Re: Strange sockstat entries

"John Levine" <[email protected]>
Newsgroups gmane.os.freebsd.questions
Organization Taughannock Networks
Message-ID <[email protected]>
It appears that Doug Hardie <[email protected]> said:
>I am seeing a number of unusual sockstat entries that look like:
>
>??       ??            ??    ?? tcp4    10.0.1.230:587        178.16.54.22:63001
>
>The occur at the end of the output.  Often there are about 10 or so entries.  Most of them vanish after a few seconds.  However, two are quite persistent.  What
>causes this type of entry?

Port 587 is mail submission, so that's a spambot trying to break into your mail server.

I see lots of them on my submission server.  Unless you have usernames and passwords that are trivially guessable,
they shouldn't be a problem.

I also see them on port 25 so I added a feature to my mail server so that AUTH on port 25 always succeeds, and
it puts the mail they try to send into the spam trap.  I get far more of those.

-- 
Regards,
John Levine, [email protected], Primary Perpetrator of "The Internet for Dummies",
Please consider the environment before reading this e-mail. https://jl.ly
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.