OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: Strange Issues with my mailserver setup...

From: Dusty (dustyfuckthegov.co.uk)
Date: Fri Jun 27 2008 - 10:26:18 CDT


Sorry my fault. Tested from the wrong client.

I sent a reply to buqtrack-querysecurityfocus.com here is the log, I have not recieved anything back either just like the list:

Jun 27 15:24:01 stoned-hacker postfix/smtpd[32760]: connect from localhost.localdomain[127.0.0.1]
Jun 27 15:24:01 stoned-hacker postfix/smtpd[32760]: C023719E098A: client=localhost.localdomain[127.0.0.1]
Jun 27 15:24:01 stoned-hacker postfix/cleanup[32763]: C023719E098A: message-id=<a42bd52e94b5c3f8a5eb09cdd2314445localhost>
Jun 27 15:24:01 stoned-hacker postfix/qmgr[31981]: C023719E098A: from=<dustyfuckthegov.co.uk>, size=491, nrcpt=1 (queue active)
Jun 27 15:24:01 stoned-hacker dovecot: IMAP(dustyfuckthegov.co.uk): Disconnected: Logged out
Jun 27 15:24:01 stoned-hacker postfix/smtpd[32760]: disconnect from localhost.localdomain[127.0.0.1]
Jun 27 15:24:02 stoned-hacker dovecot: imap-login: Login: user=<dustyfuckthegov.co.uk>, method=PLAIN, rip=127.0.0.1, lip=127.0.0.1, secured
Jun 27 15:24:02 stoned-hacker dovecot: IMAP(dustyfuckthegov.co.uk): Disconnected: Logged out
Jun 27 15:24:02 stoned-hacker dovecot: imap-login: Login: user=<dustyfuckthegov.co.uk>, method=PLAIN, rip=127.0.0.1, lip=127.0.0.1, secured
Jun 27 15:24:02 stoned-hacker dovecot: IMAP(dustyfuckthegov.co.uk): Disconnected: Logged out
Jun 27 15:24:06 stoned-hacker postfix/smtpd[1328]: connect from localhost.localdomain[127.0.0.1]
Jun 27 15:24:06 stoned-hacker postfix/smtpd[1328]: 49B8719E098B: client=localhost.localdomain[127.0.0.1]
Jun 27 15:24:06 stoned-hacker postfix/cleanup[32763]: 49B8719E098B: message-id=<a42bd52e94b5c3f8a5eb09cdd2314445localhost>
Jun 27 15:24:06 stoned-hacker postfix/qmgr[31981]: 49B8719E098B: from=<dustyfuckthegov.co.uk>, size=987, nrcpt=1 (queue active)
Jun 27 15:24:06 stoned-hacker postfix/smtpd[1328]: disconnect from localhost.localdomain[127.0.0.1]
Jun 27 15:24:06 stoned-hacker amavis[30506]: (30506-04) Passed CLEAN, LOCAL [127.0.0.1] [127.0.0.1] <dustyfuckthegov.co.uk> -> <bugtraq-querysecurityfocus.com>, Message-ID: <a42bd52e94b5c3f8a5eb09cdd2314445localhost>, mail_id: EhdDNtUm9-Um, Hits: 1.694, size: 491, queued_as: 49B8719E098B, 4516 ms
Jun 27 15:24:06 stoned-hacker postfix/smtp[32764]: C023719E098A: to=<bugtraq-querysecurityfocus.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=4.5, delays=0.01/0/0/4.5, dsn=2.0.0, status=sent (250 2.0.0 Ok: queued as 49B8719E098B)
Jun 27 15:24:06 stoned-hacker postfix/qmgr[31981]: C023719E098A: removed
Jun 27 15:24:07 stoned-hacker postfix/smtp[1329]: 49B8719E098B: to=<bugtraq-querysecurityfocus.com>, relay=mx1.securityfocus.com[205.206.231.35]:25, delay=1.3, delays=0.01/0.01/0.92/0.4, dsn=2.0.0, status=sent (250 2.0.0 m5R8kBgP003919 Message accepted for delivery)
Jun 27 15:24:07 stoned-hacker postfix/qmgr[31981]: 49B8719E098B: removed

rootstoned-hacker:/etc/postfix# postconf -n
alias_database = hash:/etc/aliases
alias_maps = hash:/etc/aliases
append_dot_mydomain = no
biff = no
config_directory = /etc/postfix
content_filter = smtp-amavis:[127.0.0.1]:10024
inet_interfaces = all
mailbox_size_limit = 0
mydestination = localhost.co.uk, localhost
myhostname = stoned-hacker.co.uk
mynetworks = 127.0.0.0/8 [::ffff:127.0.0.0]/104 [::1]/128
myorigin = /etc/mailname
readme_directory = no
receive_override_options = no_address_mappings
recipient_delimiter = +
relayhost =
smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache
smtpd_banner = $myhostname ESMTP $mail_name (Ubuntu)
smtpd_recipient_restrictions = permit_mynetworks,permit_sasl_authenticated,reject_unauth_destination
smtpd_sasl_auth_enable = yes
smtpd_sasl_path = private/auth
smtpd_sasl_type = dovecot
smtpd_sender_restrictions = permit_mynetworks, check_sender_access hash:/etc/postfix/sender_access, reject_unknown_sender_domain
smtpd_tls_auth_only = yes
smtpd_tls_cert_file = /etc/ssl/certs/postfix.pem
smtpd_tls_key_file = /etc/ssl/private/postfix.pem
smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache
smtpd_use_tls = yes
virtual_alias_maps = mysql:/etc/postfix/mysql-virtual-alias-maps.cf,mysql:/etc/postfix/mysql-email2email.cf
virtual_gid_maps = static:5000
virtual_mailbox_domains = mysql:/etc/postfix/mysql-virtual-mailbox-domains.cf
virtual_mailbox_maps = mysql:/etc/postfix/mysql-virtual-mailbox-maps.cf
virtual_transport = dovecot
virtual_uid_maps = static:5000
rootstoned-hacker:/etc/postfix#

On Fri, 27 Jun 2008 17:19:21 +0200, Martin Barry <martysupine.com> wrote:
> $quoted_author = "Dusty" ;
>>
>> Jun 27 15:10:31 stoned-hacker postfix/smtpd[32459]: connect from
> host81-152-220-205.range81-152.btcentralplus.com[81.152.220.205]
>> Jun 27 15:10:32 stoned-hacker postfix/smtpd[32459]: NOQUEUE: reject:
> RCPT from host81-152-220-205.range81-152.btcentralplus.com[81.152.220.205]:
> 554 5.7.1 <bugtraq-querysecurityfocus.com>: Relay access denied;
> from=<dustyfuckthegov.co.uk> to=<bugtraq-querysecurityfocus.com>
> proto=ESMTP helo=<[127.0.0.1]>
>> Jun 27 15:10:37 stoned-hacker postfix/smtpd[32459]: disconnect from
> host81-152-220-205.range81-152.btcentralplus.com[81.152.220.205]
>>
>> looks like they have temporarily blocked me or something ?
>
> This is *your* server rejecting you. How are you sending mail?
>
>
> cheers
> Marty