OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: "connect from localhost" messages in the log

From: Reggie Sniff (rsniffamllc.com)
Date: Wed Jan 10 2007 - 10:20:58 CST


I am running RHEL3, with postfix-2.2.11-1
I upgraded Postfix last night (from postfix-2.0.16-14.RHEL3, which was the
default "latest" version for RedHat EL3.)

The only other App processes we have running are Apache and MySQL. We have
the "standard" kernel processes but that's about it.
I just noticed that 'smartd' and 'rhnsd' were also running, so I just
stopped them for now.

I guess I will have to write something that can monitor and dump the
traffic.

I'll update if/when I can figure it out.

Reg
----- Original Message -----
From: "Rene van Hoek" <reneactive8.nl>
To: "Postfix users" <postfix-userspostfix.org>
Sent: Wednesday, January 10, 2007 1:22 AM
Subject: Re: "connect from localhost" messages in the log

>
> Reggie Sniff wrote:
>> Can anybody suggest as to why we get these regular connections? I can't
>> figure out where they are coming from...
>> We aren't running any other mail processes other than postfix, so I
>> cannot figure what is connecting g line this.
>>
>> Jan 8 07:12:26 rp1 postfix/smtpd[9504]: connect from
>> localhost[127.0.0.1]
>> Jan 8 07:12:26 rp1 postfix/smtpd[9504]: lost connection after CONNECT
>> from localhost[127.0.0.1]
>> Jan 8 07:12:26 rp1 postfix/smtpd[9504]: disconnect from
>> localhost[127.0.0.1]
>>
>> When I try
>> # telnet localhost 25
>>
>> The logging is somewhat different as it now includes ".localdomain":
>> Jan 9 22:57:18 rp1 postfix/smtpd[7523]: connect from
>> localhost.localdomain[127.0.0.1]
>> Jan 9 22:57:20 rp1 postfix/smtpd[7523]: disconnect from
>> localhost.localdomain[127.0.0.1]
>>
>>
>> Thanks,
>>
>> Reggie
>>
>
> Hi,
>
> I have an similair problem, but I can't pinpoint it.
>
> See thread:
> http://groups.google.nl/group/list.postfix.users/browse_frm/thread/8cb267934f60414e/703239152552989b?tvc=1&q=postfix+connect+from+localhost%5B127.0.0.1%5D&hl=nl#703239152552989b
>
> I have written an python script which act as policy-server. This script
> dumps output from ps, sockstat, etc. So far, I did not see anything
> relevant.
>
> I am running FreeBSD 6.1-RELEASE-p11 and Postfix 2.3.4
>
> Which OS and Postfix version are you running? If you discover anything,
> please let me know.
>
> Greetings,
>
> Rene van Hoek
> rene active8 nl
>
>
>