[MDaemon-L] ada email aneh di log

2016-10-11 Terurut Topik Syafril Hermansyah
On 12/10/16 11:48, Yarohim wrote:
> Saya coba cek di log ada yang aneh ip nya gonta ganti, dan beberapa kali
> terjadi setiap detik keluar
> bisa dibantu analisa log tersebut , berikut saya kirimkan lognya
> 
> 
> Wed 2016-10-12 11:45:50.451: 05: [525040] Accepting SMTP connection from
> 209.222.104.118:64940  to
> 192.168.10.254:25 

> Wed 2016-10-12 11:45:50.687: 02: [525040] <-- EHLO ylmf-pc
> Wed 2016-10-12 11:45:50.687: 03: [525040] --> 550 5.7.1 Sender unknown
> Wed 2016-10-12 11:45:50.687: 01: [525040] Host screening refused
> connection to 127.0.0.1:25  from ylmf-pc
> [209.222.104.118:64940 ] (matched to line
> "all ylmf-pc refuse")

Node/PC ylmf-pc memang mengganggu seluruh mail server didunia.
Abaikan saja, toh sudah ditolak.





-- 
syafril
---
Syafril Hermansyah
MDaemon-L Moderators, MDaemon 16.5.1-64, SP 5.0.1-64
Harap tidak cc: atau kirim ke private mail untuk masalah MDaemon.

Learning without thought is labor lost; thought without learning is
perilous.
--- Confucius (551 BC - 479 BC), The Confucian Analects


-- 
--MDaemon-L--
Milis ini untuk Diskusi antar pengguna MDaemon Mail Server.

Netiket: https://wiki.openstack.org/wiki/MailingListEtiquette
Arsip: http://mdaemon-l.dutaint.com
Dokumentasi : http://mdaemon.dutaint.co.id
Henti Langgan: Kirim mail ke MDaemon-L-unsubscribe [at] dutaint.com
Berlangganan: kirim mail ke MDaemon-L-subscribe [at] dutaint.com
Versi terakhir MD 16.5.1, SP 5.0.1, OC 4.0, SG 4.0.1





[MDaemon-L] ada email aneh di log

2016-10-11 Terurut Topik Yarohim
Dear Pak Syafril,
Saya coba cek di log ada yang aneh ip nya gonta ganti, dan beberapa kali
terjadi setiap detik keluar
bisa dibantu analisa log tersebut , berikut saya kirimkan lognya


Wed 2016-10-12 11:45:50.451: 05: [525040] Session 525040; child 0001
Wed 2016-10-12 11:45:50.451: 05: [525040] Accepting SMTP connection from
209.222.104.118:64940 to 192.168.10.254:25
Wed 2016-10-12 11:45:50.451: 03: [525040] --> 220 pttms.co.id ESMTP MDaemon
16.5.0; Wed, 12 Oct 2016 11:45:50 +0700
Wed 2016-10-12 11:45:50.687: 02: [525040] <-- EHLO ylmf-pc
Wed 2016-10-12 11:45:50.687: 03: [525040] --> 550 5.7.1 Sender unknown
Wed 2016-10-12 11:45:50.687: 01: [525040] Host screening refused connection
to 127.0.0.1:25 from ylmf-pc [209.222.104.118:64940] (matched to line "all
ylmf-pc refuse")
Wed 2016-10-12 11:45:50.688: 04: [525040] SMTP session terminated (Bytes
in/out: 14/97)
Wed 2016-10-12 11:45:50.688: 01: --
Wed 2016-10-12 11:45:51.167: 05: [525041] Session 525041; child 0001
Wed 2016-10-12 11:45:51.167: 05: [525041] Accepting SMTP connection from
209.222.104.118:65040 to 192.168.10.254:25
Wed 2016-10-12 11:45:51.167: 03: [525041] --> 220 pttms.co.id ESMTP MDaemon
16.5.0; Wed, 12 Oct 2016 11:45:51 +0700
Wed 2016-10-12 11:45:51.404: 02: [525041] <-- EHLO ylmf-pc
Wed 2016-10-12 11:45:51.404: 03: [525041] --> 550 5.7.1 Sender unknown
Wed 2016-10-12 11:45:51.404: 01: [525041] Host screening refused connection
to 127.0.0.1:25 from ylmf-pc [209.222.104.118:65040] (matched to line "all
ylmf-pc refuse")
Wed 2016-10-12 11:45:51.405: 04: [525041] SMTP session terminated (Bytes
in/out: 14/97)
Wed 2016-10-12 11:45:51.405: 01: --
Wed 2016-10-12 11:45:51.878: 05: [525042] Session 525042; child 0001
Wed 2016-10-12 11:45:51.878: 05: [525042] Accepting SMTP connection from
209.222.104.118:65140 to 192.168.10.254:25
Wed 2016-10-12 11:45:51.878: 03: [525042] --> 220 pttms.co.id ESMTP MDaemon
16.5.0; Wed, 12 Oct 2016 11:45:51 +0700
Wed 2016-10-12 11:45:52.115: 02: [525042] <-- EHLO ylmf-pc
Wed 2016-10-12 11:45:52.115: 03: [525042] --> 550 5.7.1 Sender unknown
Wed 2016-10-12 11:45:52.115: 01: [525042] Host screening refused connection
to 127.0.0.1:25 from ylmf-pc [209.222.104.118:65140] (matched to line "all
ylmf-pc refuse")
Wed 2016-10-12 11:45:52.116: 04: [525042] SMTP session terminated (Bytes
in/out: 14/97)
Wed 2016-10-12 11:45:52.116: 01: --
Wed 2016-10-12 11:45:52.592: 05: [525043] Session 525043; child 0001
Wed 2016-10-12 11:45:52.592: 05: [525043] Accepting SMTP connection from
209.222.104.118:65237 to 192.168.10.254:25
Wed 2016-10-12 11:45:52.593: 03: [525043] --> 220 pttms.co.id ESMTP MDaemon
16.5.0; Wed, 12 Oct 2016 11:45:52 +0700
Wed 2016-10-12 11:45:52.832: 02: [525043] <-- EHLO ylmf-pc
Wed 2016-10-12 11:45:52.832: 03: [525043] --> 550 5.7.1 Sender unknown
Wed 2016-10-12 11:45:52.832: 01: [525043] Host screening refused connection
to 127.0.0.1:25 from ylmf-pc [209.222.104.118:65237] (matched to line "all
ylmf-pc refuse")
Wed 2016-10-12 11:45:52.834: 04: [525043] SMTP session terminated (Bytes
in/out: 14/97)
Wed 2016-10-12 11:45:52.834: 01: --

-- 
--MDaemon-L--
Milis ini untuk Diskusi antar pengguna MDaemon Mail Server.

Netiket: https://wiki.openstack.org/wiki/MailingListEtiquette
Arsip: http://mdaemon-l.dutaint.com
Dokumentasi : http://mdaemon.dutaint.co.id
Henti Langgan: Kirim mail ke MDaemon-L-unsubscribe [at] dutaint.com
Berlangganan: kirim mail ke MDaemon-L-subscribe [at] dutaint.com
Versi terakhir MD 16.5.1, SP 5.0.1, OC 4.0, SG 4.0.1