>IMail support says that someone is trying to hack my server and they can do
>nothing about it.
>
>I used "snort" to log all the traffic coming to the port 110, but the logs
>do not show any such weird characters sent to the server.
>
>I have some more information here. I found the following two lines in my
>logs:
>
>07:31 11:49 POP3D UNK: %1!s! - %2!s
>07:31 11:49 POP3D (0000013B) logon failure for gsumathi zerowait.net from
><my IP here>
>
>This login attempt was made from my own network. Though the second line is
>normal, but the first line displays %1!s! and %2!s where domain name and
>user ID sould be displayed
>
>I hope this will help in accepting that this is not any hacking attempt.
yep, it sure looks like those are variables that aren�t getting filled in
before the text is written to the log file
Len
http://MenAndMice.com/DNS-training
http://BIND8NT.MEIway.com : ISC BIND 8.2.4 for NT4 & W2K
http://IMGate.MEIway.com : Build free, hi-perf, anti-abuse mail gateways
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/