diff --git a/decnet.log b/decnet.log new file mode 100644 index 0000000..07dbe11 --- /dev/null +++ b/decnet.log @@ -0,0 +1,159 @@ +<134>1 2026-04-04T07:40:53.045660+00:00 decky-devops k8s - startup - Kubernetes API server starting as decky-devops +<134>1 2026-04-04T07:40:53.058000+00:00 decky-devops docker_api - startup - Docker API server starting as decky-devops +<134>1 2026-04-04T07:40:53.147349+00:00 decky-legacy vnc - startup - VNC server starting as decky-legacy +<134>1 2026-04-04T07:40:53.224094+00:00 decky-fileserv tftp - startup - TFTP server starting as decky-fileserv +<134>1 2026-04-04T07:40:53.231313+00:00 decky-fileserv ftp - startup - FTP server starting as decky-fileserv on port 21 +<134>1 2026-04-04T07:40:53.237175+00:00 decky-fileserv smb - startup - SMB server starting as decky-fileserv +<134>1 2026-04-04T07:40:53.331998+00:00 decky-webmail imap - startup - IMAP server starting as decky-webmail +<134>1 2026-04-04T07:40:53.441710+00:00 decky-webmail http - startup - HTTP server starting as decky-webmail +<134>1 2026-04-04T07:40:53.482287+00:00 decky-webmail smtp - startup - SMTP server starting as decky-webmail +<134>1 2026-04-04T07:40:53.487752+00:00 decky-webmail pop3 - startup - POP3 server starting as decky-webmail +<134>1 2026-04-04T07:40:53.493478+00:00 decky-iot mqtt - startup - MQTT server starting as decky-iot +<134>1 2026-04-04T07:40:53.519136+00:00 decky-iot snmp - startup - SNMP server starting as decky-iot +<134>1 2026-04-04T07:40:53.586186+00:00 decky-voip sip - startup - SIP server starting as decky-voip +<134>1 2026-04-04T07:40:53.734237+00:00 decky-dbsrv02 postgres - startup - PostgreSQL server starting as decky-dbsrv02 +<134>1 2026-04-04T07:40:53.746573+00:00 decky-voip llmnr - startup - LLMNR/mDNS server starting as decky-voip +<134>1 2026-04-04T07:40:53.792767+00:00 decky-dbsrv02 elasticsearch - startup - Elasticsearch server starting as decky-dbsrv02 +<134>1 2026-04-04T07:40:53.817558+00:00 decky-dbsrv02 mongodb - startup - MongoDB server starting as decky-dbsrv02 +<134>1 2026-04-04T07:40:53.848912+00:00 decky-ldapdc ldap - startup - LDAP server starting as decky-ldapdc +<134>1 2026-04-04T07:40:53.860378+00:00 decky-winbox rdp - startup - RDP server starting as decky-winbox on port 3389 +<134>1 2026-04-04T07:40:53.911084+00:00 decky-winbox mssql - startup - MSSQL server starting as decky-winbox +<134>1 2026-04-04T07:40:53.978994+00:00 decky-winbox smb - startup - SMB server starting as decky-winbox +<134>1 2026-04-04T07:41:07.439918+00:00 decky-webmail pop3 - connect [decnet@55555 src="192.168.1.5" src_port="46462"] +<134>1 2026-04-04T07:41:07.439922+00:00 decky-webmail imap - connect [decnet@55555 src="192.168.1.5" src_port="54734"] +<134>1 2026-04-04T07:41:07.439868+00:00 decky-webmail smtp - connect [decnet@55555 src="192.168.1.5" src_port="54606"] +<134>1 2026-04-04T07:41:07.440333+00:00 decky-fileserv ftp - connection [decnet@55555 src_ip="192.168.1.5" src_port="39736"] +<134>1 2026-04-04T07:41:07.442465+00:00 decky-webmail smtp - disconnect [decnet@55555 src="192.168.1.5"] +<134>1 2026-04-04T07:41:13.446744+00:00 decky-webmail imap - command [decnet@55555 src="192.168.1.5" cmd="GET / HTTP/1.0"] +<134>1 2026-04-04T07:41:13.446743+00:00 decky-webmail pop3 - command [decnet@55555 src="192.168.1.5" cmd=""] +<134>1 2026-04-04T07:41:13.447251+00:00 decky-webmail pop3 - command [decnet@55555 src="192.168.1.5" cmd=""] +<134>1 2026-04-04T07:41:13.446995+00:00 decky-webmail http - request [decnet@55555 method="GET" path="/" remote_addr="192.168.1.5" headers="{}" body=""] +<134>1 2026-04-04T07:41:13.447556+00:00 decky-fileserv ftp - disconnect [decnet@55555 src_ip="192.168.1.5" src_port="39736"] +<134>1 2026-04-04T07:41:18.451412+00:00 decky-webmail imap - disconnect [decnet@55555 src="192.168.1.5"] +<134>1 2026-04-04T07:41:18.451529+00:00 decky-webmail pop3 - disconnect [decnet@55555 src="192.168.1.5"] +<134>1 2026-04-04T07:41:18.451729+00:00 decky-webmail imap - connect [decnet@55555 src="192.168.1.5" src_port="55996"] +<134>1 2026-04-04T07:41:18.451746+00:00 decky-webmail pop3 - connect [decnet@55555 src="192.168.1.5" src_port="36592"] +<134>1 2026-04-04T07:41:18.451844+00:00 decky-webmail pop3 - command [decnet@55555 src="192.168.1.5" cmd="OPTIONS / HTTP/1.0"] +<134>1 2026-04-04T07:41:18.451928+00:00 decky-webmail pop3 - command [decnet@55555 src="192.168.1.5" cmd=""] +<134>1 2026-04-04T07:41:23.456442+00:00 decky-webmail pop3 - disconnect [decnet@55555 src="192.168.1.5"] +<134>1 2026-04-04T07:41:23.456408+00:00 decky-webmail imap - disconnect [decnet@55555 src="192.168.1.5"] +<134>1 2026-04-04T07:41:24.734697+00:00 decky-webmail pop3 - connect [decnet@55555 src="192.168.1.5" src_port="36604"] +<134>1 2026-04-04T07:41:24.736542+00:00 decky-webmail pop3 - connect [decnet@55555 src="192.168.1.5" src_port="36606"] +<134>1 2026-04-04T07:41:24.737069+00:00 decky-webmail smtp - connect [decnet@55555 src="192.168.1.5" src_port="56204"] +<134>1 2026-04-04T07:41:24.737449+00:00 decky-fileserv ftp - connection [decnet@55555 src_ip="192.168.1.5" src_port="48992"] +<134>1 2026-04-04T07:41:24.737834+00:00 decky-fileserv ftp - connection [decnet@55555 src_ip="192.168.1.5" src_port="48994"] +<134>1 2026-04-04T07:41:24.738282+00:00 decky-fileserv ftp - connection [decnet@55555 src_ip="192.168.1.5" src_port="49002"] +<134>1 2026-04-04T07:41:24.738760+00:00 decky-fileserv ftp - connection [decnet@55555 src_ip="192.168.1.5" src_port="49004"] +<134>1 2026-04-04T07:41:24.739240+00:00 decky-webmail pop3 - connect [decnet@55555 src="192.168.1.5" src_port="36622"] +<134>1 2026-04-04T07:41:24.741300+00:00 decky-webmail pop3 - command [decnet@55555 src="192.168.1.5" cmd="STLS"] +<134>1 2026-04-04T07:41:24.741346+00:00 decky-webmail pop3 - command [decnet@55555 src="192.168.1.5" cmd="STLS"] +<134>1 2026-04-04T07:41:24.741319+00:00 decky-webmail smtp - ehlo [decnet@55555 src="192.168.1.5" domain="nmap.scanme.org"] +<134>1 2026-04-04T07:41:24.741391+00:00 decky-fileserv ftp - user [decnet@55555 username="anonymous"] +<134>1 2026-04-04T07:41:24.741474+00:00 decky-fileserv ftp - user [decnet@55555 username="anonymous"] +<134>1 2026-04-04T07:41:24.741374+00:00 decky-webmail http - request [decnet@55555 method="GET" path="/nmaplowercheck1775288484" remote_addr="192.168.1.5" headers="{'Host': '192.168.1.110', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Connection': 'close'}" body=""] +<134>1 2026-04-04T07:41:24.741566+00:00 decky-webmail http - request [decnet@55555 method="GET" path="/.git/HEAD" remote_addr="192.168.1.5" headers="{'Host': '192.168.1.110', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Connection': 'close'}" body=""] +<134>1 2026-04-04T07:41:24.741988+00:00 decky-webmail http - request [decnet@55555 method="OPTIONS" path="/" remote_addr="192.168.1.5" headers="{'Host': '192.168.1.110', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Connection': 'close'}" body=""] +<134>1 2026-04-04T07:41:24.742327+00:00 decky-webmail http - request [decnet@55555 method="PROPFIND" path="/" remote_addr="192.168.1.5" headers="{'Depth': '0', 'Host': '192.168.1.110', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Connection': 'close'}" body=""] +<134>1 2026-04-04T07:41:24.742608+00:00 decky-webmail http - request [decnet@55555 method="POST" path="/" remote_addr="192.168.1.5" headers="{'Content-Length': '88', 'Connection': 'close', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Content-Type': 'application/x-www-form-urlencoded', 'Host': '192.168.1.110'}" body=" system.listMethods "] +<134>1 2026-04-04T07:41:24.742807+00:00 decky-webmail http - request [decnet@55555 method="GET" path="/" remote_addr="192.168.1.5" headers="{'Host': '192.168.1.110', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Connection': 'close'}" body=""] +<134>1 2026-04-04T07:41:24.741701+00:00 decky-webmail http - request [decnet@55555 method="GET" path="/" remote_addr="192.168.1.5" headers="{}" body=""] +<134>1 2026-04-04T07:41:24.742699+00:00 decky-webmail http - request [decnet@55555 method="OPTIONS" path="/" remote_addr="192.168.1.5" headers="{'Host': '192.168.1.110', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Connection': 'close'}" body=""] +<134>1 2026-04-04T07:41:24.742135+00:00 decky-webmail http - request [decnet@55555 method="POST" path="/sdk" remote_addr="192.168.1.5" headers="{'Content-Length': '441', 'Host': '192.168.1.110', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Connection': 'close'}" body="00000001-00000001<_this xsi:type=\"ManagedObjectReference\" type=\"ServiceInstance\">ServiceInstance"] +<134>1 2026-04-04T07:41:24.742460+00:00 decky-webmail http - request [decnet@55555 method="OPTIONS" path="/" remote_addr="192.168.1.5" headers="{'Connection': 'close', 'Origin': 'example.com', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Access-Control-Request-Method': 'HEAD', 'Host': '192.168.1.110'}" body=""] +<134>1 2026-04-04T07:41:24.745408+00:00 decky-webmail pop3 - disconnect [decnet@55555 src="192.168.1.5"] +<134>1 2026-04-04T07:41:24.745793+00:00 decky-webmail pop3 - disconnect [decnet@55555 src="192.168.1.5"] +<134>1 2026-04-04T07:41:24.745837+00:00 decky-webmail pop3 - command [decnet@55555 src="192.168.1.5" cmd="AUTH NTLM"] +<134>1 2026-04-04T07:41:24.745797+00:00 decky-fileserv ftp - user [decnet@55555 username="anonymous"] +<134>1 2026-04-04T07:41:24.745960+00:00 decky-fileserv ftp - auth_attempt [decnet@55555 username="anonymous" password="IEUser@"] +<134>1 2026-04-04T07:41:24.745842+00:00 decky-webmail http - request [decnet@55555 method="FGDH" path="/" remote_addr="192.168.1.5" headers="{'Host': '192.168.1.110', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Connection': 'close'}" body=""] +<134>1 2026-04-04T07:41:24.746083+00:00 decky-webmail smtp - connect [decnet@55555 src="192.168.1.5" src_port="56216"] +<134>1 2026-04-04T07:41:24.746041+00:00 decky-webmail imap - connect [decnet@55555 src="192.168.1.5" src_port="56008"] +<134>1 2026-04-04T07:41:24.745961+00:00 decky-webmail http - request [decnet@55555 method="OPTIONS" path="/" remote_addr="192.168.1.5" headers="{'Connection': 'close', 'Origin': 'example.com', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Access-Control-Request-Method': 'GET', 'Host': '192.168.1.110'}" body=""] +<134>1 2026-04-04T07:41:24.746514+00:00 decky-fileserv ftp - auth_attempt [decnet@55555 username="anonymous" password="IEUser@"] +<134>1 2026-04-04T07:41:24.746245+00:00 decky-webmail http - request [decnet@55555 method="GET" path="/NmapUpperCheck1775288484" remote_addr="192.168.1.5" headers="{'Host': '192.168.1.110', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Connection': 'close'}" body=""] +<134>1 2026-04-04T07:41:24.746723+00:00 decky-fileserv ftp - disconnect [decnet@55555 src_ip="192.168.1.5" src_port="48994"] +<134>1 2026-04-04T07:41:24.746073+00:00 decky-webmail http - request [decnet@55555 method="PROPFIND" path="/" remote_addr="192.168.1.5" headers="{'Content-Length': '0', 'Connection': 'close', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Host': '192.168.1.110', 'Depth': '1'}" body=""] +<134>1 2026-04-04T07:41:24.795603+00:00 decky-webmail pop3 - command [decnet@55555 src="192.168.1.5" cmd="TlRMTVNTUAABAAAAB4IIoAAAAAAAAAAAAAAAAAAAAAA="] +<134>1 2026-04-04T07:41:24.795629+00:00 decky-webmail smtp - disconnect [decnet@55555 src="192.168.1.5"] +<134>1 2026-04-04T07:41:24.795621+00:00 decky-webmail imap - connect [decnet@55555 src="192.168.1.5" src_port="56016"] +<134>1 2026-04-04T07:41:24.795604+00:00 decky-fileserv ftp - auth_attempt [decnet@55555 username="anonymous" password="IEUser@"] +<134>1 2026-04-04T07:41:24.795738+00:00 decky-webmail http - request [decnet@55555 method="GET" path="/" remote_addr="192.168.1.5" headers="{'Host': '192.168.1.110', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Connection': 'close'}" body=""] +<134>1 2026-04-04T07:41:24.795928+00:00 decky-webmail http - request [decnet@55555 method="GET" path="/robots.txt" remote_addr="192.168.1.5" headers="{'Host': '192.168.1.110', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Connection': 'close'}" body=""] +<134>1 2026-04-04T07:41:24.796118+00:00 decky-webmail http - request [decnet@55555 method="PROPFIND" path="/" remote_addr="192.168.1.5" headers="{'Depth': '0', 'Host': '192.168.1.110', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Connection': 'close'}" body=""] +<134>1 2026-04-04T07:41:24.845180+00:00 decky-webmail smtp - connect [decnet@55555 src="192.168.1.5" src_port="56226"] +<134>1 2026-04-04T07:41:24.845355+00:00 decky-webmail smtp - ehlo [decnet@55555 src="192.168.1.5" domain="nmap.scanme.org"] +<134>1 2026-04-04T07:41:24.845379+00:00 decky-webmail http - request [decnet@55555 method="OPTIONS" path="/" remote_addr="192.168.1.5" headers="{'Connection': 'close', 'Origin': 'example.com', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Access-Control-Request-Method': 'POST', 'Host': '192.168.1.110'}" body=""] +<134>1 2026-04-04T07:41:24.894554+00:00 decky-webmail pop3 - disconnect [decnet@55555 src="192.168.1.5"] +<134>1 2026-04-04T07:41:24.894871+00:00 decky-webmail http - request [decnet@55555 method="GET" path="/Nmap/folder/check1775288484" remote_addr="192.168.1.5" headers="{'Host': '192.168.1.110', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Connection': 'close'}" body=""] +<134>1 2026-04-04T07:41:24.895133+00:00 decky-webmail http - request [decnet@55555 method="POST" path="/" remote_addr="192.168.1.5" headers="{'Content-Length': '0', 'Host': '192.168.1.110', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Connection': 'close'}" body=""] +<134>1 2026-04-04T07:41:24.944224+00:00 decky-webmail smtp - ehlo [decnet@55555 src="192.168.1.5" domain="nmap.scanme.org"] +<134>1 2026-04-04T07:41:24.944215+00:00 decky-webmail imap - connect [decnet@55555 src="192.168.1.5" src_port="56032"] +<134>1 2026-04-04T07:41:24.944346+00:00 decky-webmail smtp - unknown_command [decnet@55555 src="192.168.1.5" command="HELP"] +<134>1 2026-04-04T07:41:24.994175+00:00 decky-webmail imap - disconnect [decnet@55555 src="192.168.1.5"] +<134>1 2026-04-04T07:41:24.994238+00:00 decky-webmail smtp - connect [decnet@55555 src="192.168.1.5" src_port="56234"] +<134>1 2026-04-04T07:41:24.994534+00:00 decky-webmail http - request [decnet@55555 method="OPTIONS" path="/" remote_addr="192.168.1.5" headers="{'Connection': 'close', 'Origin': 'example.com', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Access-Control-Request-Method': 'PUT', 'Host': '192.168.1.110'}" body=""] +<134>1 2026-04-04T07:41:25.044450+00:00 decky-webmail smtp - auth_attempt [decnet@55555 src="192.168.1.5" command="AUTH NTLM"] +<134>1 2026-04-04T07:41:25.044450+00:00 decky-webmail imap - command [decnet@55555 src="192.168.1.5" cmd="000b AUTHENTICATE NTLM"] +<134>1 2026-04-04T07:41:25.044580+00:00 decky-webmail smtp - disconnect [decnet@55555 src="192.168.1.5"] +<134>1 2026-04-04T07:41:25.044674+00:00 decky-webmail smtp - disconnect [decnet@55555 src="192.168.1.5"] +<134>1 2026-04-04T07:41:25.093812+00:00 decky-webmail smtp - ehlo [decnet@55555 src="192.168.1.5" domain="nmap.scanme.org"] +<134>1 2026-04-04T07:41:25.094022+00:00 decky-webmail http - request [decnet@55555 method="GET" path="/favicon.ico" remote_addr="192.168.1.5" headers="{'Host': '192.168.1.110', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Connection': 'close'}" body=""] +<134>1 2026-04-04T07:41:25.142989+00:00 decky-webmail imap - command [decnet@55555 src="192.168.1.5" cmd="TlRMTVNTUAABAAAAB4IIoAAAAAAAAAAAAAAAAAAAAAA="] +<134>1 2026-04-04T07:41:25.143126+00:00 decky-webmail http - request [decnet@55555 method="OPTIONS" path="/" remote_addr="192.168.1.5" headers="{'Connection': 'close', 'Origin': 'example.com', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Access-Control-Request-Method': 'DELETE', 'Host': '192.168.1.110'}" body=""] +<134>1 2026-04-04T07:41:25.241565+00:00 decky-webmail imap - disconnect [decnet@55555 src="192.168.1.5"] +<134>1 2026-04-04T07:41:25.241690+00:00 decky-webmail imap - disconnect [decnet@55555 src="192.168.1.5"] +<134>1 2026-04-04T07:41:25.290930+00:00 decky-webmail smtp - disconnect [decnet@55555 src="192.168.1.5"] +<134>1 2026-04-04T07:41:25.291070+00:00 decky-webmail http - request [decnet@55555 method="OPTIONS" path="/" remote_addr="192.168.1.5" headers="{'Connection': 'close', 'Origin': 'example.com', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Access-Control-Request-Method': 'TRACE', 'Host': '192.168.1.110'}" body=""] +<134>1 2026-04-04T07:41:25.438930+00:00 decky-webmail http - request [decnet@55555 method="OPTIONS" path="/" remote_addr="192.168.1.5" headers="{'Connection': 'close', 'Origin': 'example.com', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Access-Control-Request-Method': 'OPTIONS', 'Host': '192.168.1.110'}" body=""] +<134>1 2026-04-04T07:41:25.586609+00:00 decky-webmail http - request [decnet@55555 method="OPTIONS" path="/" remote_addr="192.168.1.5" headers="{'Connection': 'close', 'Origin': 'example.com', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Access-Control-Request-Method': 'CONNECT', 'Host': '192.168.1.110'}" body=""] +<134>1 2026-04-04T07:41:25.734144+00:00 decky-webmail http - request [decnet@55555 method="OPTIONS" path="/" remote_addr="192.168.1.5" headers="{'Connection': 'close', 'Origin': 'example.com', 'User-Agent': 'Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)', 'Access-Control-Request-Method': 'PATCH', 'Host': '192.168.1.110'}" body=""] +<134>1 2026-04-04T07:41:29.778527+00:00 decky-fileserv ftp - disconnect [decnet@55555 src_ip="192.168.1.5" src_port="49004"] +<134>1 2026-04-04T07:41:31.976898+00:00 decky-fileserv ftp - disconnect [decnet@55555 src_ip="192.168.1.5" src_port="48992"] +<134>1 2026-04-04T07:41:33.746244+00:00 decky-fileserv ftp - disconnect [decnet@55555 src_ip="192.168.1.5" src_port="49002"] +<134>1 2026-04-04T07:41:33.747544+00:00 decky-webmail imap - connect [decnet@55555 src="192.168.1.5" src_port="39972"] +<134>1 2026-04-04T07:41:33.748339+00:00 decky-webmail http - request [decnet@55555 method="GET" path="/" remote_addr="192.168.1.5" headers="{}" body=""] +<134>1 2026-04-04T07:41:33.748742+00:00 decky-webmail imap - connect [decnet@55555 src="192.168.1.5" src_port="39984"] +<134>1 2026-04-04T07:41:33.748916+00:00 decky-webmail imap - command [decnet@55555 src="192.168.1.5" cmd="($�i��jÁ{Bк�F����(ri[;z �s~_?� �+Ō,7n/.���P�PO��3=�\\�0RS�r395/�,�0�̨̩̪�����\]�a�S�+�/������\\�`�R�$"] +<134>1 2026-04-04T07:41:33.748959+00:00 decky-webmail imap - command [decnet@55555 src="192.168.1.5" cmd="��� �E����Q����P=�<��Ai� "] +<134>1 2026-04-04T07:41:33.748983+00:00 decky-webmail imap - command [decnet@55555 src="192.168.1.5" cmd="���# (&    "] +<134>1 2026-04-04T07:41:33.749009+00:00 decky-webmail imap - command [decnet@55555 src="192.168.1.5" cmd=" +-3����aq�څv�+DS[\\���c-'4R�(��a�J��L�2^7��luѡ��v�^�g%Y����Sx�r�-jR��C#b���r��"] +<134>1 2026-04-04T07:41:33.749035+00:00 decky-webmail imap - command [decnet@55555 src="192.168.1.5" cmd="�i���TLػ��A�1�s��'"] +<134>1 2026-04-04T07:41:33.749060+00:00 decky-webmail imap - command [decnet@55555 src="192.168.1.5" cmd="�4,�� � �G��q�–B仠�� K7O�Y�rq���3VtzD��̨"] +<134>1 2026-04-04T07:41:33.749041+00:00 decky-webmail http - request [decnet@55555 method="GET" path="/" remote_addr="192.168.1.5" headers="{'Host': '192.168.1.110'}" body=""] +<134>1 2026-04-04T07:41:33.749083+00:00 decky-webmail imap - command [decnet@55555 src="192.168.1.5" cmd="Ѓu�Y����-�\"��eSp*Zֹ L��{ �#�:����9!ɂCm�I�$ݦ1ϻo-H���*��X��{����p�ޚ|W��ƫf ��T�%�F5�8�������WU�a��c >�� u\]��i~�V���&�z"] +<134>1 2026-04-04T07:41:33.749104+00:00 decky-webmail imap - command [decnet@55555 src="192.168.1.5" cmd="�1�\\��Wc�C���v˺�6z� ��0�$iS� 3'�8<�"] +<134>1 2026-04-04T07:41:33.749122+00:00 decky-webmail imap - command [decnet@55555 src="192.168.1.5" cmd="��2��"] +<134>1 2026-04-04T07:41:33.749138+00:00 decky-webmail imap - command [decnet@55555 src="192.168.1.5" cmd="��\"/� �E���tv!"] +<134>1 2026-04-04T07:41:33.749160+00:00 decky-webmail imap - command [decnet@55555 src="192.168.1.5" cmd="񋞸�)��[j}�`��\\V|k��ԣy�Y��?�2�`�w¬ܶ#�X}��[cg3�W8E�tl�y<�Z�ʇ���% dQBk9=+��ȳ���(�y����*[8���qyN`���5>j�� 825�f��2. s\\dLar"] +<134>1 2026-04-04T07:41:33.749238+00:00 decky-webmail imap - connect [decnet@55555 src="192.168.1.5" src_port="39996"] +<134>1 2026-04-04T07:41:33.749290+00:00 decky-webmail imap - command [decnet@55555 src="192.168.1.5" cmd="WSi���,g�O�(T�YC��ѢO�Ę�����"] +<134>1 2026-04-04T07:41:33.749328+00:00 decky-webmail imap - command [decnet@55555 src="192.168.1.5" cmd="/"] +<134>1 2026-04-04T07:41:33.749369+00:00 decky-webmail imap - disconnect [decnet@55555 src="192.168.1.5"] +<134>1 2026-04-04T07:41:33.749411+00:00 decky-webmail imap - disconnect [decnet@55555 src="192.168.1.5"] +<134>1 2026-04-04T07:41:33.749441+00:00 decky-webmail imap - disconnect [decnet@55555 src="192.168.1.5"] +<134>1 2026-04-04T07:41:33.749484+00:00 decky-webmail smtp - connect [decnet@55555 src="192.168.1.5" src_port="47822"] +<134>1 2026-04-04T07:41:33.749708+00:00 decky-webmail smtp - ehlo [decnet@55555 src="192.168.1.5" domain="nmap.scanme.org"] +<134>1 2026-04-04T07:41:33.749852+00:00 decky-webmail smtp - disconnect [decnet@55555 src="192.168.1.5"] +<134>1 2026-04-04T07:41:33.749936+00:00 decky-webmail smtp - connect [decnet@55555 src="192.168.1.5" src_port="47834"] +<134>1 2026-04-04T07:41:33.750118+00:00 decky-webmail smtp - connect [decnet@55555 src="192.168.1.5" src_port="47846"] +<134>1 2026-04-04T07:41:33.750202+00:00 decky-webmail smtp - disconnect [decnet@55555 src="192.168.1.5"] +<134>1 2026-04-04T07:41:33.750261+00:00 decky-webmail smtp - disconnect [decnet@55555 src="192.168.1.5"] +<134>1 2026-04-04T07:41:33.750423+00:00 decky-webmail pop3 - connect [decnet@55555 src="192.168.1.5" src_port="48678"] +<134>1 2026-04-04T07:41:33.750684+00:00 decky-webmail pop3 - command [decnet@55555 src="192.168.1.5" cmd="STLS"] +<134>1 2026-04-04T07:41:33.750772+00:00 decky-webmail pop3 - disconnect [decnet@55555 src="192.168.1.5"] +<134>1 2026-04-04T07:41:33.750852+00:00 decky-webmail pop3 - connect [decnet@55555 src="192.168.1.5" src_port="48684"] +<134>1 2026-04-04T07:41:33.750920+00:00 decky-webmail pop3 - command [decnet@55555 src="192.168.1.5" cmd="($h_\\n�W�f 6~���'U��ԥ\"{���jg� �*M�$���at}5gq��)�X�w�7��_�r395/�,�0�̨̩̪�����\]�a�S�+�/������\\�`�R�"] +<134>1 2026-04-04T07:41:33.750964+00:00 decky-webmail pop3 - command [decnet@55555 src="192.168.1.5" cmd="��� �E����Q����P=�<��Ai� "] +<134>1 2026-04-04T07:41:33.750997+00:00 decky-webmail pop3 - command [decnet@55555 src="192.168.1.5" cmd="���# (&    "] +<134>1 2026-04-04T07:41:33.751027+00:00 decky-webmail pop3 - command [decnet@55555 src="192.168.1.5" cmd=" +-3�����pEt�\"g3�Ff` c�FY4�2�$3�t��Q�QKR/ �+5���� q �&�@�������B��(?�3�R/ �3�qr�! �"] +<134>1 2026-04-04T07:41:33.751096+00:00 decky-webmail pop3 - connect [decnet@55555 src="192.168.1.5" src_port="48698"] +<134>1 2026-04-04T07:41:33.751153+00:00 decky-webmail pop3 - command [decnet@55555 src="192.168.1.5" cmd="WSi���{���5��5т�R��!�;jj �7ވ�� "] +<134>1 2026-04-04T07:41:33.751197+00:00 decky-webmail pop3 - command [decnet@55555 src="192.168.1.5" cmd="/"] +<134>1 2026-04-04T07:41:33.751245+00:00 decky-webmail pop3 - disconnect [decnet@55555 src="192.168.1.5"] +<134>1 2026-04-04T07:41:33.751285+00:00 decky-webmail pop3 - disconnect [decnet@55555 src="192.168.1.5"] +<134>1 2026-04-04T07:41:33.751337+00:00 decky-fileserv ftp - connection [decnet@55555 src_ip="192.168.1.5" src_port="44606"] +<134>1 2026-04-04T07:41:33.751704+00:00 decky-fileserv ftp - disconnect [decnet@55555 src_ip="192.168.1.5" src_port="44606"] +<134>1 2026-04-04T07:41:33.751814+00:00 decky-fileserv ftp - connection [decnet@55555 src_ip="192.168.1.5" src_port="44614"] +<134>1 2026-04-04T07:41:33.751968+00:00 decky-fileserv ftp - connection [decnet@55555 src_ip="192.168.1.5" src_port="44630"] +<134>1 2026-04-04T07:41:33.752086+00:00 decky-fileserv ftp - disconnect [decnet@55555 src_ip="192.168.1.5" src_port="44630"] +<134>1 2026-04-04T07:41:33.752162+00:00 decky-fileserv ftp - disconnect [decnet@55555 src_ip="192.168.1.5" src_port="44614"] diff --git a/decnet/logging/file_handler.py b/decnet/logging/file_handler.py index 06d877a..47267d0 100644 --- a/decnet/logging/file_handler.py +++ b/decnet/logging/file_handler.py @@ -1,3 +1,4 @@ +from __future__ import annotations """ Rotating file handler for DECNET syslog output. diff --git a/decnet/logging/syslog_formatter.py b/decnet/logging/syslog_formatter.py index b2b6e37..998fff0 100644 --- a/decnet/logging/syslog_formatter.py +++ b/decnet/logging/syslog_formatter.py @@ -1,3 +1,4 @@ +from __future__ import annotations """ RFC 5424 syslog formatter for DECNET. diff --git a/templates/decnet_logging.py b/templates/decnet_logging.py index 9f1f935..0ad17fb 100644 --- a/templates/decnet_logging.py +++ b/templates/decnet_logging.py @@ -1,4 +1,5 @@ #!/usr/bin/env python3 +from __future__ import annotations """ Shared RFC 5424 syslog helper for DECNET service templates. diff --git a/templates/docker_api/decnet_logging.py b/templates/docker_api/decnet_logging.py index 9f1f935..0ad17fb 100644 --- a/templates/docker_api/decnet_logging.py +++ b/templates/docker_api/decnet_logging.py @@ -1,4 +1,5 @@ #!/usr/bin/env python3 +from __future__ import annotations """ Shared RFC 5424 syslog helper for DECNET service templates. diff --git a/templates/elasticsearch/decnet_logging.py b/templates/elasticsearch/decnet_logging.py index 9f1f935..0ad17fb 100644 --- a/templates/elasticsearch/decnet_logging.py +++ b/templates/elasticsearch/decnet_logging.py @@ -1,4 +1,5 @@ #!/usr/bin/env python3 +from __future__ import annotations """ Shared RFC 5424 syslog helper for DECNET service templates. diff --git a/templates/ftp/decnet_logging.py b/templates/ftp/decnet_logging.py index 9f1f935..0ad17fb 100644 --- a/templates/ftp/decnet_logging.py +++ b/templates/ftp/decnet_logging.py @@ -1,4 +1,5 @@ #!/usr/bin/env python3 +from __future__ import annotations """ Shared RFC 5424 syslog helper for DECNET service templates. diff --git a/templates/http/decnet_logging.py b/templates/http/decnet_logging.py index 9f1f935..0ad17fb 100644 --- a/templates/http/decnet_logging.py +++ b/templates/http/decnet_logging.py @@ -1,4 +1,5 @@ #!/usr/bin/env python3 +from __future__ import annotations """ Shared RFC 5424 syslog helper for DECNET service templates. diff --git a/templates/imap/decnet_logging.py b/templates/imap/decnet_logging.py index 9f1f935..0ad17fb 100644 --- a/templates/imap/decnet_logging.py +++ b/templates/imap/decnet_logging.py @@ -1,4 +1,5 @@ #!/usr/bin/env python3 +from __future__ import annotations """ Shared RFC 5424 syslog helper for DECNET service templates. diff --git a/templates/k8s/decnet_logging.py b/templates/k8s/decnet_logging.py index 9f1f935..0ad17fb 100644 --- a/templates/k8s/decnet_logging.py +++ b/templates/k8s/decnet_logging.py @@ -1,4 +1,5 @@ #!/usr/bin/env python3 +from __future__ import annotations """ Shared RFC 5424 syslog helper for DECNET service templates. diff --git a/templates/ldap/decnet_logging.py b/templates/ldap/decnet_logging.py index 9f1f935..0ad17fb 100644 --- a/templates/ldap/decnet_logging.py +++ b/templates/ldap/decnet_logging.py @@ -1,4 +1,5 @@ #!/usr/bin/env python3 +from __future__ import annotations """ Shared RFC 5424 syslog helper for DECNET service templates. diff --git a/templates/llmnr/decnet_logging.py b/templates/llmnr/decnet_logging.py index 9f1f935..0ad17fb 100644 --- a/templates/llmnr/decnet_logging.py +++ b/templates/llmnr/decnet_logging.py @@ -1,4 +1,5 @@ #!/usr/bin/env python3 +from __future__ import annotations """ Shared RFC 5424 syslog helper for DECNET service templates. diff --git a/templates/mongodb/decnet_logging.py b/templates/mongodb/decnet_logging.py index 9f1f935..0ad17fb 100644 --- a/templates/mongodb/decnet_logging.py +++ b/templates/mongodb/decnet_logging.py @@ -1,4 +1,5 @@ #!/usr/bin/env python3 +from __future__ import annotations """ Shared RFC 5424 syslog helper for DECNET service templates. diff --git a/templates/mqtt/decnet_logging.py b/templates/mqtt/decnet_logging.py index 9f1f935..0ad17fb 100644 --- a/templates/mqtt/decnet_logging.py +++ b/templates/mqtt/decnet_logging.py @@ -1,4 +1,5 @@ #!/usr/bin/env python3 +from __future__ import annotations """ Shared RFC 5424 syslog helper for DECNET service templates. diff --git a/templates/mssql/decnet_logging.py b/templates/mssql/decnet_logging.py index 9f1f935..0ad17fb 100644 --- a/templates/mssql/decnet_logging.py +++ b/templates/mssql/decnet_logging.py @@ -1,4 +1,5 @@ #!/usr/bin/env python3 +from __future__ import annotations """ Shared RFC 5424 syslog helper for DECNET service templates. diff --git a/templates/mysql/decnet_logging.py b/templates/mysql/decnet_logging.py index 9f1f935..0ad17fb 100644 --- a/templates/mysql/decnet_logging.py +++ b/templates/mysql/decnet_logging.py @@ -1,4 +1,5 @@ #!/usr/bin/env python3 +from __future__ import annotations """ Shared RFC 5424 syslog helper for DECNET service templates. diff --git a/templates/pop3/decnet_logging.py b/templates/pop3/decnet_logging.py index 9f1f935..0ad17fb 100644 --- a/templates/pop3/decnet_logging.py +++ b/templates/pop3/decnet_logging.py @@ -1,4 +1,5 @@ #!/usr/bin/env python3 +from __future__ import annotations """ Shared RFC 5424 syslog helper for DECNET service templates. diff --git a/templates/postgres/decnet_logging.py b/templates/postgres/decnet_logging.py index 9f1f935..0ad17fb 100644 --- a/templates/postgres/decnet_logging.py +++ b/templates/postgres/decnet_logging.py @@ -1,4 +1,5 @@ #!/usr/bin/env python3 +from __future__ import annotations """ Shared RFC 5424 syslog helper for DECNET service templates. diff --git a/templates/rdp/decnet_logging.py b/templates/rdp/decnet_logging.py index 9f1f935..0ad17fb 100644 --- a/templates/rdp/decnet_logging.py +++ b/templates/rdp/decnet_logging.py @@ -1,4 +1,5 @@ #!/usr/bin/env python3 +from __future__ import annotations """ Shared RFC 5424 syslog helper for DECNET service templates. diff --git a/templates/redis/decnet_logging.py b/templates/redis/decnet_logging.py index 9f1f935..0ad17fb 100644 --- a/templates/redis/decnet_logging.py +++ b/templates/redis/decnet_logging.py @@ -1,4 +1,5 @@ #!/usr/bin/env python3 +from __future__ import annotations """ Shared RFC 5424 syslog helper for DECNET service templates. diff --git a/templates/sip/decnet_logging.py b/templates/sip/decnet_logging.py index 9f1f935..0ad17fb 100644 --- a/templates/sip/decnet_logging.py +++ b/templates/sip/decnet_logging.py @@ -1,4 +1,5 @@ #!/usr/bin/env python3 +from __future__ import annotations """ Shared RFC 5424 syslog helper for DECNET service templates. diff --git a/templates/smb/decnet_logging.py b/templates/smb/decnet_logging.py index 9f1f935..0ad17fb 100644 --- a/templates/smb/decnet_logging.py +++ b/templates/smb/decnet_logging.py @@ -1,4 +1,5 @@ #!/usr/bin/env python3 +from __future__ import annotations """ Shared RFC 5424 syslog helper for DECNET service templates. diff --git a/templates/smtp/decnet_logging.py b/templates/smtp/decnet_logging.py index 9f1f935..0ad17fb 100644 --- a/templates/smtp/decnet_logging.py +++ b/templates/smtp/decnet_logging.py @@ -1,4 +1,5 @@ #!/usr/bin/env python3 +from __future__ import annotations """ Shared RFC 5424 syslog helper for DECNET service templates. diff --git a/templates/snmp/decnet_logging.py b/templates/snmp/decnet_logging.py index 9f1f935..0ad17fb 100644 --- a/templates/snmp/decnet_logging.py +++ b/templates/snmp/decnet_logging.py @@ -1,4 +1,5 @@ #!/usr/bin/env python3 +from __future__ import annotations """ Shared RFC 5424 syslog helper for DECNET service templates. diff --git a/templates/tftp/decnet_logging.py b/templates/tftp/decnet_logging.py index 9f1f935..0ad17fb 100644 --- a/templates/tftp/decnet_logging.py +++ b/templates/tftp/decnet_logging.py @@ -1,4 +1,5 @@ #!/usr/bin/env python3 +from __future__ import annotations """ Shared RFC 5424 syslog helper for DECNET service templates. diff --git a/templates/vnc/decnet_logging.py b/templates/vnc/decnet_logging.py index 9f1f935..0ad17fb 100644 --- a/templates/vnc/decnet_logging.py +++ b/templates/vnc/decnet_logging.py @@ -1,4 +1,5 @@ #!/usr/bin/env python3 +from __future__ import annotations """ Shared RFC 5424 syslog helper for DECNET service templates. diff --git a/test-scan b/test-scan index 2456525..facf080 100644 --- a/test-scan +++ b/test-scan @@ -1,6 +1,6 @@ -# Nmap 7.92 scan initiated Sat Apr 4 04:36:10 2026 as: nmap -sS -sV -O -A -oN test-scan 192.168.1.110-119 +# Nmap 7.92 scan initiated Sat Apr 4 04:41:05 2026 as: nmap -sS -sV -O -A -oN test-scan 192.168.1.110-119 Nmap scan report for 192.168.1.110 -Host is up (0.000044s latency). +Host is up (0.000035s latency). Not shown: 996 closed tcp ports (reset) PORT STATE SERVICE VERSION 25/tcp open smtp Postfix smtpd @@ -24,23 +24,23 @@ PORT STATE SERVICE VERSION | GetRequest: | * OK [decky-webmail] IMAP4rev1 Service Ready |_ Command not recognized -|_imap-capabilities: AUTH=LOGINA0001 OK IMAP4rev1 completed CAPABILITY AUTH=PLAIN +|_imap-capabilities: OK CAPABILITY AUTH=LOGINA0001 IMAP4rev1 completed AUTH=PLAIN 2 services unrecognized despite returning data. If you know the service/version, please submit the following fingerprints at https://nmap.org/cgi-bin/submit.cgi?new-service : ==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)============== -SF-Port110-TCP:V=7.92%I=7%D=4/4%Time=69D0BF72%P=x86_64-redhat-linux-gnu%r( +SF-Port110-TCP:V=7.92%I=7%D=4/4%Time=69D0C099%P=x86_64-redhat-linux-gnu%r( SF:NULL,25,"\+OK\x20decky-webmail\x20POP3\x20server\x20ready\r\n")%r(Gener SF:icLines,51,"\+OK\x20decky-webmail\x20POP3\x20server\x20ready\r\n-ERR\x2 SF:0Unknown\x20command\r\n-ERR\x20Unknown\x20command\r\n")%r(HTTPOptions,5 SF:1,"\+OK\x20decky-webmail\x20POP3\x20server\x20ready\r\n-ERR\x20Unknown\ SF:x20command\r\n-ERR\x20Unknown\x20command\r\n"); ==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)============== -SF-Port143-TCP:V=7.92%I=7%D=4/4%Time=69D0BF72%P=x86_64-redhat-linux-gnu%r( +SF-Port143-TCP:V=7.92%I=7%D=4/4%Time=69D0C099%P=x86_64-redhat-linux-gnu%r( SF:NULL,2E,"\*\x20OK\x20\[decky-webmail\]\x20IMAP4rev1\x20Service\x20Ready SF:\r\n")%r(GetRequest,4E,"\*\x20OK\x20\[decky-webmail\]\x20IMAP4rev1\x20S SF:ervice\x20Ready\r\nGET\x20BAD\x20Command\x20not\x20recognized\r\n")%r(G SF:enericLines,2E,"\*\x20OK\x20\[decky-webmail\]\x20IMAP4rev1\x20Service\x SF:20Ready\r\n"); -MAC Address: DE:A7:41:91:07:8A (Unknown) +MAC Address: D2:55:C7:0D:B4:FC (Unknown) Device type: general purpose Running: Linux 5.X OS CPE: cpe:/o:linux:linux_kernel:5 @@ -53,7 +53,7 @@ HOP RTT ADDRESS 1 0.04 ms 192.168.1.110 Nmap scan report for 192.168.1.111 -Host is up (0.000015s latency). +Host is up (0.000016s latency). Not shown: 998 closed tcp ports (reset) PORT STATE SERVICE VERSION 21/tcp open ftp vsftpd (before 2.0.8) or WU-FTPD @@ -63,11 +63,11 @@ PORT STATE SERVICE VERSION | SMBr |_ "3DUfw 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service : -SF-Port445-TCP:V=7.92%I=7%D=4/4%Time=69D0BF77%P=x86_64-redhat-linux-gnu%r( +SF-Port445-TCP:V=7.92%I=7%D=4/4%Time=69D0C09E%P=x86_64-redhat-linux-gnu%r( SF:SMBProgNeg,51,"\0\0\0M\xffSMBr\0\0\0\0\x80\0\xc0\0\0\0\0\0\0\0\0\0\0\0\ SF:0\0\0@\x06\0\0\x01\0\x11\x07\0\x03\x01\0\x01\0\0\xfa\0\0\0\0\x01\0\0\0\ SF:0\0p\0\0\0\0\0\0\0\0\0\0\0\0\0\x08\x08\0\x11\"3DUfw\x88"); -MAC Address: 4A:96:18:DB:DA:38 (Unknown) +MAC Address: 92:44:B7:6C:F6:D0 (Unknown) Device type: general purpose Running: Linux 5.X OS CPE: cpe:/o:linux:linux_kernel:5 @@ -76,23 +76,23 @@ Network Distance: 1 hop Service Info: Host: Twisted Host script results: -| smb2-security-mode: -| 2.0.2: -|_ Message signing enabled but not required -| smb2-time: -| date: 2026-04-04T07:36:29 -|_ start_date: 2026-04-04T07:36:29 | smb-security-mode: | account_used: guest | authentication_level: user | challenge_response: supported |_ message_signing: disabled (dangerous, but default) +| smb2-time: +| date: 2026-04-04T07:41:24 +|_ start_date: 2026-04-04T07:41:24 +| smb2-security-mode: +| 2.0.2: +|_ Message signing enabled but not required |_ms-sql-info: ERROR: Script execution failed (use -d to debug) -|_clock-skew: mean: -77660d15h48m16s, deviation: 109828d18h09m25s, median: -155321d07h36m32s +|_clock-skew: mean: -77660d15h50m42s, deviation: 109828d18h12m51s, median: -155321d07h41m24s TRACEROUTE HOP RTT ADDRESS -1 0.01 ms 192.168.1.111 +1 0.02 ms 192.168.1.111 OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . -# Nmap done at Sat Apr 4 04:36:38 2026 -- 10 IP addresses (2 hosts up) scanned in 28.29 seconds +# Nmap done at Sat Apr 4 04:41:33 2026 -- 10 IP addresses (2 hosts up) scanned in 28.27 seconds