Just started seeing lot's of these entries in syslog:

Apr 20 23:15:01 www proftpd[5807]: www.xxx-xxxx.com (localhost[127.0.0.1]) -
no
such user 'anonymous'
Apr 20 23:15:01 www proftpd[5807]: www.xxx-xxxx.com (localhost[127.0.0.1]) -
no
such user 'anonymous'
Apr 20 23:15:01 www proftpd[5807]: www.xxx-xxxx.com (localhost[127.0.0.1]) -
FTP
session closed.

Any idea what might be doing this?

Also, PortSentry reports lots of Port 137 scans?

Any ideas greatly appreciated.

TD
[EMAIL PROTECTED]

_______________________________________________
cobalt-security mailing list
[EMAIL PROTECTED]
http://list.cobalt.com/mailman/listinfo/cobalt-security

Reply via email to