OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: AW: postfix - postgrey - lost connection after RSET

lst_hoe02kwsoft.de
Date: Fri Nov 27 2009 - 08:48:05 CST


Zitat von Eero Volotinen <eero.volotineniki.fi>:

> Braun Björn wrote:
>> My logs (mail.log)
>>
>> Nov 5 10:07:56 grey2 postfix/smtpd[7153]: connect from
>> unknown[ddd.dd.ddd.dd]
>> Nov 5 10:07:56 grey2 postfix/smtpd[7153]: NOQUEUE: reject: RCPT
>> from unknown[ddd.dd.ddd.dd]: 450 4.7.1 <aaaaaa.DE>: Recipient
>> address rejected: Greylisted, see
>> http://isg.ee.ethz.ch/tools/postgrey/help/aaa.DE.html;
>> from=<bbbbbb.com> to=<aaabbb.DE> proto=ESMTP helo=<mail.bbb.com>
>> Nov 5 10:07:56 grey2 postfix/smtpd[7153]: lost connection after
>> RSET from unknown[ddd.dd.ddd.dd]
>> Nov 5 10:07:56 grey2 postfix/smtpd[7153]: disconnect from
>> unknown[ddd.dd.ddd.dd]
>>
>> Or are these the wrong logs?
>
> Well, looks like spammer is connecting from ddd.dd.ddd.dd and after
> graylisting (45X temporary error) spammer software just drops
> connection.

This depends if "aaaaaa.DE" is missing a mail from "bbbbbb.com" and
"ddd.dd.ddd.dd" is a valid mailserver for "bbb.com" then the problem
is worth to investigate.

Regards

Andreas