[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-security] Port Sentry Alert



its just someone probing port 995 or someone trying to download their mail
securely.
could be an incorrectly configured mail client. i wouldnt worry about it.

its used for secure POP3 so make of it what you will.

the "tcp pop3 protocol over TLS/SSL (was spop3)"
is just a description of what the port does.

do you use that port and offer secure pop3 ?

----- Original Message -----
From: "Kameel" <kameel@xxxxxxxxxxxxxxx>
To: <cobalt-security@xxxxxxxxxxxxxxx>
Sent: Wednesday, September 11, 2002 5:33 AM
Subject: [cobalt-security] Port Sentry Alert


> Heya,
>
> I've had several port sentry alerts from this IP.
> I don't understand what it means by "tcp pop3 protocol over TLS/SSL (was
> spop3)" or if this is a threat ?
>
> Can someone please let me know how significant (if at all) this is ?
>
> Thanks,
> Kam (the paranoid).
>
>
> Portsentry had an alert to <my domain> from the following IP address and
port:
> 61.1.60.156 995
>
> Service:
> pop3s 995/tcp pop3 protocol over TLS/SSL (was spop3)
> pop3s 995/udp pop3 protocol over TLS/SSL (was spop3)
>