While browsing through logs, I found this in /var/log/messages and in
/var/log/xferlog:
portmap[20922]: connect from XXX.X.XX.XXX to dump(): request from
unauthorized host
The IP address in question happens to be a domain server at that particular
domain. (NS1.XXXXXXX.NET when I do a `whois XXX.X.XXX.`) XXX.X.XX.XXX is
NOT in my ISP's address block.
Any clues as to what this is? I also noticed that /var/log/secure shows
nothing at that particular time.
-W-
--
To unsubscribe: mail [EMAIL PROTECTED] with "unsubscribe"
as the Subject.