OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: "lost connection after CONNECT" in logs

From: Artem Bokhan (artistacadem.org)
Date: Tue Oct 02 2007 - 00:34:04 CDT


After upgrading to 2.4.5:

Oct 2 12:24:58 postfix-smtp/smtpd[2805]: connect from unknown[unknown]
Oct 2 12:24:58 postfix-smtp/smtpd[2805]: lost connection after CONNECT
from unknown[unknown]
Oct 2 12:24:58 postfix-smtp/smtpd[2805]: disconnect from unknown[unknown]

Is it correct behaviour? There is no way to catch the real client's
ip-address?

Wietse Venema ?????:
> Bokhan Artem:
>
>> Wietse Venema ?????:
>>
>>> Bokhan Artem:
>>>
>>>> >accept(6, {sa_family=AF_INET, sin_port=htons(4867),
>>>> sin_addr=inet_addr("88.243.14.120")}, [221520815261220880]) = 17
>>>>
>>>> As I understand, this is remote smtp client, so why localhost(127.0.0.1)
>>>> is logged?
>>>>
>>> Upgrade to 2.3.10 or later.
>>>
>>> Wietse
>>>
>> It's 2.4.0
>>
>
> Upgrade to 2.4.2 or later.
>
> Wietse
>
> +
> + 20070425
> +
> + Bugfix: don't falsely report "lost connection from
> + localhost[127.0.0.1]" when Postfix is being portscanned.
> + Files: smtpd/smtpd_peer.c, qmqpd/qmqpd_peer.c.
>
>