Actually, it looks to me like someone possibly using the double-byte domains
that are now available. You may want to check to see if that may be the
issue.

Brian Andrus

----- Original Message -----
From: "Ajay Tikoo" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Thursday, August 02, 2001 6:23 AM
Subject: RE: [IMail Forum] Am I being hacked?


>
> IMail support says that someone is trying to hack my server and they can
do
> nothing about it.
>
> I used "snort" to log all the traffic coming to the port 110, but the logs
> do not show any such weird characters sent to the server.
>
> I have some more information here. I found the following two lines in my
> logs:
>
> 07:31 11:49 POP3D  UNK: %1!s! - %2!s
> 07:31 11:49 POP3D  (0000013B)  logon failure for gsumathi zerowait.net
from
> <my IP here>
>
> This login attempt was made from my own network. Though the second line is
> normal, but the first line displays %1!s! and %2!s where domain name and
> user ID sould be displayed
>
> I hope this will help in accepting that this is not any hacking attempt.
> There is some problem with Imail POP3 logging. This type of characters are
> there only with POP3D entries and it happens intermittently.
>
> ________________
> Ajay Tikoo
>
>
> Please visit http://www.ipswitch.com/support/mailing-lists.html
> to be removed from this list.
>
> An Archive of this list is available at:
> http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
>


Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Reply via email to