[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[cobalt-security] Newbie question again...getting paranoid with spam :>
- Subject: [cobalt-security] Newbie question again...getting paranoid with spam :>
- From: "Render-Vue" <sales@xxxxxxxxxxxxxx>
- Date: Wed, 15 Aug 2001 19:36:45 +1200
- List-id: Mailing list for users to address network security on Cobalt products. <cobalt-security.list.cobalt.com>
Hi yah :>
Can someone tell me if I should be worried about this...after checking the
logs for spam attempts, I've noticed that every 15 minutes the following
happens.
/var/log/messages:-
Aug 14 22:45:01 ns proftpd[29365]: ns.websitedesign-websitehosting.com
(localhost[127.0.0.1]) - FTP session closed.
/var/log/maillog:-
Aug 14 22:45:03 ns imapd[29366]: imap service init from 127.0.0.1
Aug 14 22:45:03 ns imapd[29366]: Login failure user=Active_Monitor_69
host=localhost [127.0.0.1]
Aug 14 22:45:06 ns imapd[29366]: Command stream end of file, while reading
line user=Active_Monitor_69 host=localhost [127.0.0.1]
Aug 14 22:45:06 ns sendmail[29368]: NOQUEUE: Null connection from localhost
[127.0.0.1]
Aug 14 22:45:06 ns in.qpopper[29367]: EOF from Active_Monitor_69 at
127.0.0.1 (localhost): [0] 2 (No such file or directory); 0 (Success)
Aug 14 22:45:06 ns in.qpopper[29367]: Active_Monitor_69 at localhost
(127.0.0.1): -ERR POP EOF or I/O Error: 2 (No such file or directory); 0
(Success)
Is this a case of someone trying to hack in or has it something to do with
the amount of time specified in the relay window following a successful pop.
One of our customers who have a DSL connection and router are connecting at
the same time checking there various pop3 accounts
Many thanks in advance
Chae