Re: CGP 4.2.8 Return-path validation seems broken

От: Dmitry Akindinov <CGatePro_at_mx_ru>
Дата: Thu 13 Jan 2005 - 11:20:48 MSK

Здравствуйте,

Nickolay Kondrashov wrote:
>
> Hello
>
> Yesterday i've upgraded to 4.2.8 from 4.2.5 and encountered following
> bug(?):

Проблема известная и уже исправлена для следующих версий: при использовании в настройках SMTP smarthost'а неправильно проверяется через DNS имя домена в return-path. Временно отключите forwarding server или проверку return-path.

> All incoming messages was rejected with the string in the logs like:
>
> 22:53:38.88 1 SMTPI-00001([192.168.0.8]) Return-Path
> 'bugtraq-return-17654-knu=avtomatikarus.com@securityfocus.com' rejected:
> host name is unknown
>
> After setting DNR and SMTP log level to "All info" and checking bind
> request logs i've found, that just before reporting string above DNR
> tried to resolve curious domain name '*' (without quotes). Low details
> log follows:
>
> 23:12:37.94 3 DNR-00020(*) MX:host name is unknown
> 23:12:37.94 3 DNR-00021(*) A:host name is unknown
> 23:12:37.94 1 SMTPI-00005([192.168.0.8]) Return-Path
> 'asterisk-users-bounces@lists.digium.com' rejected: host name is unknown
>
> And DNR "All info" log is below:
>
> 23:38:25.43 4 DNR-00001(mail.avtsev.spb.ru) A-request
> 23:38:25.43 4 DNR-00001(mail.avtsev.spb.ru) request sent to [127.0.0.1]
> 23:38:25.46 5 DNR-00001(mail.avtsev.spb.ru) got 131 bytes from
> [127.0.0.1:53]: 00 01 81 80 00 01 00 01 00 02 00 02 04 6D 61 69 6C 06 61
> 76 74 73 65 76 03 73 70 62 02 72 75 00 00 01 00 01 C0 0C 00 01 00 01 00
> 00 07 08 00 04 D4 77 BF 1A C0 11 00 02 00 01 00 00 07 08 00 10 04 64 6E
> 73 32 05 7A 65 6E
> 23:38:25.46 5 DNR-00001(mail.avtsev.spb.ru) A:OK
> 23:38:25.46 4 DNR-00001(mail.avtsev.spb.ru) A-response[0]:
> mail.avtsev.spb.ru=[212.119.191.26]
> 23:38:25.54 4 DNR-00002(mail.avtsev.spb.ru) A-request
> 23:38:25.54 5 DNR-00002(mail.avtsev.spb.ru) got 131 bytes from
> [127.0.0.1:53]: 00 02 81 80 00 01 00 01 00 02 00 02 04 6D 61 69 6C 06 61
> 76 74 73 65 76 03 73 70 62 02 72 75 00 00 01 00 01 C0 0C 00 01 00 01 00
> 00 07 08 00 04 D4 77 BF 1A C0 11 00 02 00 01 00 00 07 08 00 10 04 64 6E
> 73 31 05 7A 65 6E
> 23:38:25.54 4 DNR-00002(mail.avtsev.spb.ru) request sent to [127.0.0.1]
> 23:38:25.54 5 DNR-00002(mail.avtsev.spb.ru) A:OK
> 23:38:25.54 4 DNR-00002(mail.avtsev.spb.ru) A-response[0]:
> mail.avtsev.spb.ru=[212.119.191.26]
> 23:38:25.55 4 DNR-00003(*) MX-request
> 23:38:25.55 5 DNR-00003(*) got 94 bytes from [127.0.0.1:53]: 00 03 81 83
> 00 01 00 00 00 01 00 00 01 2A 00 00 0F 00 01 00 00 06 00 01 00 00 0C 91
> 00 40 01 41 0C 52 4F 4F 54 2D 53 45 52 56 45 52 53 03 4E 45 54 00 05 4E
> 53 54 4C 44 0C 56 45 52 49 53 49 47 4E 2D 47 52 53 03 43 4F 4D 00 77 82
> 0A 9D 00
> 23:38:25.55 4 DNR-00003(*) request sent to [127.0.0.1]
> 23:38:25.55 3 DNR-00003(*) MX:host name is unknown
> 23:38:25.55 4 DNR-00004(*) A-request
> 23:38:25.55 5 DNR-00004(*) got 94 bytes from [127.0.0.1:53]: 00 04 81 83
> 00 01 00 00 00 01 00 00 01 2A 00 00 01 00 01 00 00 06 00 01 00 00 0C 91
> 00 40 01 41 0C 52 4F 4F 54 2D 53 45 52 56 45 52 53 03 4E 45 54 00 05 4E
> 53 54 4C 44 0C 56 45 52 49 53 49 47 4E 2D 47 52 53 03 43 4F 4D 00 77 82
> 0A 9D 00
> 23:38:25.55 4 DNR-00004(*) request sent to [127.0.0.1]
> 23:38:25.55 3 DNR-00004(*) A:host name is unknown
> 23:38:25.55 1 SMTPI-00001([192.168.0.8]) Return-Path
> 'root@mail.avtsev.spb.ru' rejected: host name is unknown
>
> mail.avtsev.spb.ru - is our gateway.
>
> For a while, I just set "Verify: HELO and Return Paths for:" in the
> "SMTP settings/Receiving" pane to "nobody". And it accepts messages now.
> I think I should note, that with the CGP 4.2.5 everything was working fine.
>
> Thank you for your attention.
>

-- 
Best regards,
Dmitry Akindinov -- Stalker Labs.
Получено Thu Jan 13 08:20:08 2005

Этот архив был сгенерирован hypermail 2.1.8 : Tue 21 Feb 2006 - 03:15:44 MSK