Hi Everyone,
Every 30 seconds or so I get this in my log file
938452598.679039 tcpserver: pid 8819 from 12.69.1.57
938452598.807091 tcpserver: ok 8817 :139.142.67.213:25
57.middletown-02.va.dial-access.att.net:12.69.1.57::4037
938452598.835702 tcpserver: status: 4/40
938452598.836327 tcpserver: pid 8820 from 12.69.1.57
938452598.882569 tcpserver: status: 5/40
938452598.883661 tcpserver: pid 8821 from 12.69.1.57
938452598.883973 tcpserver: ok 8818 :139.142.67.213:25
57.middletown-02.va.dial-access.att.net:12.69.1.57::4039
938452598.981531 tcpserver: ok 8819 :139.142.67.213:25
57.middletown-02.va.dial-access.att.net:12.69.1.57::4041
938452599.074135 tcpserver: status: 6/40
938452599.074801 tcpserver: pid 8822 from 12.69.1.57
938452599.203219 tcpserver: status: 7/40
938452599.204369 tcpserver: pid 8823 from 12.69.1.57
938452599.224972 tcpserver: ok 8820 :139.142.67.213:25
57.middletown-02.va.dial-access.att.net:12.69.1.57::4043
938452599.324194 tcpserver: ok 8821 :139.142.67.213:25
57.middletown-02.va.dial-access.att.net:12.69.1.57::4045
938452599.352396 tcpserver: status: 8/40
938452599.353117 tcpserver: pid 8824 from 12.69.1.57
938452599.448430 tcpserver: ok 8822 :139.142.67.213:25
57.middletown-02.va.dial-access.att.net:12.69.1.57::4047
938452599.501438 tcpserver: status: 9/40
938452599.502081 tcpserver: pid 8825 from 12.69.1.57
938452599.593579 tcpserver: ok 8823 :139.142.67.213:25
57.middletown-02.va.dial-access.att.net:12.69.1.57::4049
938452599.748770 tcpserver: ok 8824 :139.142.67.213:25
57.middletown-02.va.dial-access.att.net:12.69.1.57::4051
938452599.843773 tcpserver: ok 8825 :139.142.67.213:25
57.middletown-02.va.dial-access.att.net:12.69.1.57::4053
938452600.450562 tcpserver: end 8817 status 256
938452600.450647 tcpserver: status: 8/40
938452600.487000 tcpserver: end 8818 status 256
938452600.487062 tcpserver: status: 7/40
938452600.578999 tcpserver: end 8819 status 256
938452600.579061 tcpserver: status: 6/40
938452600.846009 tcpserver: end 8820 status 256
938452600.846124 tcpserver: status: 5/40
938452600.918916 tcpserver: end 8821 status 256
938452600.918976 tcpserver: status: 4/40
938452601.052387 tcpserver: end 8822 status 256
938452601.052452 tcpserver: status: 3/40
938452601.322522 tcpserver: end 8823 status 256
938452601.322582 tcpserver: status: 2/40
938452601.553313 tcpserver: end 8824 status 256
938452601.553377 tcpserver: status: 1/40
938452601.553646 tcpserver: end 8825 status 256
After digging around some I couldn't any docs on qmail-smtpd log format. I've
tried blocking 12.69.1.57 in /etc/tcp.smtp but after a few minutes the person
gets a different IP address... If someone could point me to someplace where I
could learn whats happening or explain it here that would be great, thanks,
Tom