Following a lengthy interrogation involving rubber hoses and a "Yanni Live"
CD, the suspect revealed that on 3/16/03 7:39 AM, Bill Cole at
[EMAIL PROTECTED] wrote:

Yes, now I see, I did not have SMTP logging set to a level low enough to see
the complete error. I have two problems, one being that I am on the MAPS
DUL, which is probably an insurmountable one, and the second being that my
server is failing an open relay test because it is allowing mail to be sent
when the sender pretends to be from the resolved WAN IP of my router.
Following is the transcript of the test; note that I have set the client
host checking and verify return paths to on, and my client host range is
192.168.1.1-192.168.1.254:

Mail Relay testing.
Connecting to 68.36.191.86 for test ...

<<<�220-Stalker�Internet�Mail�Server�V.1.8b8�is�ready.
<<<�220�ESMTP�is�spoken�here.�You�are�welcome
>>>�HELO�www.rbl.jp
<<<�250�optionsbydesign.com�is�pleased�to�meet�you

Relay test 0
>>>�RSET
<<<�250�SMTP�state�reset
>>>�MAIL�FROM:�<[EMAIL PROTECTED]>
<<<�250�<[EMAIL PROTECTED]>�sender�accepted
>>>�RCPT�TO:�<[EMAIL PROTECTED]>
<<<�571�<[EMAIL PROTECTED]>�we�do�not�relay.
relay NOT accepted!!

Relay test 1
>>>�RSET
<<<�250�SMTP�state�reset
>>>�MAIL�FROM:�<spamtest>
<<<�572�<spamtest>�domain�must�be�specified
relay NOT accepted!!

Relay test 2
>>>�RSET
<<<�250�SMTP�state�reset
>>>�MAIL�FROM:�<>
<<<�250�<>�sender�accepted
>>>�RCPT�TO:�<[EMAIL PROTECTED]>
<<<�571�<[EMAIL PROTECTED]>�we�do�not�relay.
relay NOT accepted!!

Relay test 3
>>>�RSET
<<<�250�SMTP�state�reset
>>>�MAIL�FROM:�<[EMAIL PROTECTED]>
<<<�250�<[EMAIL PROTECTED]>�sender�accepted
>>>�RCPT�TO:�<[EMAIL PROTECTED]>
<<<�571�<[EMAIL PROTECTED]>�we�do�not�relay.
relay NOT accepted!!

Relay test 4
>>>�RSET
<<<�250�SMTP�state�reset
>>>�MAIL�FROM:�<[EMAIL PROTECTED]>
<<<�572�<[EMAIL PROTECTED]>�IP-address�names�are�not�accepted
relay NOT accepted!!

Relay test 5
>>>�RSET
<<<�250�SMTP�state�reset
>>>�MAIL�FROM:�<[EMAIL PROTECTED]>
<<<�250�<[EMAIL PROTECTED]>�sender�accepted
>>>�RCPT�TO:�<[EMAIL PROTECTED]>
<<<�471�<[EMAIL PROTECTED]>��cannot�be�ac
cepted�now:�path�is�unknown.
relay NOT accepted!!

Relay test 6
>>>�RSET
<<<�250�SMTP�state�reset
>>>�MAIL�FROM:�<[EMAIL PROTECTED]>
<<<�250�<[EMAIL PROTECTED]>�sender�accepted
>>>�RCPT�TO:�<[EMAIL PROTECTED]>
<<<�571�<[EMAIL PROTECTED]>�we�do�not�relay.
relay NOT accepted!!

Relay test 7
>>>�RSET
<<<�250�SMTP�state�reset
>>>�MAIL�FROM:�<[EMAIL PROTECTED]>
<<<�250�<[EMAIL PROTECTED]>�sender�accepted
>>>�RCPT�TO:�<"[EMAIL PROTECTED]">
<<<�250�<"[EMAIL PROTECTED]">�recipient�accepted
relay accepted!! 

Relay test 8
>>>�RSET
<<<�250�SMTP�state�reset
>>>�MAIL�FROM:�<[EMAIL PROTECTED]>
<<<�250�<[EMAIL PROTECTED]>�sender�accepted
>>>�RCPT�TO:�<"relaytest%rbl.jp">
<<<�250�<"relaytest%rbl.jp">�recipient�accepted
relay accepted!! 


> At 7:23 AM -0500 3/16/03, Gil Poulsen  imposed structure on a stream
> of electrons, yielding:
>> Using SIMS 1.8b8 running on a G3-upgraded 8500, OS 9.1. Been working fine
>> for days now, but I just checked the queue and noted that some messages to
>> AOL were stuck in there. The error info in the log seemed kind of bizarre,
>> so I thought I would post it in case anyone had seen this before:
>> 
>> 00:25:38 3 SMTP-244(aol.com) Expected 220 <Hello>, got 550
>> http://postmaster.info.aol.com\r
>> 00:25:38 3 SMTP [S.0000003086] dequeueing
>> 00:25:38 3 SMTP [S.0000003106] dequeueing
>> 00:25:38 3 SMTP [S.0000003107] dequeueing
>> 00:55:38 3 SMTP-245(aol.com) Expected 220 <Hello>, got 550
>> http://postmaster.info.aol.com\r
>> 00:55:38 3 SMTP [S.0000003086] dequeueing
>> 00:55:38 3 SMTP [S.0000003106] dequeueing
>> 00:55:38 3 SMTP [S.0000003107] dequeueing
>> 
>> Nothing AOL does surprises me anymore, but I just wanted some reassurance
>> that this is on their end.
> 
> Yes, it is.
> 
> However, it's a bad sign for you. It very likely means that AOL
> thinks you are (or were, when connected, as you appear not to be
> right now...)  on an IP that should not be talked to at all.
> 
> Absent some evidence that you have any sort of permanent connection
> to the IP's that your mail server uses, I would tend to agree with
> them.


--
Gil Poulsen, Mac Wirehead

************************
[EMAIL PROTECTED] Consulting 
23 Marco Polo Court
Franklin Park, NJ 08823-1703
Voice: 732-940-1673
FAX: 732-940-1674
http://altimac.com
************************



#############################################################
This message is sent to you because you are subscribed to
  the mailing list <[EMAIL PROTECTED]>.
To unsubscribe, E-mail to: <[EMAIL PROTECTED]>
To switch to the DIGEST mode, E-mail to <[EMAIL PROTECTED]>
To switch to the INDEX mode, E-mail to <[EMAIL PROTECTED]>
Send administrative queries to  <[EMAIL PROTECTED]>

Reply via email to