OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
"lost connection after CONNECT" in logs

From: Artem Bokhan (artistacadem.org)
Date: Mon Aug 13 2007 - 06:42:43 CDT


I've got strange entries in postfix's logs:

Aug 13 18:25:41 postfix-mx/smtpd-mx[28394]: connect from
localhost[127.0.0.1]
Aug 13 18:25:41 postfix-mx/smtpd-mx[28394]: lost connection after
CONNECT from localhost[127.0.0.1]
Aug 13 18:25:41 postfix-mx/smtpd-mx[28394]: disconnect from
localhost[127.0.0.1]
Aug 13 18:25:41 postfix-mx/smtpd-mx[27321]: connect from
localhost[127.0.0.1]
Aug 13 18:25:41 postfix-mx/smtpd-mx[27321]: lost connection after
CONNECT from localhost[127.0.0.1]
Aug 13 18:25:41 postfix-mx/smtpd-mx[27321]: disconnect from
localhost[127.0.0.1]
Aug 13 18:25:45 postfix-mx/smtpd-mx[20354]: connect from
localhost[127.0.0.1]
Aug 13 18:25:45 postfix-mx/smtpd-mx[20354]: warning: Connection rate
limit exceeded: 51 from localhost[127.0.0.1] for service 0.0.0.0:2527
Aug 13 18:25:45 postfix-mx/smtpd-mx[20354]: disconnect from
localhost[127.0.0.1]
Aug 13 18:26:17 postfix-mx/smtpd-mx[27303]: connect from
localhost[127.0.0.1]
Aug 13 18:26:17 postfix-mx/smtpd-mx[27303]: warning: Connection rate
limit exceeded: 52 from localhost[127.0.0.1] for service 0.0.0.0:2527
Aug 13 18:26:17 postfix-mx/smtpd-mx[27303]: disconnect from
localhost[127.0.0.1]

According to tcpdump and iptables counters, nobody connects to service
0.0.0.0:2527 with 127.0.0.1 source address. What is the possible reason
of such behaviour?..

postfix 2.4.0,
Linux 2.6.15-26-amd64-server #1 SMP Thu Aug 3 03:32:26 UTC 2006 x86_64
GNU/Linux

master.cf cut:

0.0.0.0:2527 inet n - n - 800
smtpd-mx -o smtpd_proxy_filter=127.0.0.1:1125
                                                                                
-o smtpd_end_of_data_restrictions=