WelcomeWelcome | FAQFAQ | DownloadsDownloads | WikiWiki

Author Topic: Strange logs showing in /var/log/samba  (Read 3936 times)

Offline PingPing

  • Jr. Member
  • **
  • Posts: 99
Strange logs showing in /var/log/samba
« on: July 07, 2009, 08:45:23 AM »
I took a quick look at the logs in /var/log/samba and noticed I had loads from machines I don't recognise, eg.:


My /etc/samba/smb.conf has the line "logfile = /var/log/samba/log.%m"
and I only have three machines on my network (hostnames):


I'm concerned that I've had a break-in/been cracked.
Looking at some of the logs there are lots of things like:

getpeername failed. Error was Transport endpoint is not connected
  read_socket_with_timeout: client read error = Connection reset by peer.

[2009/06/29 11:11:49,  1] smbd/service.c:make_connection(1284)
  make_connection: refusing to connect with no session setup

The server sits behind my firewall/gateway and the only port open is 80 (I run my busybox httpd on the same machine as samba).

Am I the victim of a bot net?