[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-users] raq4 sendmail lost input channel messages



Hello everyone,

I'm getting lots of (probably 100+/day) sendmail messages about lost input channels on two raq4s and its becoming a problem while going through my logchecks. I would like to filter this stuff out, but since I don't really understand what it means I'm hesitant to do so. Maybe its another problem that I need to fix. Here are a couple of the lines:

Nov 6 04:27:35 foo sendmail[1180]: hA69RUW01180: lost input channel from 189.Red-80-32-82.pooles.rima-tde.net [80.32.82.189] to MTA after rcpt Nov 6 05:23:37 foo sendmail[3847]: hA6ANbW03847: lost input channel from c-67-162-197-129.client.comcast.net [67.162.197.129] to MTA after rcpt Nov 5 23:00:11 foo sendmail[18083]: hA640AW18083: lost input channel from 200-168-158-248.speedyterra.com.br [200.168.158.248] (may be forged) to MTA after rcpt Nov 5 23:20:53 foo sendmail[16102]: hA63KpW16102: lost input channel from Current93@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx [4.46.177.196] to MTA after rcpt Nov 5 23:20:53 foo sendmail[16102]: hA63KpW16102: timeout waiting for input from tamqfl1-ar9-4-46-177-196.tamqfl1.dsl-verizon.net during server cmd read

From googling some on the web it seems that this is a pretty generic message. I read that it could be anything from clients disconnecting too soon to my server is being used to send spam to a DDoS attack. I've tested and retested POP auth so I doubt this is the case, and its not a DDoS. Since they are mostly DSL/cable hosts I'm guessing its spam from trojans or whatever, but could it be suggestive of something else? Is it safe to filter out with logcheck?

Thanks in advance for any replies, and thanks everyone who posts to the list, I've learned a bunch.

--
Josh