OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Andrew McNamara (andrewmconnect.com.au)
Date: Sun Jan 21 2001 - 18:43:07 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    >> This used is getting about 55 copies if the email, over and over
    >> again... any suggestions?
    >>
    >> Jan 19 10:30:38 wwboldmail postfix/smtp[48764]: 4EA7A262987: to=<kdowlingsiemens-psc.com>, relay=eaugalle.siemens-psc.com[161.134.129.6], delay=328126, status=deferred (lost connection with eaugalle.siemens-psc.com[161.134.129.6] while sending end of data -- message may be sent more than once)
    >
    >Pretty interesting prompt from this server:
    >Connected to 161.134.129.6.
    >220 **************************************0******0*********20 ****200**0*********0*00

    AH! Yes - it's a Cisco PIX, configured to do "fixup protocol smtp".
    From cisco's web site:

        As of version 5.1 and later, the fixup protocol smtp command changes
        the characters in the SMTP banner to asterisks except for the "2", "0",
        "0 " characters. Carriage return (CR) and linefeed (LF) characters are
        ignored.

    These boxes have a bug when running code less than 5.2(4) or 6.0(1):

        Bug Id : CSCds90792

        Headline: fixup smtp blocks emails when . and are not in the same packet

        When the "." and "CRLF", to specify EOF of an email, are crossing the
        PIX from the outside to inside, in seperated packets, the PIX drops
        the whole email and does not let it in. As a workaround, fixup
        protocol smtp can be disabled. The PIX now handle the case when
        "." termination sequence is split across multiple TCP frames.

     ---
    Andrew McNamara (System Architect)

    connect.com.au Pty Ltd
    Lvl 3, 213 Miller St, North Sydney, NSW 2060, Australia
    Phone: +61 2 9409 2117, Fax: +61 2 9409 2111