hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Dedicated Server : PortSentry/LogSentry
Reply

Dedicated Server Current and past experiences with dedicated server providers, bandwidth, and server performance. Review managed and unmanaged dedicated web servers, discuss both Windows and Unix dedicated server solutions, and discuss dedicated hosting providers. If your service is unavailable, please click here.
Forum Jump

PortSentry/LogSentry

Reply Post New Thread In Dedicated Server Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 11-26-2002, 01:35 PM
yellowdefend yellowdefend is offline
Newbie
 
Join Date: Nov 2002
Location: Stafford (Houston) TX
Posts: 6
*

PortSentry/LogSentry


I had recently installed PortSentry/LogSentry on our XTR by the company I purchased the RAQ from.

Not knowing the full details of the e-mails received I searched the sites and found nothing on it.

About every 15 min I get the following Msg:

Security Violations
=-=-=-=-=-=-=-=-=-=
Nov 26 08:30:00 www cced(smd)[21844]: client [0:21842] has admin rights Nov 26 08:30:05 www sendmail[21867]: NOQUEUE: localhost [127.0.0.1] did not issue MAIL/EXPN/VRFY/ETRN during connection to MTA

Unusual System Events
=-=-=-=-=-=-=-=-=-=-=
Nov 26 08:30:00 www cced(smd)[3453]: client connection accepted from [0:21842] Nov 26 08:30:00 www cced(smd)[21844]: client [0:21842] has admin rights Nov 26 08:30:03 www cced(smd)[21844]: client [0:21842] disconnected Nov 26 08:30:03 www proftpd[21845]: www.mydomain.com (localhost[127.0.0.1]) - FTP session opened.
Nov 26 08:30:03 www proftpd[21845]: www.mydomain.com (localhost[127.0.0.1]) - FTP session closed.
Nov 26 08:30:03 www in.proftpd[21845]: connect from 127.0.0.1 Nov 26 08:30:04 www imapd[21846]: connect from 127.0.0.1 Nov 26 08:30:05 www in.qpopper[21866]: connect from 127.0.0.1 Nov 26 08:22:01 www amavis[21508]: starting. amavis 0.3.12pre8 Tue Aug 13 12:31:02 EDT 2002 Nov 26 08:24:32 www amavis[21615]: starting. amavis 0.3.12pre8 Tue Aug 13 12:31:02 EDT 2002 Nov 26 08:30:04 www imapd[21846]: imap service init from 127.0.0.1 Nov 26 08:30:04 www imapd[21846]: Logout user=??? host=localhost [127.0.0.1] Nov 26 08:30:05 www sendmail[21867]: NOQUEUE: localhost [127.0.0.1] did not issue MAIL/EXPN/VRFY/ETRN during connection to MTA Nov 26 08:31:33 www amavis[21938]: starting. amavis 0.3.12pre8 Tue Aug 13 12:31:02 EDT 2002


I have been using the UI daily but not 24/7

Am I being hacked or is there a bug in the software.

Alan

Reply With Quote


Sponsored Links
  #2  
Old 11-29-2002, 01:24 PM
BruceT BruceT is offline
Web Hosting Master
 
Join Date: Nov 2002
Location: Michigan
Posts: 695
Every 15 minutes on the quarter-hour, Active Monitor attempts to connect to all enabled services to ensure they are running. That is the source of your messages.

__________________
http://www.lamphowto.com/ - LAMP and LAMP+SSL HowTo
http://www.cobaltfaqs.com/ - Cobalt FAQs and HowTos

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?