Hi, I have a couple of these in my logs: Apr 29 05:01:03 p15089763 PAM-warn[19900]: user: (uid=0) -> admin [remote: ?nobody@?nowhere] Apr 29 05:01:03 p15089763 server [218.79.178.192] cmd read[19900]: NOQUEUE: [218.79.178.192] did not issue MAIL/EXPN/VRFY/ETRN during connection to MTA They repeat 14 times within 2 minutes. Afterward I see just one of the above two lines: Apr 29 05:01:49 p15089763 server [218.79.178.192] cmd read[19922]: NOQUEUE: [218.79.178.192] did not issue MAIL/EXPN/VRFY/ETRN during connection to MTA They repeat 110 times within 13 minutes. What triggered these logging messages? 218.79.178.192 is the IP of an attacker. He also did an extensive port scan, tried for some httpd security holes and so on. Best regards, Matthias -- See header for e-mail address and name.