How do I prevent IMAP attacks
Usually IMAP attacks occur over 143 TCP (IMAP) and 443 TCP (API, HTTPS).Â
The following steps may prevent such an attack:. Â
Block the offending IP(s) at the site's network firewall/router. Â The drawback to this would be the attacker coming from another IP.
Create access rules at the network firewall/router to allow only specific IPs to pass. Â
Create a block rule for all other IPs. Â
If there are remote users connection from home or roaming, they'll likely have dynamic IPs (changing IPs). Â The way around this is to have the remote user connect to the office VPN, then they'll be able to access internal servers such as the PBX.
On the PBX, go to Server -> Access Controls. Â Use the same idea as the network firewall/router. Â Create rules to allow specific remote users or outside SIP providers. Â
Uncheck IMAP, both APIs, and Web Admin for the All Networks rule.