Gentoo Archives: gentoo-user

From: Alan McKinnon <alan.mckinnon@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Can't block pop3 attack
Date: Fri, 23 Oct 2009 20:58:14
Message-Id: 200910232257.09736.alan.mckinnon@gmail.com
In Reply to: [gentoo-user] Can't block pop3 attack by Robin Atwood
1 On Friday 23 October 2009 21:49:42 Robin Atwood wrote:
2 > My syslog is showing zillions of messages:
3 >
4 > Oct 24 02:25:58 opal xinetd[8054]: START: pop-3 pid=16534
5 > from=61.134.64.199 Oct 24 02:25:59 opal xinetd[16534]: warning:
6 > /etc/hosts.allow, line 7: can't verify hostname:
7 > gethostbyname(199.64.134.61.broad.gs.dynamic.163data.com.cn) failed
8 > Oct 24 02:26:09 opal xinetd[8054]: EXIT: pop-3 status=0 pid=16534
9 > duration=11(sec)
10 >
11 > I run denyhosts but don't trap pop3 messages so I manually added the IP
12 > address to /etc/hosts.deny and..., it made absolutely no difference. I run
13 > qpopper which is compiled with xinetd support and xinetd uses tcpd, so I
14 > assumed the address would be blocked. Apparently not so. Any ideas?
15
16
17 You have allow ALL ALL early in hosts.allow, or
18 you have allow pop3 all earlier in hosts.allow
19
20 --
21 alan dot mckinnon at gmail dot com

Replies

Subject Author
Re: [gentoo-user] Can't block pop3 attack Robin Atwood <robin.atwood@×××××××××.net>