[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] Strange sendmail reports -- email attack?



Do you continue to receive them if you drop the raq from the network? I'm
just wondering if sendmail has gotten into one of it's nasty little loops...

As far as the other one, I get those every so often myself. I think it's
just named cleaning it's cache.

"Brian M. Rahill" wrote:

> Hi All,
>
> Any idea what this log (see below) means.  I've got tons of them...this
> message is create something like every 30 seconds for days...
>
> ____________
> Apr 20 18:59:31 admin sendmail[14980]: f3KMwAa14980: ruleset=check_mail,
> arg1=<asvdsign@xxxxxxxxxxx>, relay=IDENT:root@[202.161.150.2], reject=451
> 4.1.8 <asvdsign@xxxxxxxxxxx>... Domain of sender address
> asvdsign@xxxxxxxxxxx does not resolve
> ____________
>
> Is is some sort of email attack?
>
> I've also been seeing some of these (2/hr)
>
> _________
> Apr 19 16:51:19 admin named[20848]: ns_forw:
> query(120.172.235.216.in-addr.arpa) All possible A RR's lame
> __________
>
> Any thoughts are much appreciated.
>
> Thanks!
>
> Brian
>
> _______________________________________________
> cobalt-users mailing list
> cobalt-users@xxxxxxxxxxxxxxx
> To Subscribe or Unsubscribe, please go to:
> http://list.cobalt.com/mailman/listinfo/cobalt-users

--
Rule #1 - The customer is always right.
Rule #2 - They must pay for their arrogance!

Regards,
Timothy Bissell
Sun Microsystems Sr. Help Desk Technician
Phone: 1-800-266-4378