I wrote my own snort rule to detect and block brute forcing and sending spam through the web mail (It will only block if you have snortsam properly setup). This rule blocks anyone that does an HTTP POST more than 20 times within 10 seconds (I believe it is a ratio – average of 2 times per second).
HINT: Replace X.X.X.X with the IP of your web server. Take out the â€œfwsam: src, 5 minutes;â€ if you are not using snortsam (you should be ;p). Replace 123456789 with your own custom ID and make it large so it doesnâ€™t conflict with default snort rules.