Educause Security Discussion mailing list archives

Re: Compromise Email Accounts


From: Russell Fulton <r.fulton () AUCKLAND AC NZ>
Date: Tue, 3 Feb 2009 20:35:35 +1300


On 31/01/2009, at 5:23 AM, Joe Vieira wrote:

Currently we have a python script to detect compromised accounts(runs
once an hour). it runs thru postfix logs looking for bounces, and at a
certain threshold will lock out your account.

Basically the idea is that, NO ONE actually generates 100+ bounces in
one hour, and if they do, they are probably spamming people.

BIngo!  why didn't I think of that!

Will modify my script to do that and see how it goes...

Thanks, Russell


Attachment: smime.p7s
Description:


Current thread: