[Wftl-lug] lastlog and syslogd weirdness

Warren Togami warren at togami.com
Mon Mar 12 10:11:04 PST 2001


That's exactly how many spammers operate.  They scan entire networks looking
for open relays, or they create open relays for themselves using root kits
and known exploits.  Nelsons's earlier e-mail said that only port 80 should
be open to incoming traffic from the outside.

----- Original Message -----
From: "Robert Buecker" <rbuecker at darkscape.net>
To: "Linux & Unix Advocates & Users" <luau at list.luau.hi.net>
Sent: Monday, March 12, 2001 8:09 AM
Subject: [luau] RE: [Wftl-lug] lastlog and syslogd weirdness


> Like they're going to probe hawaii.rr.com looking for Nelson's box
everytime
> they want to sell some new MLM scheme :-p
> Besides, last time I heard he was using smtp auth+tls, no?
>
> Robert
>
> > Uh oh.  Could that mean someone is using you as spam relay?
> >
> > > Interesting ports on a24b31n75client13.hawaii.rr.com (24.31.75.13):
> > > (Ports scanned but not shown below are in state: filtered)
> > > Port       State       Service
> > > 25/tcp     open        smtp
> > > 80/tcp     open        http
> > >



More information about the LUAU mailing list