D&C Lug - Home Page
Devon & Cornwall Linux Users' Group

[ Date Index ][ Thread Index ]
[ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] Question for your web servers firewall logs



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Monday 10 February 2003 4:40 pm, Theo Zourzouvillys wrote:
> (i'll forget otherwise, for sure) ;)

Am amazing achivment - i didn't forget ;)

The good news, or bad, depening on what your problem is, is there are the 
entries collected from all our firewalls....

SRC=210.73.52.10
SRC=210.73.52.10
SRC=210.73.52.10
SRC=210.73.52.10
SRC=218.29.92.140
SRC=218.29.92.140
SRC=218.29.92.140

supprise supprise, those IP addresses are all from china... so my guess is 
just scans for open SMTP servers rather than a misguided attempt to use an A 
record for a domain.  either that, or dodgy spamming software ;)


SRC=212.27.194.146
SRC=212.27.194.146
SRC=212.27.194.146
SRC=212.27.194.146
SRC=212.27.194.146
SRC=212.27.194.146
SRC=212.27.194.146
SRC=212.27.194.146
SRC=212.27.194.146

this one is from an isp in prauge, but ...

none of those IP addresses have ssent any mail throughany of our mail boxes 
since 6am yesterday, either, so it is almost certianly just open relay 
scanning.

hope that helps ;)

 ~ Theo


- -- 
Theo Zourzouvillys
<theo@xxxxxxxxxxxxxxxx>
<http://theo.me.uk/>




-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQE+SO6D448CrwpTn6YRAgtPAKDQ0FKasdYDspvWCq/4eZDxn8NKSgCfZ47a
eIO9H9fF0xIVFj19oDkkhWA=
=oGc2
-----END PGP SIGNATURE-----


--
The Mailing List for the Devon & Cornwall LUG
Mail majordomo@xxxxxxxxxxxx with "unsubscribe list" in the
message body to unsubscribe.


Lynx friendly