hi together, today i found some interesting entries in my warn-log: Sep 24 14:51:20 host sendmail[13594]: OAA13594: forward /bin/false/.forward.host: Not a directory Sep 24 14:51:20 host sendmail[13594]: OAA13594: forward /bin/false/.forward: Not a directory Sep 24 14:51:20 host sendmail[13596]: OAA13594: forward /bin/false/.forward.host: Not a directory Sep 24 14:51:20 host sendmail[13596]: OAA13594: forward /bin/false/.forward: Not a directory Sep 24 16:14:04 host sendmail[14191]: QAA14190: forward /bin/false/.forward.host: Not a directory Sep 24 16:14:04 host sendmail[14191]: QAA14190: forward /bin/false/.forward: Not a directory Sep 24 16:40:51 host (squid)[353]: WARNING: DNSSERVER #3 (FD 8) exited Sep 21 16:40:51 host popper[14309]: warning: can't get client address: Connection reset by peer Sep 24 16:40:52 host popper[14336]: warning: can't get client address: Connection reset by peer Sep 24 17:07:50 host sendmail[14525]: RAA14524: forward /bin/false/.forward.host: Not a directory Sep 24 17:07:50 host sendmail[14525]: RAA14524: forward /bin/false/.forward: Not a directory any normal user connecting to the system (intern/extern) can't use a valid shell (just /bin/false). what's going on? some kind of attack? i think i am a little bit paranoid since i am reading this mailing list...:-) thanks and bye, daniel