Hi all!

        For those of you still interested i taking a look at this... this
is an extract from my log files... Perhaps it can help you guys more than
it is helping me... ;)

        For those of you who are going to scroll down... perhaps you can
see what i can: a DNS thing going on? Any ideas?

--------------------
Subject: olympus 04/24/01:21.02 system check
--------------------
Security Violations
=-=-=-=-=-=-=-=-=-=
Apr 24 20:29:19 olympus postfix/smtp[5026]: 611082132: to=<[EMAIL PROTECTED]>, 
relay=abc-svr3.netabc.com.br[200.245.88.27], delay=12, status=deferred (host 
abc-svr3.netabc.com.br[200.245.88.27] said: 450 <[EMAIL PROTECTED]>: Sender 
address rejected: Domain not found)
Apr 24 20:56:27 olympus postfix/smtp[8661]: 611082132: to=<[EMAIL PROTECTED]>, 
relay=abc-svr3.netabc.com.br[200.245.88.27], delay=1640, status=deferred (host 
abc-svr3.netabc.com.br[200.245.88.27] said: 450 <[EMAIL PROTECTED]>: Sender 
address rejected: Domain not found)
Apr 24 20:29:19 olympus postfix/smtp[5026]: 611082132: to=<[EMAIL PROTECTED]>, 
relay=abc-svr3.netabc.com.br[200.245.88.27], delay=12, status=deferred (host 
abc-svr3.netabc.com.br[200.245.88.27] said: 450 <[EMAIL PROTECTED]>: Sender 
address rejected: Domain not found)
Apr 24 20:56:27 olympus postfix/smtp[8661]: 611082132: to=<[EMAIL PROTECTED]>, 
relay=abc-svr3.netabc.com.br[200.245.88.27], delay=1640, status=deferred (host 
abc-svr3.netabc.com.br[200.245.88.27] said: 450 <[EMAIL PROTECTED]>: Sender 
address rejected: Domain not found)

Unusual System Events
=-=-=-=-=-=-=-=-=-=-=
Apr 24 20:02:02 olympus postfix/pickup[4761]: AEBF62133: uid=0 from=<root>
Apr 24 20:02:02 olympus postfix/cleanup[4926]: AEBF62133: message-id=<[EMAIL 
PROTECTED]>
Apr 24 20:02:02 olympus postfix/qmgr[4762]: AEBF62133: from=<[EMAIL 
PROTECTED]>, size=6891 (queue active)
Apr 24 20:02:02 olympus icmplogd: destination unreachable from olympus 
[127.0.0.1]
Apr 24 20:02:02 olympus postfix/local[4928]: AEBF62133: to=<[EMAIL PROTECTED]>, 
relay=local, delay=0, status=sent ("|/usr/bin/procmail -a "$EXTENSION"")

Apr 24 20:05:08 olympus tcplogd: smtp connection attempt from 
olympus.het.brown.edu [128.148.26.122]
Apr 24 20:05:08 olympus postfix/smtpd[4936]: connect from 
olympus.het.brown.edu[128.148.26.122]
Apr 24 20:05:08 olympus postfix/smtpd[4936]: 7D1282132: 
client=olympus.het.brown.edu[128.148.26.122]
Apr 24 20:05:08 olympus postfix/cleanup[4937]: 7D1282132: message-id=<[EMAIL 
PROTECTED]>
Apr 24 20:05:08 olympus postfix/smtpd[4936]: disconnect from 
olympus.het.brown.edu[128.148.26.122]
Apr 24 20:05:08 olympus postfix/qmgr[4762]: 7D1282132: from=<[EMAIL 
PROTECTED]>, size=1992 (queue active)
Apr 24 20:05:08 olympus icmplogd: destination unreachable from olympus 
[127.0.0.1]
Apr 24 20:05:08 olympus postfix/local[4939]: 7D1282132: to=<[EMAIL PROTECTED]>, 
relay=local, delay=0, status=sent ("|/usr/bin/procmail -a "$EXTENSION"")
Apr 24 20:05:09 olympus tcplogd: auth connection attempt from murphy.debian.org 
[216.234.231.6]
Apr 24 20:05:09 olympus oidentd[4941]: Connection from murphy.debian.org 
(216.234.231.6):4207
Apr 24 20:05:09 olympus oidentd[4941]: [216.234.231.6] Successful lookup: 3347 
, 25 : postfix (postfix)
Apr 24 20:05:09 olympus postfix/smtp[4938]: 7D1282132: 
to=<debian-user@lists.debian.org>, relay=murphy.debian.org[216.234.231.6], 
delay=1, status=sent (250 ok 988156963 qp 8184)

Apr 24 20:20:45 olympus tcplogd: smtp connection attempt from 
olympus.het.brown.edu [128.148.26.122]
Apr 24 20:20:45 olympus postfix/smtpd[5003]: connect from 
olympus.het.brown.edu[128.148.26.122]
Apr 24 20:20:45 olympus postfix/smtpd[5003]: A45262132: 
client=olympus.het.brown.edu[128.148.26.122]
Apr 24 20:20:45 olympus postfix/cleanup[5004]: A45262132: message-id=<[EMAIL 
PROTECTED]>
Apr 24 20:20:45 olympus postfix/smtpd[5003]: disconnect from 
olympus.het.brown.edu[128.148.26.122]
Apr 24 20:20:45 olympus postfix/qmgr[4762]: A45262132: from=<[EMAIL 
PROTECTED]>, size=2931 (queue active)
Apr 24 20:20:46 olympus tcplogd: auth connection attempt from lnx00.cecm.usp.br 
[143.107.90.10]
Apr 24 20:20:46 olympus oidentd[5008]: Connection from lnx00.cecm.usp.br 
(143.107.90.10):1309
Apr 24 20:20:46 olympus oidentd[5008]: [143.107.90.10] Successful lookup: 3417 
, 25 : postfix (postfix)
Apr 24 20:20:46 olympus tcplogd: auth connection attempt from bidu.ime.usp.br 
[143.107.45.12]
Apr 24 20:20:46 olympus oidentd[5009]: Connection from bidu.ime.usp.br 
(143.107.45.12):63139
Apr 24 20:20:46 olympus oidentd[5009]: [143.107.45.12] Successful lookup: 3416 
, 25 : postfix (postfix)
Apr 24 20:20:47 olympus postfix/smtp[5006]: A45262132: to=<[EMAIL PROTECTED]>, 
relay=lnx00.cecm.usp.br[143.107.90.10], delay=2, status=bounced (host 
lnx00.cecm.usp.br[143.107.90.10] said: 552 sorry, your envelope sender domain 
must exist (#5.7.1))
Apr 24 20:20:48 olympus postfix/smtp[5007]: A45262132: to=<[EMAIL PROTECTED]>, 
relay=bidu.ime.usp.br[143.107.45.12], delay=3, status=sent (250 ok 988157902 qp 
17913)
Apr 24 20:20:48 olympus postfix/cleanup[5004]: 036842133: message-id=<[EMAIL 
PROTECTED]>
Apr 24 20:20:48 olympus postfix/qmgr[4762]: 036842133: from=<>, size=4256 
(queue active)
Apr 24 20:20:48 olympus icmplogd: destination unreachable from olympus 
[127.0.0.1]
Apr 24 20:20:48 olympus postfix/local[5011]: 036842133: to=<[EMAIL PROTECTED]>, 
relay=local, delay=0, status=sent ("|/usr/bin/procmail -a "$EXTENSION"")
Apr 24 20:22:10 olympus postfix/smtpd[5003]: connect from 
olympus.het.brown.edu[128.148.26.122]
Apr 24 20:22:10 olympus tcplogd: smtp connection attempt from 
olympus.het.brown.edu [128.148.26.122]
Apr 24 20:22:10 olympus postfix/smtpd[5003]: 2C05E2132: 
client=olympus.het.brown.edu[128.148.26.122]
Apr 24 20:22:10 olympus postfix/cleanup[5004]: 2C05E2132: message-id=<[EMAIL 
PROTECTED]>
Apr 24 20:22:10 olympus postfix/cleanup[5004]: 2C05E2132: 
resent-message-id=<[EMAIL PROTECTED]>
Apr 24 20:22:10 olympus postfix/smtpd[5003]: disconnect from 
olympus.het.brown.edu[128.148.26.122]
Apr 24 20:22:10 olympus postfix/qmgr[4762]: 2C05E2132: from=<[EMAIL 
PROTECTED]>, size=4721 (queue active)
Apr 24 20:22:10 olympus tcplogd: auth connection attempt from 
later.het.brown.edu [128.148.26.46]
Apr 24 20:22:10 olympus oidentd[5013]: Connection from later.het.brown.edu 
(128.148.26.46):52106
Apr 24 20:22:10 olympus oidentd[5013]: [128.148.26.46] Successful lookup: 3419 
, 25 : postfix (postfix)
Apr 24 20:22:10 olympus postfix/smtp[5006]: 2C05E2132: to=<[EMAIL PROTECTED]>, 
relay=mail.het.brown.edu[128.148.26.46], delay=0, status=sent (250 2.0.0 
f3P0Jih14240 Message accepted for delivery)
Apr 24 20:22:10 olympus tcplogd: smtp connection attempt from 
later.het.brown.edu [128.148.26.46]
Apr 24 20:22:10 olympus postfix/smtpd[5003]: connect from 
later.het.brown.edu[128.148.26.46]
Apr 24 20:22:10 olympus postfix/smtpd[5003]: EBDE32132: 
client=later.het.brown.edu[128.148.26.46]
Apr 24 20:22:10 olympus postfix/cleanup[5004]: EBDE32132: message-id=<[EMAIL 
PROTECTED]>
Apr 24 20:22:11 olympus postfix/qmgr[4762]: EBDE32132: from=<>, size=7248 
(queue active)
Apr 24 20:22:11 olympus icmplogd: destination unreachable from olympus 
[127.0.0.1]
Apr 24 20:22:11 olympus postfix/local[5011]: EBDE32132: to=<[EMAIL PROTECTED]>, 
relay=local, delay=1, status=sent ("|/usr/bin/procmail -a "$EXTENSION"")
Apr 24 20:22:11 olympus postfix/smtpd[5003]: disconnect from 
later.het.brown.edu[128.148.26.46]
Apr 24 20:23:03 olympus postfix/smtpd[5003]: connect from 
olympus.het.brown.edu[128.148.26.122]
Apr 24 20:23:03 olympus tcplogd: smtp connection attempt from 
olympus.het.brown.edu [128.148.26.122]
Apr 24 20:23:03 olympus postfix/smtpd[5003]: 870E02132: 
client=olympus.het.brown.edu[128.148.26.122]
Apr 24 20:23:03 olympus postfix/cleanup[5004]: 870E02132: message-id=<[EMAIL 
PROTECTED]>
Apr 24 20:23:03 olympus postfix/cleanup[5004]: 870E02132: 
resent-message-id=<[EMAIL PROTECTED]>
Apr 24 20:23:03 olympus postfix/smtpd[5003]: disconnect from 
olympus.het.brown.edu[128.148.26.122]
Apr 24 20:23:03 olympus postfix/qmgr[4762]: 870E02132: from=<[EMAIL 
PROTECTED]>, size=7717 (queue active)
Apr 24 20:23:04 olympus tcplogd: auth connection attempt from latt.if.usp.br 
[143.107.129.103]
Apr 24 20:23:04 olympus oidentd[5015]: Connection from latt.if.usp.br 
(143.107.129.103):1095
Apr 24 20:23:04 olympus oidentd[5015]: [143.107.129.103] Successful lookup: 
3421 , 25 : postfix (postfix)
Apr 24 20:23:05 olympus postfix/smtp[5006]: 870E02132: to=<[EMAIL PROTECTED]>, 
relay=latt.if.usp.br[143.107.129.103], delay=2, status=sent (250 ok 988158039 
qp 21789)

Reply via email to