Hi, I did not find the compromised account yet, but I see a lot off messages like the following one in our logs:
/var/log/httpd/ssl_request_log.1:[21/May/2011:01:10:54 +0200] 74.82.171.30 TLSv1 RC4-MD5 "POST /horde/imp/compose.php?uniq=721hskg326yc HTTP/1.1" 92 /var/log/httpd/ssl_request_log.1:[21/May/2011:01:14:38 +0200] 74.82.171.30 TLSv1 RC4-MD5 "POST /horde/imp/compose.php?uniq=6khanz8ousab HTTP/1.1" 92 /var/log/httpd/ssl_request_log.1:[21/May/2011:01:24:41 +0200] 74.82.171.30 TLSv1 RC4-MD5 "POST /horde/imp/compose.php?uniq=2bcbqsb503hi HTTP/1.1" 92 May be anyone has an idea how to protect against such direct postings... if it is possible anyway? Any suggestion is welcome!!!! -- Götz Reinicke IT-Koordinator Tel. +49 7141 969 420 Fax +49 7141 969 55 420 E-Mail [email protected] Filmakademie Baden-Württemberg GmbH Akademiehof 10 71638 Ludwigsburg www.filmakademie.de Eintragung Amtsgericht Stuttgart HRB 205016 Vorsitzende des Aufsichtsrats: Prof. Dr. Claudia Hübner Geschäftsführer: Prof. Thomas Schadt
smime.p7s
Description: S/MIME Cryptographic Signature
-- IMP mailing list Frequently Asked Questions: http://horde.org/faq/ To unsubscribe, mail: [email protected]
