Apr 14 14:49:30 rakete sendmail[22485]: OAA22485: ruleset=check_mail,
arg1=<hu...@hurz.com>, relay=49-203.B.dial.o-tel-o.net [212.144.49.203],
reject=451 <hu...@hurz.com>... Sender domain must resolve
Apr 14 14:49:30 rakete sendmail[22485]: OAA22485: from=<hu...@hurz.com>,
size=0, class=0, pri=0, nrcpts=0, proto=ESMTP,
relay=49-203.B.dial.o-tel-o.net [212.144.49.203]
or
Apr 15 01:35:09 rakete sendmail[23951]: BAA23951: from=<hu...@hurz.com>,
size=0, class=0, pri=0, nrcpts=0, proto=ESMTP,
relay=ro...@48-60.B.dial.o-tel-o.net [212.144.48.60]
or
Apr 15 01:38:54 rakete sendmail[23961]: BAA23961: ruleset=check_mail,
arg1=<hu...@hurz.com>, relay=root@[212.144.54.56],reject=451
<hu...@hurz.com>... Sender domain must resolve
Apr 15 01:38:54 rakete sendmail[23961]: BAA23961: from=<hu...@hurz.com>,
size=0, class=0, pri=0, nrcpts=0, proto=ESMTP, relay=root@[212.144.54.56]
Yesterday we managed to run a portscan on one of those IP addresses and it
looked like a badly configured NT box (ftp, http, smtp, netbios all open, we
even got a password prompt to access the sever via smb) running a David
mailserver software. Then again, the relay=root@[212.144.54.56] line
suggests that someone is playing with a, presumably, Linux box. What is this
hurz trying to do?
cheers frank