Hey all,

I've been seeing the following about 4 or 5 times a week, any idea what
they are trying to accomplish?

---
Dec  7 07:30:32 backup sendmail[8699]: HAA08699: <[EMAIL PROTECTED]>... User
unknown
Dec  7 07:30:33 backup sendmail[8699]: HAA08699: <[EMAIL PROTECTED]>...
User unknown

<snipped another 30 lines of this type stuff>

Dec  7 07:30:34 backup sendmail[8699]: HAA08699: <[EMAIL PROTECTED]>... User
unknown
Dec  7 07:30:34 backup sendmail[8699]: HAA08699:
from=<[EMAIL PROTECTED]>, size=0, class=0, pri=0, nrcpt
s=0, proto=SMTP, relay=3Cust77.tnt4.krk1.da.uu.net [63.27.2.77]
---

I had thought they were trying to find addresses on the machine via brute
force, but I haven't seen any increase in SPAM. What are they trying to
do?

I usually block the IP, but the same thing will show up from another IP.
They due tend to come from uu.net, bellsouth.net and uswest.net.

Later,

Bill Carlson
-- 
Systems Programmer    [EMAIL PROTECTED]    |  Opinions are mine,
Virtual Hospital      http://www.vh.org/        |  not my employer's.
University of Iowa Hospitals and Clinics        |



_______________________________________________
Redhat-list mailing list
[EMAIL PROTECTED]
https://listman.redhat.com/mailman/listinfo/redhat-list

Reply via email to