> On Jan 21, 2017, at 07:31, Kiss Gabor (Bitman) <ki...@ssg.ki.iif.hu> wrote:
> 
> My logs are fullfilled with this:
> 
> Jan 20 20:05:26 linzer postfix/smtpd[22308]: warning: hostname 
> c942452695-cloudp
> ro-214859053.cloudatcost.com does not resolve to address 167.88.40.162: Name 
> or 
> service not known
> Jan 20 20:05:26 linzer postfix/smtpd[22308]: connect from 
> unknown[167.88.40.162]
> Jan 20 20:05:28 linzer postfix/smtpd[22308]: warning: unknown[167.88.40.162]: 
> SA
> SL login authentication failed: authentication failure
> Jan 20 20:05:29 linzer postfix/smtpd[22308]: lost connection after AUTH from 
> unk
> nown[167.88.40.162]
> Jan 20 20:05:29 linzer postfix/smtpd[22308]: disconnect from 
> unknown[167.88.40.1
> 62]
> 
> Is there any way to know what username was used in these attempts.
> (An existing one every time or they are choosen from a dictionary?)
> 
> Gabor
> -- 
> The Meaning of Life of Brian

saslauthd is likely logging failure via LOG_AUTH facility, see 
/var/log/auth.log or /var/log/secure.

Reply via email to