#infosec How to block an ongoing dictionary attack / brute force attack against Windows Servers, #MSexchange and more

Syspeace - intrusion prevention for Windows servers

Syspeace website

How to block an intrusion attack against Windows Servers for free

If your server or datacenter is targeted by a brute force attack a.k.a dicttionary attacks , it might be hard to figure out how to quickly make it stop.
If the attack is from a single IP address you’d probably block it in your external firewall or the Windows Server firewall and after that start tracking and reporting the attack to see if needs following up.
However, if the attacks is triggered from hundreds or even thousands of IP addresses, it will become basically impossible to block all of them in the firewall so you need something to help you automate the task.

This is where Syspeace comes into play.

Fully functional, free trial for bruteforce prevention

Since Syspeace has a fully functional trial for 30 days, you can simply download it here ,install, regsiter with  a valid mail address, enter the licensekey into the Syspeace GUI and the attack will be automatically handled (blocked, tracked and reported) as soon as the Syspeace service starts up.

In essence, the attack will be blocked within minutes from even connecting to your server.

The entire process of downloading, installing and registering ususally only takes a few minutes and since Syspeace is a Windows service it will also automatically start if the server is rebooted.

If the attack is triggered to use just a few login attempts per attacking IP address and for a longer period of time in between attempts, I’d suggest you change te default rule to monitor for failed logins for a longer triggerwindow , for example 4 days so you’d also automatically detect hacking attempts that are trying to stay under the radar for countermeasure such as Syspeace.

The Syspeace Global BlackList

Since Syspeace has already blocked over 3.6 Million attacks worldwide , we’ve also got a Global Blacklist that is automatically downloaded to all other Syspeace clients.

This means that if an IP address has been deemed a repeat offender (meaning that it has attacked X number of Syspeace customers and Y number of servers within Z amount of tme), the attackers IP address is quite likely to already be in the GBL and therefore it will be automatically blacklisted on all Syspeace-installations, thus making it preemptively blocked.

Syspeace does not simmply disable the login for the attacker, it completely blocks the attacker on all ports from communicating with your server so if you’ve got otther services also running on the server (such as an FTP or SQL Server) the attacker will not be able to reach any if those services either. The lockdown is on all TCP ports.

More Syspeace features, supported Windows Server editions and other services such as Exchange Server, Terminal Server, SQL Server …

You will also get tracking and reporting included immediately for future reference or forensics.
Syspeace supports Windows Server editions from Windows 2003 and upwards, including the Small Business Server editions. It also supports Terminal Server (RDS) and RemoteAPP and RDWeb, Microsoft Exchange Serevr including the webmail (OWA) , Citrix, Sharepoint,
SQL Server and we’ve also released public APIs to use with various weblogins. All of this is included in Syspeace. Out of the box.
We’ve got a IIS FTP server detector in beta and also a FileZilla FTP Server detector and we’re constantly developing new detectors for various server software.

Download and try out Syspeace completely free

Even if you’re not being attacked by a large brute force attack right now, you can still download the trial and have Syspeace handle attacks for you in the background. Who knows, there could be more invalid login attemtpts than you think, such as disabled or removed users that have left the company or very subtle, slow dictioanry attacks going on in the background that actaully might be quite tricky to spot if your not  constantly monitoring logfles.

On this blog, http://syspeace.wordpress.com ,we’ve written a lot of blog articles on how Syspeace works and a lot of other articles regarding securing your servers that we hope you’ll find useful.

Tha brand new Syspeace website – now also with worldwide hacking statistics

Finally, the new website is up!

We’ve launched our new website a few weeks back and some of the news, apart from a better design and easier naviagtion, is that we’ve also included a security status page to display statistics based on Syspeace installations that report each hacker attack around the world.

Have a look for yourself at http://www.syspeace.com/security-center/security-status/ . You might find something interesting in there.

The statistis are dfivided into to two columns. The originating country for the attack and the country from where the Syspeace installation reported the attack.

The statistiscs displayed are the last 30 days of hacking attacks and so far Syspeace has blocked more than 1.4 Million brute force and dictionary attacks against Windows server worldwide!

While you’re at the website, download a free, fully functional trial to ptotect your Windows servers, Exchange servers, Terminal / Remore Desktop Services servers, Citrix servers, Sharepoint serevrs, SQL servers and more from brute force and dictioanry attacks.

Syspeace supports Windows Server 2003, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012 and the Windows Server Small Business editions.

By Juha Jurvanen

Syspeace license password reset

Hi, all.

As all of you know, we put a lot of effort and work into getting various features and improvements in place to help you protect your Windows 2003/2008/2008R2 and the Windows Server 2012 support coming up , Terminal Servers, Sharepoint Servers, Citrix Servers, Exchange Servers and so on.

We’re just so into making Syspeace the nr 1 product for intrusion prevention for Windows servers and a natural part of any Windows servers baseline security so that’s where our main focus is.

From time to time, our administrative efforts get left behind.

One of the most common questions , acually by far the most common question, emailed to our support is that when you wanted to buy a license for Syspeace, you’d forgotten your password and we provided you with a password reset link manually.
From one point of view, we’re happy to talk to you guys and help you out but of course, a password reset thing should be automated to help you get your licenses as soon as possible.

So, finally, we’ve now implemented a ”Password reset” feature on the licensing page. Simply fill in the emailaddress you used when you registered and a password reset link will be emailed to you.

We’ve also got the instructions more clearly into the email you receive when you buy a license that you actually won’t have to do anything.

The trial license you’re running will be automatically verified as a valid, live license the next time your Syspeace contacts the license server.

So, in short, you won’t have to wait for a license number to be sent to you since you’ve already got it.

PS. As a heads up, we’ll be releasing the SQL Server support and we’re also working on a GUI feature to easily sort, search, find and export various reports to CSV files D.S.

by Juha Jurvanen