its just someone probing port 995 or someone trying to download their mail securely. could be an incorrectly configured mail client. i wouldnt worry about it.
its used for secure POP3 so make of it what you will. the "tcp pop3 protocol over TLS/SSL (was spop3)" is just a description of what the port does. do you use that port and offer secure pop3 ? ----- Original Message ----- From: "Kameel" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Wednesday, September 11, 2002 5:33 AM Subject: [cobalt-security] Port Sentry Alert > Heya, > > I've had several port sentry alerts from this IP. > I don't understand what it means by "tcp pop3 protocol over TLS/SSL (was > spop3)" or if this is a threat ? > > Can someone please let me know how significant (if at all) this is ? > > Thanks, > Kam (the paranoid). > > > Portsentry had an alert to <my domain> from the following IP address and port: > 61.1.60.156 995 > > Service: > pop3s 995/tcp pop3 protocol over TLS/SSL (was spop3) > pop3s 995/udp pop3 protocol over TLS/SSL (was spop3) > _______________________________________________ cobalt-security mailing list [EMAIL PROTECTED] http://list.cobalt.com/mailman/listinfo/cobalt-security
