LinuxSir.cn,穿越时空的Linuxsir!

 找回密码
 注册
搜索
热搜: shell linux mysql
查看: 1044|回复: 1

请教,postfix是不是被攻击

[复制链接]
发表于 2008-6-13 16:42:59 | 显示全部楼层 |阅读模式
日志文件里面反复出现:
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: connection established
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: master_notify: status 0
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: name_mask: resource
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: name_mask: software
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: name_mask: noanonymous
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: warning: 10.0.0.20: hostname bogon
verification failed: Name or service not known
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: connect from unknown[10.0.0.20]
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: match_list_match: unknown: no match
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: match_list_match: 10.0.0.20: no match
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: match_list_match: unknown: no match
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: match_list_match: 10.0.0.20: no match
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: match_hostname: unknown ~? 127.0.0.0/24
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: match_hostaddr: 10.0.0.20 ~? 127.0.0.0/24
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: match_hostname: unknown ~? 10.20.30.0/24
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: match_hostaddr: 10.0.0.20 ~? 10.20.30.0/24
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: match_hostname: unknown ~? 10.110.10.0/24
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: match_hostaddr: 10.0.0.20 ~? 10.110.10.0/24
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: match_list_match: unknown: no match
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: match_list_match: 10.0.0.20: no match
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: send attr request = connect
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: send attr ident = smtp:10.0.0.20
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: private/anvil: wanted attribute: status
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: input attribute name: status
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: input attribute value: 0
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: private/anvil: wanted attribute: count
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: input attribute name: count
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: input attribute value: 1
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: private/anvil: wanted attribute: rate
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: input attribute name: rate
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: input attribute value: 1
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: private/anvil: wanted attribute: (list terminator)
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: input attribute name: (end)
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: > unknown[10.0.0.20]: 220 mail.test.com ESMTP Postfix
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: smtp_get: EOF
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: match_hostname: unknown ~? 127.0.0.0/24
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: match_hostaddr: 10.0.0.20 ~? 127.0.0.0/24
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: match_hostname: unknown ~? 10.20.30.0/24
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: match_hostaddr: 10.0.0.20 ~? 10.20.30.0/24
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: match_hostname: unknown ~? 10.110.10.0/24
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: match_hostaddr: 10.0.0.20 ~? 10.110.10.0/24
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: match_list_match: unknown: no match
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: match_list_match: 10.0.0.20: no match
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: send attr request = disconnect
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: send attr ident = smtp:10.0.0.20
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: private/anvil: wanted attribute: status
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: input attribute name: status
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: input attribute value: 0
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: private/anvil: wanted attribute: (list terminator)
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: input attribute name: (end)
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: lost connection after CONNECT from unknown[10.0.0.20]
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: disconnect from unknown[10.0.0.20]
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: master_notify: status 1
Jun 13 16:07:46 crm-mail postfix/smtpd[6372]: connection closed
发表于 2008-6-13 21:24:50 | 显示全部楼层
感觉像正常的调试信息。
都是从10.0.0.20来的吗?
回复 支持 反对

使用道具 举报

您需要登录后才可以回帖 登录 | 注册

本版积分规则

快速回复 返回顶部 返回列表