Security Incidents mailing list archives

Re: HELO/EHLP attack?.


From: Ryan Yagatich <ryagatich () CSN1 COM>
Date: Fri, 4 Aug 2000 09:58:17 -0400

don't quote me on this but, it looks to me like someone had just connected
to the SMTP daemon and just initialized the connection, and then killed it
right after. was there anything else in the logs before/after? (like
commands that were issued etc...) if not, set your log level up a bit to
grab more information and see.

ryan

-----Original Message-----
From: Incidents Mailing List [mailto:INCIDENTS () SECURITYFOCUS COM]On
Behalf Of Lic. Rodolfo Gonzalez Gonzalez
Sent: Wednesday, August 02, 2000 1:50 PM
To: INCIDENTS () SECURITYFOCUS COM
Subject: HELO/EHLP attack?.


Hello,

I got this in my logs:

Jul 31 19:49:46 mail sendmail[5153]: NOQUEUE: [64.41.151.78]: HELO/EHLO
attack?

This is a remote attack, I guess? (but I'd like to be sure, please).

Thanks.
Rodolfo.


Current thread: