its just someone probing port 995 or someone trying to download their mail
securely.
could be an incorrectly configured mail client. i wouldnt worry about it.

its used for secure POP3 so make of it what you will.

the "tcp pop3 protocol over TLS/SSL (was spop3)"
is just a description of what the port does.

do you use that port and offer secure pop3 ?

----- Original Message -----
From: "Kameel" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Wednesday, September 11, 2002 5:33 AM
Subject: [cobalt-security] Port Sentry Alert


> Heya,
>
> I've had several port sentry alerts from this IP.
> I don't understand what it means by "tcp pop3 protocol over TLS/SSL (was
> spop3)" or if this is a threat ?
>
> Can someone please let me know how significant (if at all) this is ?
>
> Thanks,
> Kam (the paranoid).
>
>
> Portsentry had an alert to <my domain> from the following IP address and
port:
> 61.1.60.156 995
>
> Service:
> pop3s 995/tcp pop3 protocol over TLS/SSL (was spop3)
> pop3s 995/udp pop3 protocol over TLS/SSL (was spop3)
>

_______________________________________________
cobalt-security mailing list
[EMAIL PROTECTED]
http://list.cobalt.com/mailman/listinfo/cobalt-security

Reply via email to