tdldp
02-13-2008, 02:49 AM
Hi jeff and all DA community...
I have a problem which could be a potential bug i do not explain...
I have a client, which is experiencing system error return messages due to users unknown or to defer due to policy infringement at yahoo and nate.com
let me show you logs :
Here is log for yahoo...
2008-02-13 10:35:18 1JNluV-0006K2-UE SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == kmj2804@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == yhfighting@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == myung57@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == rgveda11@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == sseahee@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == woosungs2000@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == bag8282@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == ok5707@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == rmrdl77@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == rtos2000@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == sbr217@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE SMTP error from remote mail server after initial connection: host mx3a.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == kjy712129@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3a.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == lynniya@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3a.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == ms770610@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3a.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == yksyks97@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3a.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE ** yksyks97@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** ms770610@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** lynniya@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** kjy712129@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** sbr217@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** rtos2000@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** rmrdl77@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** ok5707@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** bag8282@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** woosungs2000@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** sseahee@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** rgveda11@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** myung57@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** yhfighting@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** kmj2804@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE Completed
2008-02-13 10:35:18 1JPE1O-0007Fu-PB <= <> R=1JNluV-0006K2-UE U=mail P=local S=6893 T="Mail delivery failed: returning message to sender" from <> for admin@car-consulting.fr
2008-02-13 10:35:18 1JPE1O-0007Fu-PB => admin <admin@car-consulting.fr> F=<> R=virtual_user T=virtual_localdelivery S=6993
2008-02-13 10:35:18 1JPE1O-0007Fu-PB Completed
and nate.com
2008-02-13 10:27:48 1JPDu8-000717-Io <= info@car-consulting.fr H=(nlueuph.net) [211.208.187.130] P=smtp S=1067 T="¢º±ÝÀ¶±Ç´ë~Ãâ(³â7.5~12%)49595" from <info@car-consulting.fr> for winphj@nate.com
2008-02-13 10:27:50 1JPDu8-000717-Io ** winphj@nate.com F=<info@car-consulting.fr> R=lookuphost T=remote_smtp: SMTP error from remote mail server after end of data: host smtp.nate.com [203.226.255.61]: 541 5.6.0 Your message was rejected by PATTERN FILTER
2008-02-13 10:27:50 1JPDuA-00071I-RI <= <> R=1JPDu8-000717-Io U=mail P=local S=2005 T="Mail delivery failed: returning message to sender" from <> for info@car-consulting.fr
2008-02-13 10:27:50 1JPDu8-000717-Io Completed
2008-02-13 10:27:50 1JPDuA-00071I-RI => info <info@car-consulting.fr> F=<> R=virtual_user T=virtual_localdelivery S=2104
2008-02-13 10:27:50 1JPDuA-00071I-RI Completed
Problem is following :
Account admin@car-consulting.fr doesn't exist on our servers.... But apparently there seems to be activity on this email...
Account info@car-consulting.fr exists but has passwords changed every 2 days... latest set this morning is 13 caracteres long alpha-numerical... It is technically impossible this password could get hacked in less than 5 minutes...
Where is the problem...
What acl should i use to block these mail sendings from our servers ???
(i've check rbl status, and server ip seems still to be clean... Only considered as problem on yahoo filtering system)
Edit : I've tested adding domains and sender email admin@car-consulting.fr in blacklist senders, and this doesn't solve anything...
User has experienced 549 system error messages that he shouldn't have to receive...
This is very weird...
Thks for urgent response
Tdldp
I have a problem which could be a potential bug i do not explain...
I have a client, which is experiencing system error return messages due to users unknown or to defer due to policy infringement at yahoo and nate.com
let me show you logs :
Here is log for yahoo...
2008-02-13 10:35:18 1JNluV-0006K2-UE SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == kmj2804@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == yhfighting@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == myung57@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == rgveda11@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == sseahee@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == woosungs2000@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == bag8282@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == ok5707@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == rmrdl77@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == rtos2000@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == sbr217@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE SMTP error from remote mail server after initial connection: host mx3a.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == kjy712129@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3a.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == lynniya@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3a.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == ms770610@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3a.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == yksyks97@yahoo.co.kr R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3a.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE ** yksyks97@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** ms770610@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** lynniya@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** kjy712129@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** sbr217@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** rtos2000@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** rmrdl77@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** ok5707@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** bag8282@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** woosungs2000@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** sseahee@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** rgveda11@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** myung57@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** yhfighting@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** kmj2804@yahoo.co.kr: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE Completed
2008-02-13 10:35:18 1JPE1O-0007Fu-PB <= <> R=1JNluV-0006K2-UE U=mail P=local S=6893 T="Mail delivery failed: returning message to sender" from <> for admin@car-consulting.fr
2008-02-13 10:35:18 1JPE1O-0007Fu-PB => admin <admin@car-consulting.fr> F=<> R=virtual_user T=virtual_localdelivery S=6993
2008-02-13 10:35:18 1JPE1O-0007Fu-PB Completed
and nate.com
2008-02-13 10:27:48 1JPDu8-000717-Io <= info@car-consulting.fr H=(nlueuph.net) [211.208.187.130] P=smtp S=1067 T="¢º±ÝÀ¶±Ç´ë~Ãâ(³â7.5~12%)49595" from <info@car-consulting.fr> for winphj@nate.com
2008-02-13 10:27:50 1JPDu8-000717-Io ** winphj@nate.com F=<info@car-consulting.fr> R=lookuphost T=remote_smtp: SMTP error from remote mail server after end of data: host smtp.nate.com [203.226.255.61]: 541 5.6.0 Your message was rejected by PATTERN FILTER
2008-02-13 10:27:50 1JPDuA-00071I-RI <= <> R=1JPDu8-000717-Io U=mail P=local S=2005 T="Mail delivery failed: returning message to sender" from <> for info@car-consulting.fr
2008-02-13 10:27:50 1JPDu8-000717-Io Completed
2008-02-13 10:27:50 1JPDuA-00071I-RI => info <info@car-consulting.fr> F=<> R=virtual_user T=virtual_localdelivery S=2104
2008-02-13 10:27:50 1JPDuA-00071I-RI Completed
Problem is following :
Account admin@car-consulting.fr doesn't exist on our servers.... But apparently there seems to be activity on this email...
Account info@car-consulting.fr exists but has passwords changed every 2 days... latest set this morning is 13 caracteres long alpha-numerical... It is technically impossible this password could get hacked in less than 5 minutes...
Where is the problem...
What acl should i use to block these mail sendings from our servers ???
(i've check rbl status, and server ip seems still to be clean... Only considered as problem on yahoo filtering system)
Edit : I've tested adding domains and sender email admin@car-consulting.fr in blacklist senders, and this doesn't solve anything...
User has experienced 549 system error messages that he shouldn't have to receive...
This is very weird...
Thks for urgent response
Tdldp