Hello Cobalt Gurus --

After installing the last RaQ2 software update, I have been seeing
in my log several times each hour messages such as the following:

May 21 22:15:04 www proftpd[24474]: www.keller.com (www.keller.com[192.100.68.5]) - 
FTP session opened. 

Note that www.keller.com is the RaQ2 server's name and 192.100.68.5
is its IP address.

To my knowledge, users are not opening FTP sessions but even
if they were, they would not be doing so with such clockwork
regularity.  It must be some program that's doing it.  Is this a
security problem or simply a new feature of proftp that was part
of the last update?

Thanks so much for any light you can shed.

Dan Keller
[EMAIL PROTECTED]
http://www.keller.com/
+1 415 861-4500 (voice)
+1 415 861-4593 (fax)

_______________________________________________
cobalt-security mailing list
[EMAIL PROTECTED]
http://list.cobalt.com/mailman/listinfo/cobalt-security

Reply via email to