Re: pop3d exploit

2007-01-30 Thread Mirosław Jaworski
On Tue, 2007-01-30 at 15:11 -0600, Vernon A. Fort wrote: > The connections to the pop3d were from ONE specific host which had 525 > connections within 20 minutes. That's merely connection every 2 seconds. That shouldn't be a big deal, unless connections were left open and idle on purpose. Medium

Re: pop3d exploit

2007-01-30 Thread Vernon A. Fort
Mirosław Jaworski wrote: On Tue, 2007-01-30 at 11:51 -0600, Vernon A. Fort wrote: I think I just saw an attempt to exploit my pop3d service. A number of badlogin attempts followed by: Running cyrus-iampd 2.2.12-r4 on gentoo amd64 dual core. I've never seen this problem prior to today. I

Re: pop3d exploit

2007-01-30 Thread Mirosław Jaworski
On Tue, 2007-01-30 at 11:51 -0600, Vernon A. Fort wrote: > I think I just saw an attempt to exploit my pop3d service. A number of > badlogin attempts followed by: > > Running cyrus-iampd 2.2.12-r4 on gentoo amd64 dual core. I've never > seen this problem prior to today. Is there any know work

pop3d exploit

2007-01-30 Thread Vernon A. Fort
I think I just saw an attempt to exploit my pop3d service. A number of badlogin attempts followed by: Running cyrus-iampd 2.2.12-r4 on gentoo amd64 dual core. I've never seen this problem prior to today. Is there any know workaround? Vernon Jan 30 10:07:46 ictone master[28137]: about to