Linux Netfilter discussions
 help / color / mirror / Atom feed
* Unzustellbar: [SPAM] - Re: Why does this connection stop being tr acked? - Sending mail server found on relays.ordb.org (fwd)
@ 2005-06-15 17:23 R. DuFresne
  2005-06-15 17:31 ` Andy Smith
  2005-06-15 18:02 ` Jason Opperisano
  0 siblings, 2 replies; 5+ messages in thread
From: R. DuFresne @ 2005-06-15 17:23 UTC (permalink / raw)
  To: netfilter

[-- Attachment #1: Type: TEXT/PLAIN, Size: 1555 bytes --]

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1



will the folks responsible for maintaining the list please remove these 
clueless ones from the list;


http://ordb.org/lookup/?host=sysinfo.com

Lookup
This host is not listed in ORDB as an open mail relay

Main database status for sysinfo.com (70.61.80.19)
Look up this host in non-ORDB RBL's (May take a while to load)
The host sysinfo.com is not in the main database


- ---------- Forwarded message ----------
From: Systemadministrator <postmaster@echtzeit.com>
Subject: Unzustellbar: [SPAM] - Re: Why does this connection stop being tr
     acked? - Sending mail server found on relays.ordb.org
Date: Wed, 15 Jun 2005 18:06:14 +0200
To: dufresne@sysinfo.com

Your message

   To:      Andy Smith
   Cc:      netfilter@lists.netfilter.org; Jozsef Kadlecsik
   Subject: [SPAM] - Re: Why does this connection stop being tracked? -
Sending mail server found on relays.ordb.org
   Sent:    Wed, 15 Jun 2005 18:07:52 +0200

did not reach the following recipient(s):

phergenhahn@echtzeit.de on Wed, 15 Jun 2005 18:06:13 +0200
     Der Name des Empfängers wurde nicht erkannt.
 	Die MTS-ID der ursprünglichen Nachricht ist: c=de;a= ;p=echtzeit
gmbh ? ;l=EZMXS0506151606M1PANQGT
     MSEXCH:IMS:Echtzeit GmbH & Co. KG:ECHTZEIT:EZMXS 0 (000C05A6)
Unbekannter Empfänger


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFCsGQsst+vzJSwZikRAt1LAJ9xL9l5z9fKn8BZzQimgpQvYqJPrgCfbRVe
qncoDiq+Lfi4bv2DkQkG2pA=
=L99R
-----END PGP SIGNATURE-----

[-- Attachment #2: Type: MESSAGE/RFC822, Size: 3409 bytes --]

Message-ID: <Pine.LNX.4.60.0506151154340.25078@darkstar.sysinfo.com>
From: "R. DuFresne" <dufresne@sysinfo.com>
To: Andy Smith <andy@strugglers.net>
Cc: netfilter@lists.netfilter.org, Jozsef Kadlecsik <kadlec@blackhole.kfki.hu>
Subject: [SPAM] - Re: Why does this connection stop being tracked? - Sendi
	ng mail server found on relays.ordb.org
Date: Wed, 15 Jun 2005 18:07:52 +0200
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
X-MS-Embedded-Report: 
List-Help: <mailto:netfilter-request@lists.netfilter.org?subject=help>
List-Subscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>,
	<mailto:netfilter-request@lists.netfilter.org?subject=subscribe>
List-Unsubscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>,
	<mailto:netfilter-request@lists.netfilter.org?subject=unsubscribe>
Content-Type: text/plain;
	charset="iso-8859-1"

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


 	[SNIP]

>>
>> You have two choices: either disable TCP SACK support on all your
>> real/virtual machines behind your firewall, or upgrade the kernel on the
>> firewall.
>
> Do you have any instructions or a pointer to documentation onhow to
> temporarily disable SACK?  If it was a /proc setting that would be
> ideal; I don't really want to have to recompile kernels though.
>

why?  you are certainly missing out on how to fix and patch a systems when 
bugs in the kernel affect it, to the ability to add features that your 
dist maintainer has not enabled by default, or to change params in the 
kernel such as moving away or to kernel modules as opposed to stack 
functionality mapping.  Not to mention the abilities to streamline the 
kernel to fit your requirements and remove all the xtra trash that gets 
loaded in to make a kernel fit all purposes/needs/enduser-requirements.

basically, you are defeating one of the finer points in the linux realm <as 
well as the BSD's net, open, free>  you are avoiding taking actually 
control of what you are playing with <smile>.  Granted one does not do 
this sort of thing in a prod env on the fly, one tests such things on a 
dev server or desktop emulating what might be in prod. but, it's not all 
that tough to master, and certainly will likely be required at one time or 
another to get things working that were not originally provided, move to a 
newer cleaner kernel, or even to fix problems encountered over the 
stresses of time and all that.  The recipe for doing such is not all that 
complex, and if one backsup the old kernel and properly runs lilo to 
include it in the potential boot process, not all that damaging should on 
finger-fart and make a bed new kernel on first draft. but all admins in 
the free *nix-like realm should learn the particulars of rebuilding 
kernels, it will  at one time or another save their asses.

No salt for the avoiders.

Thanks,

Ron DuFresne
- -- 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         admin & senior security consultant:  sysinfo.com
                         http://sysinfo.com
Key fingerprint = 9401 4B13 B918 164C 647A  E838 B2DF AFCC 94B0 6629

...We waste time looking for the perfect lover
instead of creating the perfect love.

                 -Tom Robbins <Still Life With Woodpecker>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFCsFJdst+vzJSwZikRAiaQAKCWHlgggJUxBXu9/CeR//pLYbzHGACfRVev
kG/17gNRcUin+Dk63ai8gCA=
=2VQV
-----END PGP SIGNATURE-----

From: "R. DuFresne" <dufresne@sysinfo.com>
To: Andy Smith <andy@strugglers.net>
Cc: netfilter@lists.netfilter.org, Jozsef Kadlecsik <kadlec@blackhole.kfki.hu>
Subject: [SPAM] - Re: Why does this connection stop being tracked? - Sendi ng mail server found on relays.ordb.org
Date: Wed, 15 Jun 2005 18:07:52 +0200
Message-ID: <Pine.LNX.4.60.0506151154340.25078@darkstar.sysinfo.com>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


 	[SNIP]

>>
>> You have two choices: either disable TCP SACK support on all your
>> real/virtual machines behind your firewall, or upgrade the kernel on the
>> firewall.
>
> Do you have any instructions or a pointer to documentation onhow to
> temporarily disable SACK?  If it was a /proc setting that would be
> ideal; I don't really want to have to recompile kernels though.
>

why?  you are certainly missing out on how to fix and patch a systems when 
bugs in the kernel affect it, to the ability to add features that your 
dist maintainer has not enabled by default, or to change params in the 
kernel such as moving away or to kernel modules as opposed to stack 
functionality mapping.  Not to mention the abilities to streamline the 
kernel to fit your requirements and remove all the xtra trash that gets 
loaded in to make a kernel fit all purposes/needs/enduser-requirements.

basically, you are defeating one of the finer points in the linux realm <as 
well as the BSD's net, open, free>  you are avoiding taking actually 
control of what you are playing with <smile>.  Granted one does not do 
this sort of thing in a prod env on the fly, one tests such things on a 
dev server or desktop emulating what might be in prod. but, it's not all 
that tough to master, and certainly will likely be required at one time or 
another to get things working that were not originally provided, move to a 
newer cleaner kernel, or even to fix problems encountered over the 
stresses of time and all that.  The recipe for doing such is not all that 
complex, and if one backsup the old kernel and properly runs lilo to 
include it in the potential boot process, not all that damaging should on 
finger-fart and make a bed new kernel on first draft. but all admins in 
the free *nix-like realm should learn the particulars of rebuilding 
kernels, it will  at one time or another save their asses.

No salt for the avoiders.

Thanks,

Ron DuFresne
- -- 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         admin & senior security consultant:  sysinfo.com
                         http://sysinfo.com
Key fingerprint = 9401 4B13 B918 164C 647A  E838 B2DF AFCC 94B0 6629

...We waste time looking for the perfect lover
instead of creating the perfect love.

                 -Tom Robbins <Still Life With Woodpecker>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFCsFJdst+vzJSwZikRAiaQAKCWHlgggJUxBXu9/CeR//pLYbzHGACfRVev
kG/17gNRcUin+Dk63ai8gCA=
=2VQV
-----END PGP SIGNATURE-----

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: Unzustellbar: [SPAM] - Re: Why does this connection stop being tr acked? - Sending mail server found on relays.ordb.org (fwd)
  2005-06-15 17:23 Unzustellbar: [SPAM] - Re: Why does this connection stop being tr acked? - Sending mail server found on relays.ordb.org (fwd) R. DuFresne
@ 2005-06-15 17:31 ` Andy Smith
  2005-06-15 18:29   ` Taylor, Grant
  2005-06-15 18:02 ` Jason Opperisano
  1 sibling, 1 reply; 5+ messages in thread
From: Andy Smith @ 2005-06-15 17:31 UTC (permalink / raw)
  To: netfilter

[-- Attachment #1: Type: text/plain, Size: 488 bytes --]

On Wed, Jun 15, 2005 at 01:23:52PM -0400, R. DuFresne wrote:
> will the folks responsible for maintaining the list please remove these 
> clueless ones from the list;

Not only are they sending this bounce

- in German only
- to the person posting to the list as opposed to the list's
  bounce address
- incorrectly claiming the list's host is in ORDB

but all mail to their postmaster account bounces too!

Broken in so many ways, but then, it does appear to be Exchange..

[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: Unzustellbar: [SPAM] - Re: Why does this connection stop being tr acked? - Sending mail server found on relays.ordb.org (fwd)
  2005-06-15 17:23 Unzustellbar: [SPAM] - Re: Why does this connection stop being tr acked? - Sending mail server found on relays.ordb.org (fwd) R. DuFresne
  2005-06-15 17:31 ` Andy Smith
@ 2005-06-15 18:02 ` Jason Opperisano
  1 sibling, 0 replies; 5+ messages in thread
From: Jason Opperisano @ 2005-06-15 18:02 UTC (permalink / raw)
  To: netfilter

On Wed, Jun 15, 2005 at 01:23:52PM -0400, R. DuFresne wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> will the folks responsible for maintaining the list please remove these 
> clueless ones from the list;
> 
> http://ordb.org/lookup/?host=sysinfo.com
> 
> Lookup
> This host is not listed in ORDB as an open mail relay
> 
> Main database status for sysinfo.com (70.61.80.19)
> Look up this host in non-ORDB RBL's (May take a while to load)
> The host sysinfo.com is not in the main database

i've been much happier since adding:

  :0
  * ^From: Systemadministrator <postmaster@echtzeit.com>
  /dev/null

to my .procmailrc

-j

--
"Meg: Dad, if I don't get my driver's license, I'll never have any
 boyfriends, I'll never get married and I'll have to adopt a kid
 like Rosie O'Donnell.
 Peter: Meg... are you implying that Rosie O'Donnell can't drive?"
        --Family Guy


^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: Unzustellbar: [SPAM] - Re: Why does this connection stop being tr acked? - Sending mail server found on relays.ordb.org (fwd)
  2005-06-15 17:31 ` Andy Smith
@ 2005-06-15 18:29   ` Taylor, Grant
  2005-06-15 19:57     ` Andy Smith
  0 siblings, 1 reply; 5+ messages in thread
From: Taylor, Grant @ 2005-06-15 18:29 UTC (permalink / raw)
  To: netfilter

> - to the person posting to the list as opposed to the list's
>   bounce address

If you will notice, below are the headers from the email that you sent that I'm replying to.  You will see that the header list has not been pruned to be just the mail list server as it probably should be.  I have had quite a few email messages bounce to me because one or more servers involved in the sending process to the netfilter receiving server (vishnu.netfilter.org (2nd from the bottom)).  IMHO the mail list software should be set up such that it prunes the prior servers out of the mail headers as these sending servers (to the netfilter list it's self) are the ones in error, not the netfilter server yet the servers that are bouncing the messages are looking at the original servers.

Received: from vishnu.netfilter.org (vishnu.netfilter.org [213.95.27.115])
	by rti02.co-lo.riverviewtech.net (8.13.1/8.13.1) with ESMTP id j5FHVmZZ017756
	for <gtaylor@riverviewtech.net>; Wed, 15 Jun 2005 12:31:48 -0500
Received: from localhost ([127.0.0.1] hello=vishnu.netfilter.org)
	by vishnu.netfilter.org with esmtp (Exim 4.41 #1 (Debian))
	id 1Dibvx-0007mY-CY; Wed, 15 Jun 2005 19:44:13 +0200
Received: from [2001:ba8:0:1f1:a800:ff:fe4b:a0c1] (hello=strugglers.net)
	by vishnu.netfilter.org with esmtp (Exim 4.41 #1 (Debian))
	id 1Dibvu-0007mQ-Vd
	for <netfilter@lists.netfilter.org>; Wed, 15 Jun 2005 19:44:11 +0200
Received: from andy by strugglers.net with local (Exim 4.50)
	id 1Dibjr-000621-8A
	for netfilter@lists.netfilter.org; Wed, 15 Jun 2005 17:31:44 +0000

> - incorrectly claiming the list's host is in ORDB

Again the mail list is not changing the from email address to be the mail list like I think they should.  IMHO any and all email passing through this list should be to and from the list email address.  Unfortunetly there is probably much debate on how to run mail lists and what should and should not be done.  But alass this is not really the proper place to do so.  As of yet I have not tried contacting this mail list administrator to this regard so I can not comment one way or the other on their cooperation, perhaps it is time to do such.



Grant. . . .


^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: Unzustellbar: [SPAM] - Re: Why does this connection stop being tr acked? - Sending mail server found on relays.ordb.org (fwd)
  2005-06-15 18:29   ` Taylor, Grant
@ 2005-06-15 19:57     ` Andy Smith
  0 siblings, 0 replies; 5+ messages in thread
From: Andy Smith @ 2005-06-15 19:57 UTC (permalink / raw)
  To: netfilter

[-- Attachment #1: Type: text/plain, Size: 1682 bytes --]

On Wed, Jun 15, 2005 at 01:29:13PM -0500, Taylor, Grant wrote:
> IMHO the mail list software should be set up such that it prunes
> the prior servers out of the mail headers as these sending servers
> (to the netfilter list it's self) are the ones in error, not the
> netfilter server yet the servers that are bouncing the messages
> are looking at the original servers.

But then we wouldn't be able to see where mail had actually come
from, which would be unecessarily annoying.  If I *want* to apply my
own anti-spam metrics on the route of the email then so be it.  The
error here is not bouncing mail correctly to Sender or Return-Path:

Return-path: netfilter-bounces@lists.netfilter.org

MTAs that don't obey that will bounce mail back to the posters, not
the mailing list software, which breaks bounce handling, makes VERP
pointless, and is just plain broken.

> Again the mail list is not changing the from email address to be
> the mail list like I think they should.  IMHO any and all email
> passing through this list should be to and from the list email
> address.  Unfortunetly there is probably much debate on how to run
> mail lists and what should and should not be done.  But alass this
> is not really the proper place to do so.

It isn't the From which MTAs obey but the Sender, which in this case
is correctly set to be the mailing list.

Why remove useful info just to compensate for terribly broken
software?

> As of yet I have not tried contacting this mail list administrator
> to this regard so I can not comment one way or the other on their
> cooperation, perhaps it is time to do such.

Their address bounces too...

[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2005-06-15 19:57 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-06-15 17:23 Unzustellbar: [SPAM] - Re: Why does this connection stop being tr acked? - Sending mail server found on relays.ordb.org (fwd) R. DuFresne
2005-06-15 17:31 ` Andy Smith
2005-06-15 18:29   ` Taylor, Grant
2005-06-15 19:57     ` Andy Smith
2005-06-15 18:02 ` Jason Opperisano

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox