LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
Search this Thread
Old 11-25-2012, 11:21 AM   #1
baldur2630
Member
 
Registered: Jan 2007
Location: Belgium
Distribution: CentOS & Ubuntu
Posts: 127

Rep: Reputation: 16
Does anyone know anything about these strange addresses?


I have several IP addresses which are persistently connecting to my mail server, but apparently not sending anything.

195.140.184.246 - duoquattuorsx.zeta.ec-cluster.com
195.140.184.245 - duoquattuorquinque.zeta.ec-cluster.com
195.140.184.248 - duoquattuorocto.zeta.ec-cluster.com

In spite of the Italian names, the IP's are in Germany.

I get very worried when strange IP's connect to my mail server for no apparent reason. I get this :-
10:28:40 415 DMN: MSG 4730 Accepted connection: [195.140.184.246] (duoquattuorsx.zeta.ec-cluster.com)
10:28:40 415 DMN: MSG 4730 SMTP session ended: [195.140.184.246] (duoquattuorsx.zeta.ec-cluster.com)

The IP's change - today I had all three 7 times in total.

Anyone have any ideas, or should I just kill them on the Firewall?
 
Old 11-26-2012, 06:28 AM   #2
Velotrol
LQ Newbie
 
Registered: Apr 2011
Location: Rio, Brazil
Distribution: Gentoo
Posts: 15

Rep: Reputation: Disabled
Probably some bot trying to send spam using your SMTP server. If that's true, you probably should kill 'em on firewall or configure your SMTP server for refuse unauthorized connections.
 
Old 11-26-2012, 09:40 AM   #3
Habitual
Senior Member
 
Registered: Jan 2011
Distribution: Undecided
Posts: 3,470
Blog Entries: 6

Rep: Reputation: Disabled
https://b.kentbackman.com/2011/05/08...grade-malmail/
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Dropping Internet connectin/strange ip addresses? M$ISBS Linux - Networking 6 10-17-2010 07:54 PM
Binding 2 NICs (MAC addresses) to 2 IP Addresses in same Subnet RedHat EL4.0 skhira Linux - Networking 13 02-24-2008 08:16 PM
Binding 2 NICs (MAC addresses) to 2 IP Addresses in same Subnet RedHat EL4.0 skhira Linux - Networking 1 02-09-2008 07:17 AM
mechanics of mapping process memory addresses to physical addresses on amd64 Tischbein Linux - Kernel 2 02-01-2007 08:09 PM


All times are GMT -5. The time now is 06:23 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration