[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-security] Newbie question again...getting paranoid with spam :>



Hi yah :>

Can someone tell me if I should be worried about this...after checking the
logs for spam attempts, I've noticed that every 15 minutes the following
happens.

/var/log/messages:-

Aug 14 22:45:01 ns proftpd[29365]: ns.websitedesign-websitehosting.com
(localhost[127.0.0.1]) - FTP session closed.

/var/log/maillog:-

Aug 14 22:45:03 ns imapd[29366]: imap service init from 127.0.0.1
Aug 14 22:45:03 ns imapd[29366]: Login failure user=Active_Monitor_69
host=localhost [127.0.0.1]
Aug 14 22:45:06 ns imapd[29366]: Command stream end of file, while reading
line user=Active_Monitor_69 host=localhost [127.0.0.1]
Aug 14 22:45:06 ns sendmail[29368]: NOQUEUE: Null connection from localhost
[127.0.0.1]
Aug 14 22:45:06 ns in.qpopper[29367]: EOF from Active_Monitor_69 at
127.0.0.1 (localhost): [0] 2 (No such file or directory); 0 (Success)
Aug 14 22:45:06 ns in.qpopper[29367]: Active_Monitor_69 at localhost
(127.0.0.1): -ERR POP EOF or I/O Error: 2 (No such file or directory); 0
(Success)

Is this a case of someone trying to hack in or has it something to do with
the amount of time specified in the relay window following a successful pop.
One of our customers who have a DSL connection and router are connecting at
the same time checking there various pop3 accounts

Many thanks in advance

Chae