Legacy May Kill, (Sun, Aug 3rd)

Just saw something that I thought was long gone. The username “pop3user” is showing up in our telnet/ssh logs. I don't know how long ago it was that I used POP3 to retrieve e-mail from one of my mail servers. IMAP and various webmail systems have long since replaced this classic email protocol. But at least this one attacker is counting on someone still having a “pop3user” configured.

This article has been indexed from SANS Internet Storm Center, InfoCON: green

Read the original article: