OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Timeout after EHLO

From: Ace Suares (listssuares.an)
Date: Wed Dec 13 2006 - 07:46:37 CST


On Wednesday 13 December 2006 09:29, Wietse Venema wrote:

>
> Or you could use the combined expertise of this mailing list
> to help you explain what the data means.

Indeed, that would be great. So, shall I upload a tcpdump file, or how to
go about that ?

I dumped all traffic on port 25 for a while, resulting in a 65k gz file,
with of course lots of not-anonymized data in it (IP numbers, hostnames,
emailaddresses etc.)

There are a lot of checksum errors in it, but googling for that leads me
to believe it's not always a problem.

I see a lot of commands from my server to theirs: EHLO, MAIL FROM, RCPT
TO, and some DATA. But the DATA part is always empty and it seems the
conversation times out then.

Also, I see a reply to the EHLO command from their servers: all
those '250' replies.

But I never see a response to a MAIL FROM or a RCPT TO.

Now in my infinite ignorance, I'd think that my server was 'too fast' with
sending responses - when I telnet I am used to see some '2xx OK' response
after MAIL FROM, for instance, that is not happening.

With what kind of info can I provide this list ?

Cheers,
ace

>
> Wietse