Re: Strange sockstat entries
"John Levine" <[email protected]>
| Newsgroups | gmane.os.freebsd.questions |
|---|---|
| Organization | Taughannock Networks |
| Message-ID | <[email protected]> |
It appears that Doug Hardie <[email protected]> said: >I am seeing a number of unusual sockstat entries that look like: > >?? ?? ?? ?? tcp4 10.0.1.230:587 178.16.54.22:63001 > >The occur at the end of the output. Often there are about 10 or so entries. Most of them vanish after a few seconds. However, two are quite persistent. What >causes this type of entry? Port 587 is mail submission, so that's a spambot trying to break into your mail server. I see lots of them on my submission server. Unless you have usernames and passwords that are trivially guessable, they shouldn't be a problem. I also see them on port 25 so I added a feature to my mail server so that AUTH on port 25 always succeeds, and it puts the mail they try to send into the spam trap. I get far more of those. -- Regards, John Levine, [email protected], Primary Perpetrator of "The Internet for Dummies", Please consider the environment before reading this e-mail. https://jl.ly