Hi,

I did not find the compromised account yet, but I see a lot off messages
like the following one in our logs:

/var/log/httpd/ssl_request_log.1:[21/May/2011:01:10:54 +0200]
74.82.171.30 TLSv1 RC4-MD5 "POST
/horde/imp/compose.php?uniq=721hskg326yc HTTP/1.1" 92

/var/log/httpd/ssl_request_log.1:[21/May/2011:01:14:38 +0200]
74.82.171.30 TLSv1 RC4-MD5 "POST
/horde/imp/compose.php?uniq=6khanz8ousab HTTP/1.1" 92

/var/log/httpd/ssl_request_log.1:[21/May/2011:01:24:41 +0200]
74.82.171.30 TLSv1 RC4-MD5 "POST
/horde/imp/compose.php?uniq=2bcbqsb503hi HTTP/1.1" 92


May be anyone has an idea how to protect against such direct postings...
if it is possible anyway?



Any suggestion is welcome!!!!

-- 
Götz Reinicke
IT-Koordinator

Tel. +49 7141 969 420
Fax  +49 7141 969 55 420
E-Mail [email protected]

Filmakademie Baden-Württemberg GmbH
Akademiehof 10
71638 Ludwigsburg
www.filmakademie.de

Eintragung Amtsgericht Stuttgart HRB 205016
Vorsitzende des Aufsichtsrats:
Prof. Dr. Claudia Hübner

Geschäftsführer:
Prof. Thomas Schadt

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

-- 
IMP mailing list
Frequently Asked Questions: http://horde.org/faq/
To unsubscribe, mail: [email protected]

Reply via email to