FAQ Search Today's Posts Mark Forums Read
» Video Reviews

» Linux Archive

Linux-archive is a website aiming to archive linux email lists and to make them easily accessible for linux users/developers.


» Sponsor

» Partners

» Sponsor

Go Back   Linux Archive > Debian > Debian User

 
 
LinkBack Thread Tools
 
Old 04-12-2008, 07:20 PM
NN_il_Confusionario
 
Default Where are "Log AttacLog" emails coming from...

On Sat, Apr 12, 2008 at 09:24:30AM -0500, Hose wrote:
> installed package that is spitting out snort-esque emails to root

check cron jobs
check active daemons
check the complete headers of the e-mail
(Since you can not find the log file, double check: is the email
originating from that box? from another log-host?)

--
Chi usa software non libero avvelena anche te. Digli di smettere.
Informatica=arsenico: minime dosi in rari casi patologici, altrimenti letale.
Informatica=bomba: intelligente solo per gli stupidi che ci credono.


--
To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
 
Old 04-12-2008, 08:04 PM
Hose
 
Default Where are "Log AttacLog" emails coming from...

On Apr 12, 2008, at 2:20 PM, NN_il_Confusionario wrote:

On Sat, Apr 12, 2008 at 09:24:30AM -0500, Hose wrote:

installed package that is spitting out snort-esque emails to root


check cron jobs
check active daemons
check the complete headers of the e-mail
(Since you can not find the log file, double check: is the email
originating from that box? from another log-host?)


Well I went back through the mail server logs to identify the host and
then the email headers, and then realized something - it WASN'T
originating from the localhost. At first I thought it was, but then I
completely misread the IP address in the headers. Doh.


FYI traced it down to an old WAP we use in legacy space that someone
hacked to bits with openwrt, hence, the weird logs. Thanks.



--
To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
 

Thread Tools




All times are GMT. The time now is 08:18 AM.

VBulletin, Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO ©2007, Crawlability, Inc.
Copyright 2007 - 2008, www.linux-archive.org