Hacker attack - Attempting to guess mail file names

Notes log has a lot of messages from some trying to guess mail file names on our server in the DMZ:10/27/2008 02:07:33 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/root.nsf]

10/27/2008 02:07:33 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/router.nsf]

10/27/2008 02:07:33 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/rw.nsf]

10/27/2008 02:07:33 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/rz0plm92.nsf]

10/27/2008 02:07:33 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/sam.nsf]

10/27/2008 02:07:34 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/sa.nsf]

10/27/2008 02:07:34 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/sap.nsf]

10/27/2008 02:07:34 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/security.nsf]

10/27/2008 02:07:34 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/service.nsf]

10/27/2008 02:07:34 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/setup.nsf]

10/27/2008 02:07:34 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/sgiweb.nsf]

10/27/2008 02:07:35 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/shutdown.nsf]

10/27/2008 02:07:35 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/signa.nsf]

10/27/2008 02:07:35 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/soft.nsf]

10/27/2008 02:07:35 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/software.nsf]

10/27/2008 02:07:35 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/sqldba.nsf]

10/27/2008 02:07:36 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/sqluser.nsf]

10/27/2008 02:07:36 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/student.nsf]

10/27/2008 02:07:36 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/supervisor.nsf]

10/27/2008 02:07:36 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/support.nsf]

10/27/2008 02:07:39 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/sync.nsf]

10/27/2008 02:07:39 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/sys.nsf]

10/27/2008 02:07:40 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/sysadm.nsf]

10/27/2008 02:07:40 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/sysadmin.nsf]

10/27/2008 02:07:40 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/sysbin.nsf]

10/27/2008 02:07:40 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/sysop.nsf]

10/27/2008 02:07:40 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/sysmaint.nsf]

10/27/2008 02:07:40 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/system.nsf]

10/27/2008 02:07:41 HTTP Web Server: Lotus Notes Exception - File does not exist [/mail/system_admin.nsf]

Subject: Benevolent hacking

I found out it was from benevolent hacking from IBM that my boss has a contract for. Those messages were the “good” messages. Apparently there is a lot of databases out there that have anonymous access that they let us know so we can make a decision as to whether or not this concerns us.Among them is names.nsf and several others.

"IMPACT:

Unauthorized users can gather sensitive information, such as authentication certificates for users, custom database names, logfiles and schedules, by stealing the database."