[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-security] (no subject)



Just started seeing lot's of these entries in syslog:

Apr 20 23:15:01 www proftpd[5807]: www.xxx-xxxx.com (localhost[127.0.0.1]) -
no
such user 'anonymous'
Apr 20 23:15:01 www proftpd[5807]: www.xxx-xxxx.com (localhost[127.0.0.1]) -
no
such user 'anonymous'
Apr 20 23:15:01 www proftpd[5807]: www.xxx-xxxx.com (localhost[127.0.0.1]) -
FTP
session closed.

Any idea what might be doing this?

Also, PortSentry reports lots of Port 137 scans?

Any ideas greatly appreciated.

TD
td@xxxxxxxx