[Solved] Unreal POP3 Stats
A domain has recently started reporting extremely high POP3 Out statistics. Plesk is reporting between 8 and 10 gigabytes of data for our POP3 Out per night! I don't really know how to read the logs but I believe the inflated reporting is caused by a single account on the affected domain. The suspect account - from the logs:
For comparison, this is another user on the domain:
If I understand correctly, the user1 account performs a login, transfers 23MB of data and is disconnected after 30 seconds. Whereas the user2 account performs a login, sees no new mail and logs out.
What could be the problem? Could it be compromised? Could the client have changed settings and we're seeing IMAP traffic instead of POP3 (sorry, I'm not real familiar with these logs)?
A domain has recently started reporting extremely high POP3 Out statistics. Plesk is reporting between 8 and 10 gigabytes of data for our POP3 Out per night! I don't really know how to read the logs but I believe the inflated reporting is caused by a single account on the affected domain. The suspect account - from the logs:
May 11 11:21:18 web1 pop3d: IMAP connect from @ [xxx.xxx.xxx.xxx]INFO: LOGIN, [email protected], ip=[xxx.xxx.xxx.xxx]
May 11 11:21:52 web1 pop3d: 1336753312.107644 DISCONNECTED, [email protected], ip=[xxx.xxx.xxx.xxx], top=0, retr=22795503, time=34, rcvd=50, sent=23092177, maildir=/var/qmail/mailnames/domain.com/user1/Maildir
For comparison, this is another user on the domain:
May 11 11:30:34 web1 pop3d: IMAP connect from @ [xxx.xxx.xxx.xxx]INFO: LOGIN, [email protected], ip=[xxx.xxx.xxx.xxx]
May 11 11:30:34 web1 pop3d: 1336753834.615746 LOGOUT, [email protected], ip=[xxx.xxx.xxx.xxx], top=0, retr=0, time=0, rcvd=12, sent=39, maildir=/var/qmail/mailnames/domain.com/user2/Maildir
If I understand correctly, the user1 account performs a login, transfers 23MB of data and is disconnected after 30 seconds. Whereas the user2 account performs a login, sees no new mail and logs out.
What could be the problem? Could it be compromised? Could the client have changed settings and we're seeing IMAP traffic instead of POP3 (sorry, I'm not real familiar with these logs)?
Last edited: