This is the excerpt from our Administrative log from today - regarding the broken implementation of NTLMv1 hash checking versus the IpBruteForceDetector and what is happening to multiple of our users.
Someone REALLY needs to re-visit this because disabling or weakening the IDS rule to get around this is unacceptable - as that just leaves everything else open to "slow-rolling credential attacks".
12:46:28.257 [CUSTOMER_IP_REDACTED] IMAP Attempting to login user: [REDACTED]
12:46:28.257 [CUSTOMER_IP_REDACTED] IMAP Login successful: With user [REDACTED]
12:46:29.753 [CUSTOMER_IP_REDACTED] IMAP NTLM; AuthenticateMessage; User password too long for LMv1 authentication [HASH_REDACTED]
12:46:29.753 [CUSTOMER_IP_REDACTED] IMAP NtlmAuthenticate Login failed: NTLM; AuthenticateMessage; User password too long for LMv1 authentication.
Brute force attempts increased to 1 of 5 in 4320 minutes.
User brute force attempts increased to 10 of 20 in 360 minutes.
Next clean available at 3/11/2026 12:47:27 PM
12:46:30.353 [CUSTOMER_IP_REDACTED] IMAP NTLM; AuthenticateMessage; User password too long for LMv1 authentication [HASH_REDACTED]
12:46:30.353 [CUSTOMER_IP_REDACTED] IMAP NtlmAuthenticate False IDS counting for NTLM failures over IMAP at this IP is throttled.
12:47:42.546 [CUSTOMER_IP_REDACTED] User [REDACTED] calling patch message, owner: [REDACTED], count: 1, folder: Inbox
12:47:43.759 [CUSTOMER_IP_REDACTED] User [REDACTED] calling delete messages, folder: Inbox, owner: [REDACTED], all: , count: 1
12:51:59.020 [CUSTOMER_IP_REDACTED] User [REDACTED] calling patch message, owner: [REDACTED], count: 1, folder: Inbox
13:11:19.322 [CUSTOMER_IP_REDACTED] IMAP Attempting to login user: [REDACTED]
13:11:19.322 [CUSTOMER_IP_REDACTED] IMAP Login successful: With user [REDACTED]
13:16:59.917 [CUSTOMER_IP_REDACTED] IMAP NTLM; AuthenticateMessage; User password too long for LMv1 authentication [HASH_REDACTED]
13:16:59.917 [CUSTOMER_IP_REDACTED] IMAP NtlmAuthenticate Login failed: NTLM; AuthenticateMessage; User password too long for LMv1 authentication.
Brute force attempts increased to 2 of 5 in 4320 minutes.
User brute force attempts increased to 11 of 20 in 360 minutes.
Next clean available at 3/11/2026 1:17:59 PM
13:17:00.221 [CUSTOMER_IP_REDACTED] IMAP NTLM; AuthenticateMessage; User password too long for LMv1 authentication [HASH_REDACTED]
13:17:00.221 [CUSTOMER_IP_REDACTED] IMAP NtlmAuthenticate False IDS counting for NTLM failures over IMAP at this IP is throttled.
13:49:17.078 [CUSTOMER_IP_REDACTED] IMAP NTLM; AuthenticateMessage; User password too long for LMv1 authentication [HASH_REDACTED]
13:49:17.081 [CUSTOMER_IP_REDACTED] IMAP NtlmAuthenticate Login failed: NTLM; AuthenticateMessage; User password too long for LMv1 authentication.
Brute force attempts increased to 3 of 5 in 4320 minutes.
User brute force attempts increased to 12 of 20 in 360 minutes.
Next clean available at 3/11/2026 1:50:17 PM
13:49:18.618 [CUSTOMER_IP_REDACTED] IMAP NTLM; AuthenticateMessage; User password too long for LMv1 authentication [HASH_REDACTED]
13:49:18.618 [CUSTOMER_IP_REDACTED] IMAP NtlmAuthenticate False IDS counting for NTLM failures over IMAP at this IP is throttled.
13:49:19.972 [CUSTOMER_IP_REDACTED] IMAP Attempting to login user: [REDACTED]
13:49:19.972 [CUSTOMER_IP_REDACTED] IMAP Login successful: With user [REDACTED]
13:49:21.404 [CUSTOMER_IP_REDACTED] IMAP NTLM; AuthenticateMessage; User password too long for LMv1 authentication [HASH_REDACTED]
13:49:21.404 [CUSTOMER_IP_REDACTED] IMAP NtlmAuthenticate False IDS counting for NTLM failures over IMAP at this IP is throttled.
13:49:22.314 [CUSTOMER_IP_REDACTED] IMAP NTLM; AuthenticateMessage; User password too long for LMv1 authentication [HASH_REDACTED]
13:49:22.314 [CUSTOMER_IP_REDACTED] IMAP NtlmAuthenticate False IDS counting for NTLM failures over IMAP at this IP is throttled.
13:49:23.548 [CUSTOMER_IP_REDACTED] IMAP NTLM; AuthenticateMessage; User password too long for LMv1 authentication [HASH_REDACTED]
13:49:23.549 [CUSTOMER_IP_REDACTED] IMAP NtlmAuthenticate False IDS counting for NTLM failures over IMAP at this IP is throttled.
13:49:23.847 [CUSTOMER_IP_REDACTED] IMAP NTLM; AuthenticateMessage; User password too long for LMv1 authentication [HASH_REDACTED]
13:49:23.847 [CUSTOMER_IP_REDACTED] IMAP NtlmAuthenticate False IDS counting for NTLM failures over IMAP at this IP is throttled.
14:21:39.523 [CUSTOMER_IP_REDACTED] IMAP NTLM; AuthenticateMessage; User password too long for LMv1 authentication [HASH_REDACTED]
14:21:39.524 [CUSTOMER_IP_REDACTED] IMAP NtlmAuthenticate Login failed: NTLM; AuthenticateMessage; User password too long for LMv1 authentication.
14:21:39.903 [CUSTOMER_IP_REDACTED] IMAP NTLM; AuthenticateMessage; User password too long for LMv1 authentication [HASH_REDACTED]
14:21:39.903 [CUSTOMER_IP_REDACTED] IMAP NtlmAuthenticate False IDS counting for NTLM failures over IMAP at this IP is throttled.
Brute force attempts increased to 4 of 5 in 4320 minutes.
User brute force attempts increased to 13 of 20 in 360 minutes.
Next clean available at 3/11/2026 2:22:18 PM
14:21:40.395 [CUSTOMER_IP_REDACTED] IMAP Attempting to login user: [REDACTED]
14:21:40.395 [CUSTOMER_IP_REDACTED] IMAP Login successful: With user [REDACTED]
14:21:40.913 [CUSTOMER_IP_REDACTED] IMAP NTLM; AuthenticateMessage; User password too long for LMv1 authentication [HASH_REDACTED]
14:21:40.913 [CUSTOMER_IP_REDACTED] IMAP NtlmAuthenticate False IDS counting for NTLM failures over IMAP at this IP is throttled.
14:21:41.418 [CUSTOMER_IP_REDACTED] IMAP NTLM; AuthenticateMessage; User password too long for LMv1 authentication [HASH_REDACTED]
14:21:41.418 [CUSTOMER_IP_REDACTED] IMAP NtlmAuthenticate False IDS counting for NTLM failures over IMAP at this IP is throttled.
14:21:42.238 [CUSTOMER_IP_REDACTED] IMAP NTLM; AuthenticateMessage; User password too long for LMv1 authentication [HASH_REDACTED]
14:21:42.238 [CUSTOMER_IP_REDACTED] IMAP NtlmAuthenticate False IDS counting for NTLM failures over IMAP at this IP is throttled.
14:21:42.563 [CUSTOMER_IP_REDACTED] IMAP NTLM; AuthenticateMessage; User password too long for LMv1 authentication [HASH_REDACTED]
14:21:42.564 [CUSTOMER_IP_REDACTED] IMAP NtlmAuthenticate False IDS counting for NTLM failures over IMAP at this IP is throttled.
14:50:46.197 [CUSTOMER_IP_REDACTED] User [REDACTED] calling patch message, owner: [REDACTED], count: 1, folder: Inbox
14:50:50.367 [CUSTOMER_IP_REDACTED] User [REDACTED] calling patch message, owner: [REDACTED], count: 1, folder: Inbox
14:50:59.651 [CUSTOMER_IP_REDACTED] User [REDACTED] calling patch message, owner: [REDACTED], count: 1, folder: Inbox
14:51:28.456 [CUSTOMER_IP_REDACTED] User [REDACTED] calling send message, subject: [REDACTED]
14:51:36.533 [CUSTOMER_IP_REDACTED] User [REDACTED] calling patch message, owner: [REDACTED], count: 1, folder: Inbox
14:51:38.310 [CUSTOMER_IP_REDACTED] User [REDACTED] calling move messages, owner: [REDACTED], folder: Inbox, newOwner: [REDACTED], new folder: ACCOUNTING, count: 1
14:51:41.811 [CUSTOMER_IP_REDACTED] User [REDACTED] calling move messages, owner: [REDACTED], folder: Inbox, newOwner: [REDACTED], new folder: ACCOUNTING, count: 1
14:51:52.756 [CUSTOMER_IP_REDACTED] User [REDACTED] calling move messages, owner: [REDACTED], folder: Inbox, newOwner: [REDACTED], new folder: TIF, count: 1
14:53:54.302 [CUSTOMER_IP_REDACTED] IMAP Attempting to login user: [REDACTED]
14:53:54.302 [CUSTOMER_IP_REDACTED] IMAP Login successful: With user [REDACTED]
14:56:39.398 [CUSTOMER_IP_REDACTED] IMAP NTLM; AuthenticateMessage; User password too long for LMv1 authentication [HASH_REDACTED]
Brute force attempts increased to 5 of 5 in 4320 minutes.
User brute force attempts increased to 11 of 20 in 360 minutes.
Next clean available at 3/11/2026 2:57:32 PM
14:56:39.399 [IpBruteForceDetector] [CUSTOMER_IP_REDACTED] Added to IDS block list for violating rule Type: Password Brute Force by IP, Description: Default Brute Force by IP rule
14:56:39.403 [IpBruteForceDetector] Added 2603:6013:f140:2:bc08:a346:4c6c:e1d1 to IDS block list. Duration: 604799.9950725 seconds, Description: Default Brute Force by IP rule
14:56:39.404 [CUSTOMER_IP_REDACTED] IMAP NtlmAuthenticate Login failed: NTLM; AuthenticateMessage; User password too long for LMv1 authentication.
14:57:04.699 [CUSTOMER_IP_REDACTED] User [REDACTED] calling send message, subject: [REDACTED]
14:57:12.789 [CUSTOMER_IP_REDACTED] User [REDACTED] calling patch message, owner: [REDACTED], count: 1, folder: Inbox
14:57:16.784 [CUSTOMER_IP_REDACTED] User [REDACTED] calling patch message, owner: [REDACTED], count: 1, folder: Inbox
Additionally, as requested in other threads, if something such as an authentication protocol can be listed as a capability of a mail server (such as "AUTH-NTLM") - then it should have the ability to be turned off.
response: * CAPABILITY IMAP4rev1 AUTH=CRAM-MD5 AUTH=NTLM AUTH=PLAIN SASL-IR UTF8=ACCEPT UIDPLUS QUOTA MOVE XLIST CHILDREN ENABLE CONDSTORE X-SM-TAGS