Tema: Re: Postfix UBE
Autorius: sysmonk
Data: 2008-09-04 00:24:51
ziuras wrote:
> Sveiki,
> Pirma karta gavau toki atsakyma, nezinau ka daryti.
> fructus.s-it.lt sako kad nepriima laisko siusto is l1pc02 kompo.
> Bet l1pc02 yra vidinis kompas (l1pc02.domain.local).
> Issiusta per mail.domen.lt, su kuriuo lygtais viskas tvarkoje?
> 
> Viduje naudoti isorinius vardus (l1pc02.dome.lt)? - nemanau kad tai gera 
> ideja.
> Sakyti postfixui kad sleptu is kokiu vidiniu pc gavo laiskus 
> (l1pc02.domen.local)? - nezinau kaip tai padaryti.
> O gal cia fructus.s-it.lt persistenge?
> 
> Busiu dekingas uz situacijos isaiskinima.

Manau, buvo UBE ne del vidinio ip'o, o del kitu priezasciu, bet 
trace'ino laiska iki vidinio ipo. Ir pati ataskaita yra generic amavis'o.

Gal esi kokiuose rbl'uose ar dar kur - pasitikrink. Jei ne - pabandyk 
susisekti su fruktais tais.

Del 'slepimo' gali naudoti header_checks ir IGNORE

pvz.:
header_checks = regexp:/etc/postfix/header_checks

ir /etc/postfix/header_checks kazkas panasaus i:
/^Received from: .*\[10\.18\.\d{1,3}\.\d{1,3}\]/ IGNORE



> 
> 
> 
> ----- Original Message ----- 
> From: "Content-filter at fructus.s-it.lt" <postmaster@fructus.s-it.lt>
> To: <audrius@domen.lt>
> Sent: 2008 m. rugpjucio 29 d. 12:25
> Subject: Considered UNSOLICITED BULK EMAIL, apparently from you
> 
> 
>> A message from <audrius@domen.lt> to:
>> -> robertas@edija.lt
>>
>> was considered unsolicited bulk e-mail (UBE).
>>
>> Our internal reference code for your message is 40941-18/CMeDNJ3KhisE
>>
>> The message carried your return address, so it was either a genuine mail
>> from you, or a sender address was faked and your e-mail address abused
>> by third party, in which case we apologize for undesired notification.
>>
>> We do try to minimize backscatter for more prominent cases of UBE and
>> for infected mail, but for less obvious cases of UBE some balance
>> between losing genuine mail and sending undesired backscatter is sought,
>> and there can be some collateral damage on both sides.
>>
>> According to a 'Received:' trace, the message originated at: [195.22.x.y],
>>  l1pc02 (unknown [10.18.x.y])
>>
>> Return-Path: <audrius@domen.lt>
>> Message-ID: <001501c909b9$2b757ed0$e09d120a@domen.local>
>> Subject: xxx
>>
>> Delivery of the email was stopped!
>>
> 
> 
> --------------------------------------------------------------------------------
> 
> 
>> Return-Path: <audrius@domen.lt>
>> Received: from mail.domen.lt (kmp.domen.lt [195.22.x.y])
>> by fructus.s-it.lt (Postfix) with ESMTP id 52D75A116F
>> for <robertas@edija.lt>; Fri, 29 Aug 2008 12:25:31 +0300 (EEST)
>> Received: from mail.domen.lt (localhost [127.0.0.1])
>> by mail.domen.lt (Postfix) with ESMTP id F19EB1F16FA
>> for <robertas@edija.lt>; Fri, 29 Aug 2008 12:25:29 +0300 (EEST)
>> Received: by mail.domen.lt (Postfix, from userid 8)
>> id E41711F16FC; Fri, 29 Aug 2008 12:25:29 +0300 (EEST)
>> X-Spam-Checker-Version: SpamAssassin 3.2.3 (2007-08-08) on mail.domen.lt
>> X-Spam-Level:
>> X-Spam-Status: No, score=-1.3 required=6.0 tests=ALL_TRUSTED,AWL,BAYES_00,
>> MIME_BASE64_TEXT,TVD_SPACE_RATIO autolearn=no version=3.2.3
>> Received: from l1pc02 (unknown [10.18.x.y])
>> by mail.domen.lt (Postfix) with SMTP id E5E821F16FA
>> for <robertas@edija.lt>; Fri, 29 Aug 2008 12:25:25 +0300 (EEST)
>> Message-ID: <001501c909b9$2b757ed0$e09d120a@domen.local>
>> Reply-To: "Audrius" <audrius@domen.lt>
>> From: "Audrius" <audrius@domen.lt>
>> To: "Robertas Vicys" <robertas@edija.lt>
>> Subject: xxx
>> Date: Fri, 29 Aug 2008 12:25:25 +0300
>> MIME-Version: 1.0
>> Content-Type: multipart/mixed;
>> boundary="----=_NextPart_000_0013_01C909D2.50849C60"
>> X-Priority: 3
>> X-MSMail-Priority: Normal
>> X-Mailer: Microsoft Outlook Express 6.00.2900.3138
>> X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3198
>> X-AV-Checked: ClamAV using ClamSMTP
>>
> 
>