Accounts Locked Out
Posted: Mon Apr 23, 2007 12:05 pm
Greetings,
I'm having a problem where random accounts are being locked out on a daily basis. At first I thought people were just being stupid all at the same time, but now I've ruled out that possibility. Among the list of people who are locked out are users that don't have a person that checks them, either because the account is there for the ability to send mail only, the person has all mail redirected to another account, and some even where the person doesn't even know that they have an email address yet (a newly hired employee had his account locked out before he even knew he had been hired).
These have been found by litterally going through and checking each account to see if they are locked out or not. Something, as you can imagine, that is very time consuming... but it has had to be done daily for the last two weeks so that people can get into their email properly.
My thought was that maybe when they login they were having problems and the website automatically retried the login, but then I realized that even if that happened once, it wouldn't happen 5 times (which my login failure count is 5 before being locked out). Then there is the accounts that don't have a person to login to them in the first place that have been locked out...
My next thought was that maybe it's someone trying to guess usernames and passwords, which I was starting to think was a real possibility, until there was the person who never even knew he had an account, therefore no mail had ever been sent out or received. The hacker would have had to guess his username to be able to try it, which wouldn't have been guessable as his last name is very not-normal.
The number of accounts seems to be going down slightly, but I'm not sure if that has any meaning... The first week there were about 10 accounts daily, last week 9 accounts daily, and today 8 accounts locked out.
So.. has anyone had any problems like this, or any ideas on where I should look to be able to find a reason as to why these accounts are being locked?
Also, due to my problems of not being able to get into the SAC reliably, this gets extra-annoying because if someone reports that their account is locked out, I either have to restart the scalix-tomcat service which kicks everyone out of their webmail, or I have to wait until morning (I added restarting the service to the nightly maintenance cycle), neither of which is acceptable, especially when the request comes in at 10am or so!
Thanks for your thoughts!
Mito
I'm having a problem where random accounts are being locked out on a daily basis. At first I thought people were just being stupid all at the same time, but now I've ruled out that possibility. Among the list of people who are locked out are users that don't have a person that checks them, either because the account is there for the ability to send mail only, the person has all mail redirected to another account, and some even where the person doesn't even know that they have an email address yet (a newly hired employee had his account locked out before he even knew he had been hired).
These have been found by litterally going through and checking each account to see if they are locked out or not. Something, as you can imagine, that is very time consuming... but it has had to be done daily for the last two weeks so that people can get into their email properly.
My thought was that maybe when they login they were having problems and the website automatically retried the login, but then I realized that even if that happened once, it wouldn't happen 5 times (which my login failure count is 5 before being locked out). Then there is the accounts that don't have a person to login to them in the first place that have been locked out...
My next thought was that maybe it's someone trying to guess usernames and passwords, which I was starting to think was a real possibility, until there was the person who never even knew he had an account, therefore no mail had ever been sent out or received. The hacker would have had to guess his username to be able to try it, which wouldn't have been guessable as his last name is very not-normal.
The number of accounts seems to be going down slightly, but I'm not sure if that has any meaning... The first week there were about 10 accounts daily, last week 9 accounts daily, and today 8 accounts locked out.
So.. has anyone had any problems like this, or any ideas on where I should look to be able to find a reason as to why these accounts are being locked?
Also, due to my problems of not being able to get into the SAC reliably, this gets extra-annoying because if someone reports that their account is locked out, I either have to restart the scalix-tomcat service which kicks everyone out of their webmail, or I have to wait until morning (I added restarting the service to the nightly maintenance cycle), neither of which is acceptable, especially when the request comes in at 10am or so!
Thanks for your thoughts!
Mito