I saw the following odd log in my daily exim Rejected Mail. Why and
how would this be generated? This is indeed the /etc/group file from
my machine, followed by a chunk from /etc/services. I'm puzzled by how
this information came as an input from a machine in .ch
Anyone have any ideas about what's underway here? Thanks!
2005-04-25 23:08:20 SMTP protocol violation: synchronization error
(input sent without waiting for greeting): rejected connection from
H=80-219-86-130.dclient.hispeed.ch [80.219.86.130] input="# $FreeBSD:
src/etc/group,v 1.19.2.3 2002/06/30 17:57:17 des Exp
$\n#\nwheel:*:0:root,paimin\ndaemon:*:1:daemon\nkmem:*:2:root\nsys:*:3:
root\ntty:*:4:root\noperator:*:5:root\nmail:*:6:paimin,clamav\nbin:*:7:
\nnews:*:8:\nman:*:9:\ngames:*:13:\nstaff:*:20:root\nsshd:*:22:\nsmmsp:
*:25:\nmailnull:*:26:\nguest:*:31:root\nbind:*:53:\nuucp:*:66:\nxten:*:
67:xten\ndialer:*:68:\nnetwork:*:69:\nnogroup:*:65533:\nnobody:*:65534:
\nantsclimbtree:*:1001:\nzmrzlina:*:1002:\nwww:*:80:\nzmrzlinamail::
1000:\njimgaylord::1003:\nmarthasue::1004:\nmailman:*:91:\ngdm:*:92:
\nspam::65525:\neximedit::1005:zmrzlina,paimin\nmarvin::1008:
\nshellaccess::1009:
antsclimbtree,marthasue,jimgaylord,marvin,paimin,zmrzlina,jimgsftp,ben,m
cadmin\nftpusers::1011:
ftp,jimgftp,antftp,zmrftp,marthaftp,kelly,amnorftp,m4kftp,wedding,radius
ftp,radiusadmin,benftp,daphne,minegen,ctpappels,durgas,mcftp\nkelly::
1006:\nclamav:*:1012:\npublicftp:*:1007:\nben::1010:\nmrtg::1013:
\nminegen::1014:\nctpappels::1015:\nmysql:*:88:\ndhcpd:*:1016:
\ndurgas::1017:\nmcadmin::1018:\ndp #Name Binding
Protocol\ncompressnet 2/tcp #Management Utility\ncompressnet
2/udp #Management Utility\ncompressnet 3/tcp #Compression
Process\ncompressnet 3/udp #Compression Process\necho 4/ddp
#AppleTalk Echo Protocol\nrje 5/tcp #Remote Job Entry\nrje
5/udp #Remote Job Entry\nzip 6/ddp #Zone Information
Protocol\necho 7/tcp\necho 7/udp\ndiscard 9/tcp sink
null\ndiscard 9/udp sink null\nsystat 11/tcp users #Active
Users\nsystat 11/udp users #Active Users\ndaytime
13/tcp\ndaytime 13/udp\nqotd 17/tcp quote #Quote of the
Day\nqotd 17/udp quote #Quote of the Day\nmsp 18/tcp #Message
Send Protocol\nmsp 18/udp #Message Send Protocol\nchargen
19/tcp ttytst source #Character Generator\nchargen 19/udp
ttytst source #Character Generator\nftp-data 20/tcp #File Transfer
[Default Data]\nftp-data 20/udp #File Transfer [Default
Data]\nftp 21/tcp #File Transfer [Control]\nftp 21/udp #File
Transfer [Control]\nssh 22/tcp #Secure Shell Login\nssh 22/udp
#Secure Shell Login\ntelnet 23/tcp\ntelnet 23/udp\n# 24/tcp
any private mail system\n# 24/udp any private mail system\nsmtp
25/tcp mail #Simple Mail Transfer\nsmtp 25/udp mail #Simple
Mail Transfer\nnsw-fe 27/tcp #NSW User System FE\nnsw-fe 27/udp
#NSW User System FE\nmsg-icp 29/tcp #MSG ICP\nmsg-icp 29/udp
#MSG ICP\nmsg-auth 31/tcp #MSG Authentication\nmsg-auth 31/udp
#MSG Authentication\ndsp 33/tcp #Display Support Protocol\ndsp
33/udp #Display Support Protocol\n# 35/tcp any private printer
server\n# 35/udp any private printer server\ntime 37/tcp
timserver\ntime 37/udp timserver\nrap 38/tcp #Route Access
Protocol\nrap 38/udp #Route Access Protocol\nrlp 39/tcp
resource #Resource Location Protocol\nrlp 39/udp
resource #Resource Location Protocol\ngraphics 41/tcp\ngraphics
41/udp\nnameserver 42/tcp name #Host Name Server\nnameserver
42/udp name #Host Name Server\nnicname 43/tcp whois\nnicname
43/udp whois\nmpm-flags 44/tcp #MPM FLAGS Protocol\nmpm-flags
44/udp #MPM FLAGS Protocol\nmpm 45/tcp #Message Processing
Module [recv]\nmpm 45/udp #Message Processing Module
[recv]\nmpm-snd 46/tcp #MPM [default send]\nmpm-snd 46/udp
#MPM [default send]\nni-ftp 47/tcp #NI FTP\nni-ftp 47/udp #NI
FTP\nauditd 48/tcp #Digital Audit Daemon\nauditd 48/udp
#Digital Audit Daemon\ntacacs 49/tcp #Login Host Protocol
(TACACS)\ntacacs 49/udp #Login Host Protocol (TACACS)\nre-mail-ck
50/tcp #Remote Mail Checking Protocol\nre-mail-ck 50/udp #Remote
Mail Checking Protocol\nla-maint 51/tcp #IMP Logical Address
Maintenance\nla-maint 51/udp #IMP Logical Address
Maintenance\nxns-time 52/tcp #XNS Time Protocol\nxns-time 52/udp
#XNS Time Protocol\ndomain 53/tcp #Domain Name Server\ndomain
53/udp #Domain Name Server\nxns-ch 54/tcp #XNS
Clearinghouse\nxns-ch 54/udp #XNS Clearinghouse\nisi-gl 55/tcp
#ISI Graphics Language\nisi-gl 55/udp #ISI Graphics
Language\nxns-auth 564"
--
Mark Edwards
mark@???
Ortelius Straat 341, 2nd Floor
1056 PB Amsterdam
Netherlands
cell: +31649078949