<inserted>

On Sunday 23 September 2001 09:59, you wrote:
> At 01:15 AM Sunday, 9/23/2001, you wrote -=>
>
> >Sep 23 00:47:12 home portsentry[1073]: attackalert: UDP scan from host:
> >dhcp1.cgocable.net/24.xxx.x.xx to UDP port: 68
>
> Try adding the following to ../logcheck.ignore
>
> portsentry.*: UDP scan

OK added.. we'll see if it works in 5 minutes :)

> >Sep 23 00:47:12 home portsentry[1073]: attackalert: Host:
> >dhcp1.cgocable.net/24.xxx.x.xx is already blocked Ignoring
>
> You may want to find out why this host is doing what it is doing.  Have you
> done an nslookup on the ip and contacted the owner?

My belief is that it's my cable internet provider pinging me.  cgocable.com 
is Cogeco cable (who I have internet through) and am setup for dhcp from them 
(dynamic IP's)

> >Sep 23 00:45:00 home postfix/pickup[3669]: 887BF2BADC: uid=0 from=<root>
> >Sep 23 00:45:00 home postfix/cleanup[4791]: 887BF2BADC:
> >message-id=<[EMAIL PROTECTED]>
> >Sep 23 00:45:00 home postfix/qmgr[1605]: 887BF2BADC:
> >from=<[EMAIL PROTECTED]>, size=20502, nrcpt=1 (queue active)
> >Sep 23 00:45:01 home postfix/smtp[4793]: 887BF2BADC:
> >to=<[EMAIL PROTECTED]>,
> >relay=mail.plannettechnologies.com[216.36.196.159], delay=1, status=sent
> > (250 XAA02069 Message accepted for delivery)
>
> Try these and see what happens.  I am not familiar with postfix.  I use
> sendmail....
>
> postfix/pickup.*uid
> postfix/cleanup.*message-id
> postfix/qmgr.*from
> post/smtp.*to

Yah, I think this is just logcheck.sh actually being run and sending me email

> Hope this helps.

It does.. thanks!

Want to buy your Pack or Services from MandrakeSoft? 
Go to http://www.mandrakestore.com

Reply via email to