Hi,

I am relatively new to the whole linux experience. But I have been brought up to speed relatively fast lately. Firstly I use a VPS with a webhost and it runs FC2. I was recently hacked, I believe via a brute force attack on SSH and this lead to a complete reinstall and investigation on how to make the server more secure.

Anyway I have been keeping a very close eye on my logwatch emails and found this to a little strange. I am wondering if anyone can tell me If it is of concern.

--------------------- courier-mta Begin ------------------------

**Unmatched Entries**
Command stream end of file, while reading line user=??? host=rrcs-24-227-XXX-XX.sw.biz.rr.com [24.227.XXX.XX]: 1 Time(s)
imap service init from 24.227.XXX.XX: 1 Time(s)

---------------------- courier-mta End -------------------------

then further down this


Service imap:
24.227.XXX.XX: 1 Time(s)

**Unmatched Entries**
gpasswd[1448]: add member webadmin to group ftpusers by root


Now I am sure that it was not me who added webadmin to ftpusers. I actually removed that user from ftpusers a few days ago. The FTP server is turned off on my VPS and you have to tunnel via SSH to use FTP.

Any advice is much appreciated.