[Remops] Hastio trying to send malformed messages

Senshi-Admin admin at senshi.homeip.net
Mon May 11 00:33:43 BST 2009


-----BEGIN PGP SIGNED MESSAGE-----

Hi,

Hastio is trying to deliver tons of messages to the adress of senshi's pinger,
but they are refused because the RCPT TO: is damaged.
Example:

01:22:38.515: Connection from 83.41.2.244, Mon May 11 01:22:38 2009<lf>
01:22:38.515: << 220 senshi.homeip.net ESMTP server ready.<cr><lf>
01:22:38.367: >> EHLO mercurio.hastio.org<cr><lf>
01:22:38.377: << 250-senshi.homeip.net Hello mercurio.hastio.org; ESMTPs are:<cr><lf>250-TIME<cr><lf>
01:22:38.377: << 250-SIZE 0<cr><lf>
01:22:38.377: << 250-AUTH CRAM-MD5 LOGIN<cr><lf>
01:22:38.377: << 250-AUTH=LOGIN<cr><lf>
01:22:38.377: << 250 HELP<cr><lf>
01:22:39.787: >> MAIL FROM:<hastiobounce at gmail.com> SIZE=785<cr><lf>
01:22:56.902: << 250 Sender and size (785) OK - send RCPTs.<cr><lf>
01:22:56.042: >> RCPT TO:<remail at senshi.homeiES: F 0ES: F 090511012236><cr><lf>

I just noticed it, and it seems to have started at about 2009-05-09 23:15 GMT.

For now, I'm blocking hastio's IP at the firewall. Please tell me when you have
fixed your mail server so I can remove the block.

Senshi-Admin


-----BEGIN PGP SIGNATURE-----
Version: N/A

iQEVAwUBSgdWPXwq7QUG6CVfAQFKvAf6Au9Dmro3TjXP2G1GPqMOEQnk8yRYoPuw
Dyh1NcQdM6wl6QLNzft8a7AFRP6gX1zSw7LzflhqRbo63ptj3RTohSaIAmJYuEZP
//R08X8Ldv3lleBAC7uOw6Jov+ZXj4jrCHVNS1CI5XkkOrLzN3KRfjNc80+zIr49
tU/H0/BONzNH/dXUAGagTlJh10k7P677PBNnmwegnHzK16MvFMEdjYlWDuv98E4H
/ykqxiSNrEbFp2fz+uefisO5e7eoK191Cn4wrxwgT1RA/AwMTrxMm1heaCMlg5ro
/7x4DIVFD+fg/VwfQQa1XFHz6JZV5HWcP9ypK34mnz1n86g9ZRMcpQ==
=DZUU
-----END PGP SIGNATURE-----



More information about the Remops mailing list