OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
)

From: Justin Piszcz (jpiszczlucidpixels.com)
Date: Mon Feb 18 2008 - 17:53:50 CST


On Mon, 18 Feb 2008, Wietse Venema wrote:

> Justin Piszcz:
>> Feb 18 17:32:13 p34 postfix/smtpd[15280]: >
>> caduceus2.gmu.edu[129.174.0.41]: 354 End data with <CR><LF>.<CR><LF>
>> Feb 18 17:32:13 p34 postfix/cleanup[15983]: 15B921C000267:
>> message-id=<47B9BA48.5020905gmu.edu>
>> Feb 18 17:32:13 p34 postfix/cleanup[15983]: 15B921C000267: warning:
>> header User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1;
>> en-US; rv:1.7.2)? Gecko/20040804 Netscape/7.2 (ax) from
>> caduceus2.gmu.edu[129.174.0.41]; from=<usermail04.gmu.edu>
>> to=<jpiszczlucidpixels.com> proto=ESMTP helo=<caduceus2.gmu.edu>:
>> RULE=410
>> Feb 18 17:37:14 p34 postfix/smtpd[15280]: >
>> caduceus2.gmu.edu[129.174.0.41]: 421 4.4.2 lucidpixels.com
>> Error: timeout exceeded
>
> Suspect a broken firewall or anti-virus software. You may be able
> to capture an SMTP session
>
> # tcpdump -s 0 -w /file/name host xx and port 25
>
> as described in DEBUG_README. This will show whether the client
> sends <CR><LF>.<CR><LF> or whether something screws up the protocol.
>
> Wietse
>

There is an attachment (~1 MiB) and it sends a lot of it but then it stops
at this point, and then it hangs up and disconnects, never completing the end
of data transaction. Looks like a problem on their end, thanks. I have
forwarded the message a few times and it is reproducible.

##
T 129.174.0.40:53405 -> 75.144.35.66:25 [AP]
   ICAgICAg..ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgCiAgICAgI
   CAgICAg..ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIC
   AgICAg..ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAKICAgICAgICAgICAgICA
   gICAg..ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
   ICAg..ICAgICAgICAgICAgICAgICAgICAgICAgICAgIAogICAgICAgICAgICAgICAgICAgICAgI
   CAg..ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIC
   Ag..ICAgICAgICAgICAgICAgICAgICAgCiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICA
   g..ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
   ..ICAgICAgICAgICAgICAKICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg.
   .ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg..
   ICAgICAgIAogICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg..I
   CAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg..Ci
   AgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIC
#
T 75.144.35.66:25 -> 129.174.0.40:53405 [AP]
   421 4.4.2 lucidpixels.com Error: timeout exceeded..
##

Will follow up with the admins on their end.

Justin.