Sorry for possibly dumb question! In logcheck's output I see the next lines:
Security Violations =-=-=-=-=-=-=-=-=-= Aug 26 16:08:19 gamma su: sysop to root on /dev/ttyp0 Aug 26 16:15:30 gamma pop3d[38466]: Bad IPLOCALPORT value Aug 26 16:15:30 gamma pop3d[38466]: Bad IPREMOTEPORT value Aug 26 16:37:49 gamma su: sysop to root on /dev/ttyp0 Aug 26 16:56:20 gamma su: sysop to root on /dev/ttyp0 Aug 26 16:57:53 gamma su: sysop to root on /dev/ttyp0 ~% grep 'Aug 26 16:15:30' \ > /var/log/{maillog,auth.log,security,imapd.log,messages} /var/log/auth.log:Aug 26 16:15:30 gamma pop3d[38466]: Bad IPLOCALPORT value /var/log/auth.log:Aug 26 16:15:30 gamma pop3d[38466]: Bad IPREMOTEPORT value /var/log/security:Aug 26 16:15:30 gamma pop3d[38466]: Bad IPLOCALPORT value /var/log/security:Aug 26 16:15:30 gamma pop3d[38466]: Bad IPREMOTEPORT value /var/log/imapd.log:Aug 26 16:15:30 gamma pop3d[38466]: warning: can't get client address: Connection reset by peer /var/log/imapd.log:Aug 26 16:15:30 gamma pop3d[38466]: accepted connection /var/log/imapd.log:Aug 26 16:15:30 gamma master[13904]: process 38466 exited, status 0 /var/log/messages:Aug 26 16:15:30 gamma pop3d[38466]: warning: can't get client address: Connection reset by peer ~% What this is mean? PS: ~% uname -sr FreeBSD 4.10-STABLE ~% pkg_info -aI | grep cyrus cyrus-imapd-2.1.16_2 The cyrus mail server, supporting POP3 and IMAP4 protocols cyrus-sasl-2.1.19 RFC 2222 SASL (Simple Authentication and Security Layer) cyrus-sasl-saslauthd-2.1.19 SASL authentication server for cyrus-sasl2 ~% --- Cyrus Home Page: http://asg.web.cmu.edu/cyrus Cyrus Wiki/FAQ: http://cyruswiki.andrew.cmu.edu List Archives/Info: http://asg.web.cmu.edu/cyrus/mailing-list.html