br></div><div>Could I put it on your cloud folder?</div><div>Please, could you give me access credentials?</div><div><br></div><div>Thnaks.</div><div>Regards.</div>]]>
   </description>
   <pubDate>Wed, 02 Apr 2014 11:29:08 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7077&amp;PID=14581&amp;title=smtpauth-hacked#14581</guid>
  </item> 
  <item>
   <title><![CDATA[SMTPAUTH HACKED : Hi,I&amp;#039;m mailing you the wireskark...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7077&amp;PID=14580&amp;title=smtpauth-hacked#14580</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=833">alfaproject</a><br /><strong>Subject:</strong> 7077<br /><strong>Posted:</strong> 02 April 2014 at 11:25am<br /><br />Hi,<div><br></div><div>I'm mailing you the wireskark report.</div><div>It seems there is nothing strange in it.</div><div><br></div><div>Please, tell me if you need other details.</div><div><br></div><div>Many thanks.</div><div>Regards.</div>]]>
   </description>
   <pubDate>Wed, 02 Apr 2014 11:25:33 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7077&amp;PID=14580&amp;title=smtpauth-hacked#14580</guid>
  </item> 
  <item>
   <title><![CDATA[SMTPAUTH HACKED : We&amp;#039;ve confirmed that the...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7077&amp;PID=14579&amp;title=smtpauth-hacked#14579</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 7077<br /><strong>Posted:</strong> 31 March 2014 at 7:46pm<br /><br />We've confirmed that the users who login with SMTP AUTH will be whitelisted bypassing any BL IP checking.]]>
   </description>
   <pubDate>Mon, 31 Mar 2014 19:46:07 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7077&amp;PID=14579&amp;title=smtpauth-hacked#14579</guid>
  </item> 
  <item>
   <title><![CDATA[SMTPAUTH HACKED : SMTP AUTH is one of the commands...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7077&amp;PID=14578&amp;title=smtpauth-hacked#14578</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 7077<br /><strong>Posted:</strong> 31 March 2014 at 2:02pm<br /><br />SMTP AUTH is one of the commands that can be transmitted over SMTP, so there are no configuration settings like timeouts or SSL that can be configured just for that.&nbsp;<div><br></div><div>SSL can certainly be enabled for SpamFilter, but you would not be able for example to force SMTP AUTH to use the SSL port you configured. SMTP AUTH would still be available on the non-SSL port.</div><div><br></div><div>I'll update the post shortly to confirm or not whether the SMTP AUTH whitelisting will bypass the BL IP checking - I'm not certain at the moment without testing this in the lab. This has never been an issue in the past so it's not a common question.</div><div><br></div><div>We'll wait for your debug report as I'm hoping it will have the info we need to determine what is happening.</div>]]>
   </description>
   <pubDate>Mon, 31 Mar 2014 14:02:50 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7077&amp;PID=14578&amp;title=smtpauth-hacked#14578</guid>
  </item> 
 </channel>
</rss>