Full Disclosure mailing list archives
Re: Funny smtp helo in the logs
From: trains () doctorunix com
Date: Sun, 30 Oct 2005 07:09:23 -0600
Quoting Aditya Deshmukh <aditya.deshmukh () online gateway strangled net>:
I have been seeing this in my logs over all the public smtp server, from all over the net. Anyone know what sends these kinds of helo ? 124 09/10/2005 09:54:35 HELO -1209283632 ---> 250 my.smtp.domain.server 125 09/10/2005 09:55:27 HELO -1209747464 ---> 250 my.smtp.domain.server
<snip>
02D 29/10/2005 20:39:12 HELO -1208865784 ---> 250 my.smtp.domain.server 017 30/10/2005 11:21:26 HELO -1216191992 ---> 250 my.smtp.domain.server
they look like ip addresses to me (1216191992 => 72.125.157.248 ). I checked a few and they weren't smpt listeners. I would go for the possibility that your mail server is being used as part of a reporting mechanism to notify the mother ship of vulnerable or infected IP addresses.
------------------------------------------------- Email solutions, MS Exchange alternatives and extrication, security services, systems integration. Contact: services () doctorunix com _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Funny smtp helo in the logs Aditya Deshmukh (Oct 30)
- Re: Funny smtp helo in the logs Thierry Zoller (Oct 30)
- Re: Funny smtp helo in the logs trains (Oct 30)
- Re: Funny smtp helo in the logs Lexi (Oct 30)
- Re: Funny smtp helo in the logs Fco. Jose Garrido Matamoros (Oct 30)
- Re: Funny smtp helo in the logs Valdis . Kletnieks (Oct 30)
- Re: Funny smtp helo in the logs Kenneth Ng (Oct 30)
- Re: Funny smtp helo in the logs Bill Weiss (Oct 30)