[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] RaQ4 - Help with Portsentry on Cobalt RaQ4r



Tony this is someone actively trying to get in to your server through
port69... unless this is one of YOUR IP addies.
Is it always the same IP addy?

PortSentry is doing what it is supposed to - it's monitoring your ports for
scanners and attempts to get in; and then tossing the IP address of those
people into the hosts.deny file.  (So the next time they try scanning, you
are more or less 'invisible' to them.)

Be patient. You'll get used to the logs soon enough - but even after weeks
of having them your paranoia won't lessen any, trust me.  :)


Carrie/everyone,

The IP address is 192.168.1.1 - isn't this a reserved IP address for a local IP network? I thought it might be the Cobalt "talking to itself" - maybe something to do with the active monitoring etc.?

What about the other log entry, every 15 minutes that I get:

Feb 20 10:15:03 www sendmail[1153]: NOQUEUE: localhost [127.0.0.1] did not
issue MAIL/EXPN/VRFY/ETRN during connection to MTA

Any help gratefully recieved!

Tony
_________________________________________________________________________
Get Your Private, Free E-mail from MSN Hotmail at http://www.hotmail.com.