Just started seeing lot's of these entries in syslog:
Apr 20 23:15:01 www proftpd[5807]: www.xxx-xxxx.com (localhost[127.0.0.1]) -
no
such user 'anonymous'
Apr 20 23:15:01 www proftpd[5807]: www.xxx-xxxx.com (localhost[127.0.0.1]) -
no
such user 'anonymous'
Apr 20 23:15:01 www proftpd[5807]: www.xxx-xxxx.com (localhost[127.0.0.1]) -
FTP
session closed.
Any idea what might be doing this?
Also, PortSentry reports lots of Port 137 scans?
Any ideas greatly appreciated.
TD
[EMAIL PROTECTED]
_______________________________________________
cobalt-security mailing list
[EMAIL PROTECTED]
http://list.cobalt.com/mailman/listinfo/cobalt-security