Index: [Article Count Order] [Thread]

Date:  Mon, 28 Jan 2008 00:22:18 -0600
From:  "Brian Santee" <b.santee (at mark) visions-online.com>
Subject:  [coba-e:11813] Re: POP3 DOS attack
To:  <coba-e (at mark) bluequartz.org>
Message-Id:  <200801280622.m0S6MZgD021387 (at mark) vv2.visions-online.com>
In-Reply-To:  <479A6DC5.1020404 (at mark) theanchoragesylvania.com>
X-Mail-Count: 11813

I installed the dfix.hs tonight, is this normal output (getting this every
minute by e-mail):

/etc/cron.minutely/dfix.sh:

iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
Warning: Blocking 125.24.107.46
Jan 27 23:34:10 vv2 sendmail[9201]: m0S5XBFH009201:
125-24-107-46.adsl.totbb.net [125.24.107.46] did not issue
MAIL/EXPN/VRFY/ETRN during connection to MTA Jan 27 23:34:10 vv2
sendmail[9202]: m0S5XBWx009202: 125-24-107-46.adsl.totbb.net [125.24.107.46]
did not issue MAIL/EXPN/VRFY/ETRN during connection to MTA Jan 27 23:34:10
vv2 sendmail[9203]: m0S5XBS3009203: 125-24-107-46.adsl.totbb.net
[125.24.107.46] did not issue MAIL/EXPN/VRFY/ETRN during connection to MTA
Jan 27 23:34:10 vv2 sendmail[9204]: m0S5XBLu009204:
125-24-107-46.adsl.totbb.net [125.24.107.46] did not issue
MAIL/EXPN/VRFY/ETRN during connection to MTA Jan 27 23:35:18 vv2
sendmail[9373]: m0S5YIsY009373: 125-24-107-46.adsl.totbb.net [125.24.107.46]
did not issue MAIL/EXPN/VRFY/ETRN during connection to MTA Jan 27 23:35:18
vv2 sendmail[9370]: m0S5YIQx009370: 125-24-107-46.adsl.totbb.net
[125.24.107.46] did not issue MAIL/EXPN/VRFY/ETRN during connection to MTA
Jan 27 23:35:18 vv2 sendmail[9371]: m0S5YIIt009371:
125-24-107-46.adsl.totbb.net [125.24.107.46] did not issue
MAIL/EXPN/VRFY/ETRN during connection to MTA Jan 27 23:35:18 vv2
sendmail[9372]: m0S5YIYJ009372: 125-24-107-46.adsl.totbb.net [125.24.107.46]
did not issue MAIL/EXPN/VRFY/ETRN during connection to MTA
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
Warning: Blocking 61.6.198.190
Jan 27 23:41:07 vv2 sendmail[11016]: m0S5ero8011016: from=<jquan (at mark) du.edu>,
size=4388, class=0, nrcpts=1, msgid=<30fe01c8607a$7416ff80$c0a80164@Noelle>,
proto=SMTP, daemon=MTA, relay=[61.6.198.190] Jan 27 23:41:09 vv2
sendmail[11022]: m0S5esdv011022: from=<jquan (at mark) du.edu>, size=4417, class=0,
nrcpts=1, msgid=<310201c8607a$74d80590$c0a80164@Noelle>, proto=SMTP,
daemon=MTA, relay=[61.6.198.190] Jan 27 23:41:50 vv2 sendmail[11234]:
m0S5fo0r011234: [61.6.198.190] did not issue MAIL/EXPN/VRFY/ETRN during
connection to MTA Jan 27 23:41:57 vv2 sendmail[11245]: m0S5fv2P011245:
[61.6.198.190] did not issue MAIL/EXPN/VRFY/ETRN during connection to MTA
Jan 27 23:42:21 vv2 sendmail[11400]: m0S5gK89011400: [61.6.198.190] did not
issue MAIL/EXPN/VRFY/ETRN during connection to MTA Jan 27 23:42:21 vv2
sendmail[11402]: m0S5gLd7011402: [61.6.198.190] did not issue
MAIL/EXPN/VRFY/ETRN during connection to MTA Jan 27 23:42:29 vv2
sendmail[11415]: m0S5gThg011415: [61.6.198.190] did not issue
MAIL/EXPN/VRFY/ETRN during connection to MTA Jan 27 23:42:31 vv2
sendmail[11424]: m0S5gVQN011424: [61.6.198.190] did not issue
MAIL/EXPN/VRFY/ETRN during connection to MTA Jan 27 23:42:39 vv2
sendmail[11438]: m0S5gdFl011438: [61.6.198.190] did not issue
MAIL/EXPN/VRFY/ETRN during connection to MTA Jan 27 23:43:00 vv2
sendmail[11487]: m0S5h0VI011487: [61.6.198.190] did not issue
MAIL/EXPN/VRFY/ETRN during connection to MTA Jan 27 23:43:46 vv2
sendmail[11677]: m0S5hjAP011677: [61.6.198.190] did not issue
MAIL/EXPN/VRFY/ETRN during connection to MTA Jan 27 23:44:23 vv2
sendmail[11029]: m0S5f0Vt011029: from=<jquan (at mark) du.edu>, size=4297, class=0,
nrcpts=1, msgid=<31c501c8607a$b0e9fb60$c0a80164@Noelle>, proto=SMTP,
daemon=MTA, relay=[61.6.198.190] Jan 27 23:44:45 vv2 sendmail[11915]:
m0S5iiZc011915: [61.6.198.190] did not issue MAIL/EXPN/VRFY/ETRN during
connection to MTA Jan 27 23:45:06 vv2 sendmail[12185]: m0S5j6Lm012185:
[61.6.198.190] did not issue MAIL/EXPN/VRFY/ETRN during connection to MTA
Jan 27 23:45:22 vv2 sendmail[12312]: m0S5jLDs012312: [61.6.198.190] did not
issue MAIL/EXPN/VRFY/ETRN during connection to MTA Jan 27 23:45:30 vv2
sendmail[12344]: m0S5jUH6012344: [61.6.198.190] did not issue
MAIL/EXPN/VRFY/ETRN during connection to MTA