<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Lost Entropy &#187; internet</title>
	<atom:link href="http://lostentropy.com/tag/internet/feed/" rel="self" type="application/rss+xml" />
	<link>http://lostentropy.com</link>
	<description>Aaron B. Russell&#039;s personal blog</description>
	<lastBuildDate>Fri, 06 Jan 2012 02:54:46 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Strange POP3 traffic from Google?</title>
		<link>http://lostentropy.com/2009/04/12/strange-pop3-traffic-from-google/</link>
		<comments>http://lostentropy.com/2009/04/12/strange-pop3-traffic-from-google/#comments</comments>
		<pubDate>Sun, 12 Apr 2009 09:07:35 +0000</pubDate>
		<dc:creator>Aaron B. Russell</dc:creator>
				<category><![CDATA[Posts]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[POP3]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[servers]]></category>

		<guid isPermaLink="false">http://lostentropy.com/?p=2308</guid>
		<description><![CDATA[I just read a daily email from Logwatch to find some very strange messages&#8230; dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.208, lip=my.ip.ad.dr: 1 Time(s) dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.210, lip=my.ip.ad.dr: 3 Time(s) dovecot: pop3-login: Disconnected (no auth attempts): &#8230; <a href="http://lostentropy.com/2009/04/12/strange-pop3-traffic-from-google/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:60px;'><a class='shareaholic-fblike' data-shr_layout='box_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Flostentropy.com%2F2009%2F04%2F12%2Fstrange-pop3-traffic-from-google%2F' data-shr_title='Strange+POP3+traffic+from+Google%3F'></a><a class='shareaholic-tweetbutton' data-shr_count='vertical' data-shr_href='http%3A%2F%2Flostentropy.com%2F2009%2F04%2F12%2Fstrange-pop3-traffic-from-google%2F' data-shr_title='Strange+POP3+traffic+from+Google%3F'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetTop Automatic --><p><a title="Search cat" href="http://flickr.com/photos/35237098471@N01/6734519"><img src="http://farm1.static.flickr.com/8/6734519_569a7e0947.jpg" alt="" width="405" height="335" /></a><br />
I just read a daily email from Logwatch to find some very strange messages&#8230;</p>
<blockquote><p><code>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.208, lip=my.ip.ad.dr: 1 Time(s)</code></p>
<p><code>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.210, lip=my.ip.ad.dr: 3 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.211, lip=my.ip.ad.dr: 1 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.212, lip=my.ip.ad.dr: 1 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.213, lip=my.ip.ad.dr: 1 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.214, lip=my.ip.ad.dr: 1 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.216, lip=my.ip.ad.dr: 2 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.217, lip=my.ip.ad.dr: 1 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.218, lip=my.ip.ad.dr: 2 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.219, lip=my.ip.ad.dr: 2 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.220, lip=my.ip.ad.dr: 1 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.221, lip=my.ip.ad.dr: 4 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.225, lip=my.ip.ad.dr: 3 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.227, lip=my.ip.ad.dr: 3 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.228, lip=my.ip.ad.dr: 1 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.232, lip=my.ip.ad.dr: 1 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.234, lip=my.ip.ad.dr: 1 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.235, lip=my.ip.ad.dr: 2 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.236, lip=my.ip.ad.dr: 5 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.237, lip=my.ip.ad.dr: 1 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.238, lip=my.ip.ad.dr: 1 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.239, lip=my.ip.ad.dr: 2 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.240, lip=my.ip.ad.dr: 2 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.241, lip=my.ip.ad.dr: 2 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.244, lip=my.ip.ad.dr: 1 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.245, lip=my.ip.ad.dr: 1 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.246, lip=my.ip.ad.dr: 1 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.248, lip=my.ip.ad.dr: 1 Time(s)</p>
<p>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.249, lip=my.ip.ad.dr: 1 Time(s)</p>
<p></code><code>dovecot: pop3-login: Disconnected (no auth attempts): rip=209.85.198.251, lip=my.ip.ad.dr: 1 Time(s)</code></p></blockquote>
<p>Okay, so let&#8217;s list the strange events here:</p>
<ul>
<li>A whole bunch of sequential IPs are connecting to my POP3 port (not necessarily in order, perhaps Logwatch is just picking them out that way)</li>
<li>The remote machines are connecting, but not even attempting to authenticate (log in), they&#8217;re just disconnecting</li>
<li>The IP range is apparently <a style="text-decoration: none;" href="http://www.robtex.com/dns/rv-out-0304.google.com.html">owned by Google</a></li>
</ul>
<p>So&#8230; what&#8217;s going on here, exactly? Anyone able to shed some light onto this?</p>
<div class="shr-publisher-2308"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://lostentropy.com/2009/04/12/strange-pop3-traffic-from-google/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>

