[Exim] Attacker?? odd log entry (repeatedly but not steadil…

Top Page
Delete this message
Reply to this message
Author: John W Baxter
Date:  
To: exim-users
Subject: [Exim] Attacker?? odd log entry (repeatedly but not steadily)
I'm seeing instances of entries like the one below. The text in
parentheses "(smtp.olympus.net)" is the name (one of the names) of our
server. Does the log entry mean that 134.39.36.217 is using HELO/EHLO
smtp.olympus.net ?

2002-10-17 09:26:58 SMTP call from (smtp.olympus.net) [134.39.36.217]
dropped: too many unrecognized commands

The last identified host in a traceroute to the address is
Domain Name: CTC.EDU

Registrant:
Center for Information Services
3101 Nothup Way, Suite 100
Bellevue, WA 98004
UNITED STATES

(whose street address is wrongly spelt in the registration...Northup).

Do the above entry or this entity ring any bells. (They're within mortar
range, but that seems extreme.)

--John

--
John Baxter   jwblist@???      Port Ludlow, WA, USA