Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 27 Aug 2015 13:55:37 -0400
From:      Robert Sargent <robtsgt@sgt.com>
To:        freebsd-security@freebsd.org
Subject:   sendmail server sending milter data after latest FreeBSD upgrade
Message-ID:  <201508271755.t7RHtdjO009327@sgt.com>

index | next in thread | raw e-mail

[-- Attachment #1 --]

Hi,

After rebuilding my systems after the latest openssl/iret handler I noticed some incoming email sessions were failing.  The failures were primarily from hotmail.com, outlook.com, google.com and me.com.  The SMTP server [sendmail v 8.15.2] logs contained lines like this:

Aug 27 14:41:22 tusk sm-mta[18366]: t7REfKQd018366: col004-omc4s12.hotmail.com [65.55.34.214] did not issue MAIL/EXPN/VRFY/ETRN during connection to IPv4

I captured some packets with tcpdump and read them with wireshark.  The failed session packets' contents indicated after the SYN, SYN, ACK  3-way handshake I would send out 

Response: milter_negotiate(milter-regex): send: version 6, fflags 0x1ff, pflags 0x1fffff\n

I then rec'd an ACK from the client and then I would send out more milter data like:

Response: milter_negotiate(milter-regex): received: version 6, fflags 0x20, pflags 0x300\n
Response: milter_negotiate(opendkim): send: version 6, fflags 0x1ff, pflags 0x1fffff\n
Response: milter_negotiate(opendkim): received: version 6, fflags 0x111, pflags 0x100702\n
Response: milter_negotiate(smf-spf): send: version 6, fflags 0x1ff, pflags 0x1fffff\n
Response: milter_negotiate(smf-spf): received: version 6, fflags 0x1d, pflags 0x350\n
Response: milter_negotiate(greylist): send: version 6, fflags 0x1ff, pflags 0x1fffff\n
Response: milter_negotiate(greylist): received: version 6, fflags 0x13, pflags 0x100\n
Response: milter_negotiate(clmilter): send: version 6, fflags 0x1ff, pflags 0x1fffff\n
Response: milter_negotiate(clmilter): received: version 6, fflags 0x31, pflags 0x342\n

The client would then ACK and I would send out my normal SMTP greeting:

Response: 220 tusk.sgt.com ESMTP Sendmail 8.15.2/8.14.9; Thu, 27 Aug 2015 12:24:38 GMT\r\n

Then the client would send a FIN

-------------------

Needless to say I was concerned and tried restarting sendmail and associated milters, no change, I kept sending out milter data to the client.

I tried reinstalling sendmail from both pkgs and ports, no change.

I finally rebooted the system and the problem "went away".

There was no problem with incoming hotmail, google, apple emails prior to this latest OS upgrade.

uname -a:  FreeBSD tusk.sgt.com 9.3-RELEASE-p24 FreeBSD 9.3-RELEASE-p24 #10 r287147: Tue Aug 25 23:19:33 UTC 2015     root@tusk.sgt.com:/usr/obj/usr/src/sys/SGT93AMD64ZFS  amd64


Is this a known problem? Any ideas WTF is [was] going on?  Any suggestions on what to do next time it happens [short of rebooting]?

Please do not publicly release any of my site/domain specific data.

tcpdumpfile attached.

Thanks,
Rob


[-- Attachment #2 --]
òUBB)DԉE4"@1tA7"kh} A5xUBBDԉ)E4"@@khA7"^F}㾀xU
\
<<)DԉE("s@1tA7"kh}㾣^GPwUwDԉ)Ew"@@khA7"^G}P?milter_negotiate(milter-regex): send: version 6, fflags 0x1ff, pflags 0x1fffff
U#<<)DԉE($@1rA7"kh}㾣^P)U7Dԉ)E"@@khA7"^}Pmilter_negotiate(milter-regex): received: version 6, fflags 0x20, pflags 0x300
milter_negotiate(opendkim): send: version 6, fflags 0x1ff, pflags 0x1fffff
milter_negotiate(opendkim): received: version 6, fflags 0x111, pflags 0x100702
milter_negotiate(smf-spf): send: version 6, fflags 0x1ff, pflags 0x1fffff
milter_negotiate(smf-spf): received: version 6, fflags 0x1d, pflags 0x350
milter_negotiate(greylist): send: version 6, fflags 0x1ff, pflags 0x1fffff
milter_negotiate(greylist): received: version 6, fflags 0x13, pflags 0x100
milter_negotiate(clmilter): send: version 6, fflags 0x1ff, pflags 0x1fffff
milter_negotiate(clmilter): received: version 6, fflags 0x31, pflags 0x342
U<<)DԉE(&d@1pA7"kh}㾣a?PU~Dԉ)Ev"@@khA7"a?}P>220 tusk.sgt.com ESMTP Sendmail 8.15.2/8.14.9; Thu, 27 Aug 2015 12:24:38 GMT
U<<)DԉE()^@1mA7"kh}㾣aP4U<<Dԉ)E("@@khA7"a}PUE<<Dԉ)E("@@khA7"a}PUe<<)DԉE()@1miA7"kh}㿣aP3UFBB)DԉE4U@+A6Wkha^4 6xUZBBDԉ)E4"@@khA6Wa^4NxUS 	<<)DԉE(VC@++A6Wkha^4PߏU
H
Dԉ)Ew"@@khA6Wa^4PNmilter_negotiate(milter-regex): send: version 6, fflags 0x1ff, pflags 0x1fffff
U<<)DԉE(XB@+,A6Wkha^4PAUDԉ)E"@@khA6Wa^4PQ%milter_negotiate(milter-regex): received: version 6, fflags 0x20, pflags 0x300
milter_negotiate(opendkim): send: version 6, fflags 0x1ff, pflags 0x1fffff
milter_negotiate(opendkim): received: version 6, fflags 0x111, pflags 0x100702
milter_negotiate(smf-spf): send: version 6, fflags 0x1ff, pflags 0x1fffff
milter_negotiate(smf-spf): received: version 6, fflags 0x1d, pflags 0x350
milter_negotiate(greylist): send: version 6, fflags 0x1ff, pflags 0x1fffff
milter_negotiate(greylist): received: version 6, fflags 0x13, pflags 0x100
milter_negotiate(clmilter): send: version 6, fflags 0x1ff, pflags 0x1fffff
milter_negotiate(clmilter): received: version 6, fflags 0x31, pflags 0x342
U_<<)DԉE(Yw@+A6Wkha^4PܚUUP
Dԉ)Ev"@@khA6Wa^4PN220 tusk.sgt.com ESMTP Sendmail 8.15.2/8.14.9; Thu, 27 Aug 2015 12:24:41 GMT
UX<<)DԉE(`.@+@A6Wkha^4PLUj<<Dԉ)E("@@khA6Wa^4PN|U<<Dԉ)E("@@khA6Wa^4PN|Ul+
<<)DԉE(`@+A6Wkha^4
PK
[-- Attachment #3 --]



help

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201508271755.t7RHtdjO009327>