hi everybody,
I�m maintaining 3 different, independent networks, all connected to the
internet
for quite a while now I am finding entries of the following form in the
syslogs of ALL my gateways
in.telnetd: refused IP address
popper: refused (same) IP address
(sometimes:) in.telnetd: refused (same) IP address
what are these? I know that somebody is trying to connect to my machine
on ports where i do not want this to happen - i secured these ports
quite a while ago now, but what interests me is: what are these people
trying to do? is this sort of special scanning? breakin attempts? all of
my gateway machines are running linux, just in case this matters
greetz from Vienna
Hannes
--
Johann Georg Hautzinger http://treasury.erstebank.at
Erste Bank AG - OE 659 - T&S Support
Boersegasse 14 Tel.: 536 31 1907
1010 Wien email: [EMAIL PROTECTED]
-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]