qmail Digest 19 Jul 1999 10:00:00 -0000 Issue 702

Topics (messages 27907 through 27931):

CNAME_lookup_failed_temportarily
        27907 by: Tom Walsh <[EMAIL PROTECTED]>

Qmail exited
        27908 by: "Sam" <[EMAIL PROTECTED]>
        27909 by: Stefan Paletta <[EMAIL PROTECTED]>

Tcpserver and cyclog
        27910 by: Matthew Harrell <[EMAIL PROTECTED]>
        27911 by: Chris Johnson <[EMAIL PROTECTED]>
        27912 by: Ken Jones <[EMAIL PROTECTED]>
        27913 by: Matthew Harrell <[EMAIL PROTECTED]>
        27914 by: Matthew Harrell <[EMAIL PROTECTED]>

Load Balancing Of 2 Qmail servers
        27915 by: "Matt Schnierle" <[EMAIL PROTECTED]>

whoson and qmail
        27916 by: "Andrzej Kukula" <[EMAIL PROTECTED]>
        27917 by: Ken Jones <[EMAIL PROTECTED]>
        27918 by: "Andrzej Kukula" <[EMAIL PROTECTED]>

qmail dies
        27919 by: Gustavo V G C Rios <[EMAIL PROTECTED]>

New spammer exploit (seen on Bugtraq)
        27920 by: Bruno Wolff III <[EMAIL PROTECTED]>

Eliding quotes in envelope? (Re: New spammer exploit ...)
        27921 by: Scott Schwartz <[EMAIL PROTECTED]>
        27922 by: Russell Nelson <[EMAIL PROTECTED]>
        27924 by: Scott Schwartz <[EMAIL PROTECTED]>

Root exploit in AMaViS
        27923 by: Keith Burdis <[EMAIL PROTECTED]>

Mass migration off of qmail because of lack of DSNs?
        27925 by: Arnt Gulbrandsen <[EMAIL PROTECTED]>
        27931 by: Vince Vielhaber <[EMAIL PROTECTED]>

relaying setup
        27926 by: "Denis Voitenko" <[EMAIL PROTECTED]>
        27927 by: Tony Wade <[EMAIL PROTECTED]>
        27928 by: Chris Johnson <[EMAIL PROTECTED]>

relaying almost fixed...
        27929 by: "Denis Voitenko" <[EMAIL PROTECTED]>
        27930 by: Anand Buddhdev <[EMAIL PROTECTED]>

Administrivia:

To subscribe to the digest, e-mail:
        [EMAIL PROTECTED]

To unsubscribe from the digest, e-mail:
        [EMAIL PROTECTED]

To bug my human owner, e-mail:
        [EMAIL PROTECTED]

To post to the list, e-mail:
        [EMAIL PROTECTED]


----------------------------------------------------------------------


You have a broken zone which does not resolve "soim.com" into an IP
quad. Your primary DNS, "dns2.city.online.sh.cn", appears to be offline
and your secondary, "name.soim.online.sh.cn", never heard of "soim.com".
You need to do some work using the nslookup tool to resolve your DNS
lookup problems. The error message you are getting is a bit ambiguous
and may have been the "best guess" that the name resolver came back with
as the probable cause of the failure. If you refer to the zone snippet
you sent along with your message, you will see no IN record for
"soim.com", thus your DNS gets nasty.

Tom






Hi,
  I just installed qmail-1.03 on a sco openserver 5 box. But
when I send letter to outsite, it always tell me that error.
:(
I dont't think it is because of DNS CNAME record problem, it
is no possible all sites's DNS are wrong.


Jul 18 04:50:37 bios qmail: 932273437.400000 status: local
0/10 remote 0/20
Jul 18 05:08:40 bios qmail: 932274520.080000 status: local
0/10 remote 0/20
Jul 18 05:08:40 bios qmail: 932274520.080000 starting delivery
1: msg 58413 to r
emote [EMAIL PROTECTED]
Jul 18 05:08:40 bios qmail: 932274520.080000 status: local
0/10 remote 1/20
Jul 18 05:08:40 bios qmail: 932274520.090000 delivery 1:
deferral: CNAME_lookup_
failed_temporarily._(#4.4.3)/
Jul 18 05:08:40 bios qmail: 932274520.340000 starting delivery
2: msg 58403 to r
emote [EMAIL PROTECTED]
Jul 18 05:08:40 bios qmail: 932274520.340000 status: local
0/10 remote 1/20
Jul 18 05:08:40 bios qmail: 932274520.350000 delivery 2:
deferral: CNAME_lookup_
failed_temporarily._(#4.4.3)/
Jul 18 05:25:24 bios qmail: 932275524.490000 starting delivery
4: msg 58411 to r
emote [EMAIL PROTECTED]>
Jul 18 05:25:24 bios qmail: 932275524.500000 status: local
0/10 remote 1/20
Jul 18 05:25:24 bios qmail: 932275524.500000 delivery 4:
deferral: CNAME_lookup_
failed_temporarily._(#4.4.3)/

and NSLOOK report:
# nslookup
Default Server:  ns.tpt.net.cn
Address:  202.99.96.68

> set type=mx
> soim.com
Server:  ns.tpt.net.cn
Address:  202.99.96.68

Non-authoritative answer:
soim.com        preference = 20, mail exchanger = www.soim.com
soim.com        preference = 10, mail exchanger =
smtp.soim.com

Authoritative answers can be found from:
soim.com        nameserver = NAME.SOIM.ONLINE.SH.CN
soim.com        nameserver = DNS1.CITY.ONLINE.SH.CN
soim.com        nameserver = ns.soim.com
www.soim.com    internet address = 202.96.210.242
smtp.soim.com   internet address = 202.96.237.179
NAME.SOIM.ONLINE.SH.CN  internet address = 202.96.210.242
DNS1.CITY.ONLINE.SH.CN  internet address = 202.96.237.179
ns.soim.com     internet address = 202.96.210.242

Following is part of soim.com 's zone file:

                        IN      NS      ns
                        IN      NS
dns1.city.online.sh.cn.
                        MX      10      smtp
                        MX      20      www
ns                      IN      A       202.96.210.242
dns                     IN      A       202.96.237.177
dns1                    IN      A       202.96.237.179
crack                   IN      A       202.96.237.177
ftp                     IN      A       202.96.247.228
ftp                     IN      A       202.96.210.242
vip                     IN      A       202.96.210.242
irc                     IN      A       202.96.210.242
news                    IN      A       202.96.237.179
shareware               IN      A       202.96.210.242
smtp                    IN      A       202.96.237.179
smtp1                   IN      A       202.96.237.179
www                     IN      A       202.96.210.242

there is NO any CNAME record


now how can I do?


Thanks very much



Hotdog
[EMAIL PROTECTED]








On Sun, 18 Jul 1999, Gustavo V G C Rios wrote:

> Sam wrote:
> > 
> > On Sun, 18 Jul 1999, Gustavo V G C Rios wrote:
> > 
> > > Dear gentleman,
> > >
> > >
> > > I have just seted my FreeBSD box as a mail server, i am using qmail!
> > > Suddenly, all my mail service stopped, i decide to look for error at
> > > log.
> > > Here is what i got:
> > >
> > > vitoria:/var/log/qmail# tail -f error.grios
> > > 932235638.932075 starting delivery 299: msg 276627 to remote
> > > [EMAIL PROTECTED]
> > > 932235638.932451 status: local 0/10 remote 1/20
> > > 932235740.856392 delivery 299: deferral:
> > 
> > > 
>Connected_to_204.216.27.18_but_my_name_was_rejected./Remote_host_said:_450_Cannot_find_your_hostname,_[200.18.130.93]/
> > 
> > > How could this happen ?
> > > Why did my qmail exit ?
> > 
> > The error message seems to be pretty clear to me.  The recipient is
> > rejecting your mail because your IP address does not have valid reverse
> > DNS.
> > 
> > I'm glad to see that more and more large mail domains are insisting that
> > anyone wanting to send them mail must have their act together.  See
> > http://www.rfc-editor.org/rfc/rfc1035.txt for more information.
> 
> 
> Ok! I know my ip does not have a valid reverse DNS, but is qmail
> supposed to exit because this error?
> 
> It sounds strange, my server dies 'cause i don't have a valid reverse
> DNS.
> Is that correct ? Is that the default qmail behavior ?

Who said anything about Qmail stopping?  The logs show the mail being
deferred, that's all.





Sam wrote/schrieb/scribsit:
> Who said anything about Qmail stopping?  The logs show the mail being
> deferred, that's all.

It was a bit unclear, but the last to lines of log in the original
mail were:
> > > > 932235888.816265 alert: oh no! lost spawn connection! dying...
> > > > 932235888.821153 status: exiting

But I just don't have a clue about this one and my archive is not
helpful, either.

If this is repeatable, one could try (s)trace-ing qmail-[rl]spawn and
maybe qmail-send.

Stefan





I've been able to get cyclog to work fine with qmail-start but I'm trying to
get it to work with tcpserver.  I'm presently using this line:

    /usr/qmail/bin/tcpserver -x/etc/tcp.smtp.cdb -u 65001 -g 65000 0 smtp \
     /usr/qmail/bin/qmail-smtpd 2>&1 | /usr/qmail/bin/accustamp | \
     /usr/qmail/bin/setuser root /usr/qmail/bin/cyclog -s10000000 -n5 \
     /usr/qmail/log/smtp &

and that correctly opens a log file but nothing ever seems to get logged.  What
am I doing wrong?

-- 
  Matthew Harrell                          The best way to accelerate a 
  Bit Twiddlers, Inc.                       Macintosh is at 9.8 meters per
  [EMAIL PROTECTED]                 second squared.




On Sun, Jul 18, 1999 at 02:15:59PM -0400, Matthew Harrell wrote:
> 
> I've been able to get cyclog to work fine with qmail-start but I'm trying to
> get it to work with tcpserver.  I'm presently using this line:
> 
>     /usr/qmail/bin/tcpserver -x/etc/tcp.smtp.cdb -u 65001 -g 65000 0 smtp \
>      /usr/qmail/bin/qmail-smtpd 2>&1 | /usr/qmail/bin/accustamp | \
>      /usr/qmail/bin/setuser root /usr/qmail/bin/cyclog -s10000000 -n5 \
>      /usr/qmail/log/smtp &
> 
> and that correctly opens a log file but nothing ever seems to get logged.  What
> am I doing wrong?

Add a -v to your tcpserver invocation.

Chris





Two things

1 - add -v option to tcpserver
2 - qmail-smtp doesn't log anything :) There are some patches on
www.qmail.org
    to log additional info



Matthew Harrell wrote:
> 
> I've been able to get cyclog to work fine with qmail-start but I'm trying to
> get it to work with tcpserver.  I'm presently using this line:
> 
>     /usr/qmail/bin/tcpserver -x/etc/tcp.smtp.cdb -u 65001 -g 65000 0 smtp \
>      /usr/qmail/bin/qmail-smtpd 2>&1 | /usr/qmail/bin/accustamp | \
>      /usr/qmail/bin/setuser root /usr/qmail/bin/cyclog -s10000000 -n5 \
>      /usr/qmail/log/smtp &
> 
> and that correctly opens a log file but nothing ever seems to get logged.  What
> am I doing wrong?
> 
> --
>   Matthew Harrell                          The best way to accelerate a
>   Bit Twiddlers, Inc.                       Macintosh is at 9.8 meters per
>   [EMAIL PROTECTED]                 second squared.




: >     /usr/qmail/bin/tcpserver -x/etc/tcp.smtp.cdb -u 65001 -g 65000 0 smtp \
: >      /usr/qmail/bin/qmail-smtpd 2>&1 | /usr/qmail/bin/accustamp | \
: >      /usr/qmail/bin/setuser root /usr/qmail/bin/cyclog -s10000000 -n5 \
: >      /usr/qmail/log/smtp &
: > 
: > and that correctly opens a log file but nothing ever seems to get logged.  What
: > am I doing wrong?
: 
: Add a -v to your tcpserver invocation.

Thanks.  That's got to be the fastest mailing list response I've ever seen.

-- 
  Matthew Harrell                          I love defenseless animals,
  Bit Twiddlers, Inc.                       especially in a good gravy.
  [EMAIL PROTECTED]




: Two things
: 
: 1 - add -v option to tcpserver
: 2 - qmail-smtp doesn't log anything :) There are some patches on
: www.qmail.org
:     to log additional info

Hmm, okay.  I'm basically just trying to get a normal log of what kind of stuff
is coming in on tcpserver and what's being bounced, etc.  I'll check for those
patches.

Thanks

-- 
  Matthew Harrell                          Every morning is the dawn of a
  Bit Twiddlers, Inc.                       new error.
  [EMAIL PROTECTED]




On Thu, 15 Jul 1999, Tony Wade wrote:

TW>Hi all , 
TW>
TW>Has anyone ever attempted to have a single config file for Qmail ie. 
TW>
TW>/var/qmail/control being shared by 2 servers. 
TW>
TW>and then the servers will be identical. Both running Redhat 6.0 with kernel
TW>2.2.10
TW>and both be a DELL PowerEdge 2300 with Duel PII 400 chips and 256M Ram. 
TW>and a 18G hdd. 
TW>
TW>with the /var/qmail dir set to +- 9G
TW>
TW>could i get them to share the configs and load balance ? 

rsync/rdist the config, and NFS mount the mailstore (assuming that you are
using maildir).

-- 
--Matt Schnierle
--mgs at stargate dot net
--Stargate Industries, LLC
--#include <std/disclaimer.h>
--"It's not that simple."





I would like to use whoson protocol (http://www.average.org/ftp/whoson/)
to allow selective relaying for my site.

Is there any solution for qmail?

Regards,
Andrzej.




Andrzej Kukula wrote:
> 
> I would like to use whoson protocol (http://www.average.org/ftp/whoson/)
> to allow selective relaying for my site.
> 
> Is there any solution for qmail?
> 
> Regards,
> Andrzej.

Is there a web page for this protocol?

I just see the source.

-- 
Ken Jones
http://www.inter7.com/qmailadmin - web based qmail adminstration




> Andrzej Kukula wrote:
> > 
> > I would like to use whoson protocol (http://www.average.org/ftp/whoson/)
> > to allow selective relaying for my site.
> > 
> > Is there any solution for qmail?
> 
> Is there a web page for this protocol?
> 
> I just see the source.

No, there isn't. The proposed protocol is described in whoson.txt in the
tarball.

Andrzej.




What this error mesg means ?

932327990.841554 alert: oh no! lost spawn connection! dying...
932327990.846882 status: exiting


My qmail is dying frequently!
How can i fix it?


-- 
What about something different this year:
Crash your FreeBSD box!




On Sat, Jul 17, 1999 at 09:35:59AM -0500,
  David Dyer-Bennet <[EMAIL PROTECTED]> wrote:
> I just saw mention on bugtraq of spammers trying to exploit
> 
>     RCPT TO: <"[EMAIL PROTECTED]"@relay.host.name>
> 
> What happened was that the mail was *accepted*, and then bounced
> (qmail seems to have ignored the quotes in the address).  This is

The quotes are used to hide special characters in the local part of
the email address. Qmail doesn't treat the local part of the address
specially. The relay problem occurs, because sendmail will interpret
local parts that have some special characters in them (e.g. @, ! and %)
is internet (or uucp) addresses and may forward the mail on to that address.




I tried sending a few test messages, to ``"my self"@localhost''.
In the case when that address is supplied on the qmail-inject command
line, the same string appears in the envelope (and, since I used an
invalid target, in the bounce message.)  In the case when qmail-inject,
new-inject, smtpd, ofmipd are used, the envelope omits the quotes.
This inconsistency seems wrong to me.




Scott Schwartz writes:
 > I tried sending a few test messages, to ``"my self"@localhost''.
 > In the case when that address is supplied on the qmail-inject command
 > line, the same string appears in the envelope (and, since I used an
 > invalid target, in the bounce message.)  In the case when qmail-inject,
 > new-inject, smtpd, ofmipd are used, the envelope omits the quotes.
 > This inconsistency seems wrong to me.

Command-line arguments are RFC821 addresses, but body addresses are
RFC822 addresses.

-- 
-russ nelson <[EMAIL PROTECTED]>  http://crynwr.com/~nelson
Crynwr supports Open Source(tm) Software| PGPok | Government schools are so
521 Pleasant Valley Rd. | +1 315 268 1925 voice | bad that any rank amateur
Potsdam, NY 13676-3213  | +1 315 268 9201 FAX   | can outdo them. Homeschool!




Russell Nelson <[EMAIL PROTECTED]> writes:
| Command-line arguments are RFC821 addresses, but body addresses are
| RFC822 addresses.

I'm only talking about the envelope (rfc821 addresses).  It's
inconsistent that qmail-smtpd strips the quotes from the envelope while
qmail-inject doesn't.





Hi there

  With the recent thread on using virus scanners I thought some of you should
  be aware of a root exploit in AMaViS. See:

    http://linuxtoday.com/stories/7789.html

  -- Keith
-- 
Keith Burdis - MSc (Com Sci) - Rhodes University, South Africa  
Email   : [EMAIL PROTECTED]
WWW     : http://www.rucus.ru.ac.za/~keith/
IRC     : Panthras                                          JAPH

"Any technology sufficiently advanced is indistinguishable from a perl script"

Standard disclaimer.
---




Vince Vielhaber <[EMAIL PROTECTED]>
> On 18-May-99 Arnt Gulbrandsen wrote:
> > [EMAIL PROTECTED]
> >> Actually, qmail's VERP should allow you to be 100% successful; and
> >> DSNs won't, since they're not widely supported.  
> > 
> > Huh?  What's your threshold for "widely supported"?  Doesn't sendmail
> > have something like 80% market share and nice DSN support?
> 
> But how much of that 80% is really old sendmail?  Having 80% marketshare
> and 80% marketshare of a current product are two very different things.

I'm not going to go out and measure - it doesn't matter that much to
me.  I asked because I seem to remember sendmail getting DSN support
something like four years ago and most current sites simply didn't
exist four year ago.  Have new sites been installing sendmail 5.65 or
something like that?

--Arnt (back from vacation)





This thread died two months ago.

Vince.


On 19 Jul 1999, Arnt Gulbrandsen wrote:

> Vince Vielhaber <[EMAIL PROTECTED]>
> > On 18-May-99 Arnt Gulbrandsen wrote:
> > > [EMAIL PROTECTED]
> > >> Actually, qmail's VERP should allow you to be 100% successful; and
> > >> DSNs won't, since they're not widely supported.  
> > > 
> > > Huh?  What's your threshold for "widely supported"?  Doesn't sendmail
> > > have something like 80% market share and nice DSN support?
> > 
> > But how much of that 80% is really old sendmail?  Having 80% marketshare
> > and 80% marketshare of a current product are two very different things.
> 
> I'm not going to go out and measure - it doesn't matter that much to
> me.  I asked because I seem to remember sendmail getting DSN support
> something like four years ago and most current sites simply didn't
> exist four year ago.  Have new sites been installing sendmail 5.65 or
> something like that?
> 
> --Arnt (back from vacation)
> 

-- 
==========================================================================
Vince Vielhaber -- KA8CSH   email: [EMAIL PROTECTED]   flame-mail: /dev/null
       # include <std/disclaimers.h>                   TEAM-OS2
        Online Campground Directory    http://www.camping-usa.com
       Online Giftshop Superstore    http://www.cloudninegifts.com
==========================================================================







I am in a process of setting up my linux box to relay mail for clients on a
192.168.0.X LAN. I am trying to follow the directions from
http://www.palomine.net/qmail/selectiverelay.html and here is something that
gives me trouble.

linux:/etc# tcpserver -x/etc/tcp.smtp.cdb -u1003 -g103 0 smtp
/var/qmail/bin/qma
il-smtpd &
[2] 1405
tcpserver: fatal: unable to bind: address already used

What would that mean exactly?

Also, do I have to add the line
tcpserver -x/etc/tcp.smtp.cdb -u102 -g101 0 smtp /var/qmail/bin/qmail-smtpd
&
to my start up scripts or it is one-time procedure?

Denis Voitenko
O3M Cretative Director
[EMAIL PROTECTED]
215 386-3923






Looks like you have the SMTP port already running in /etc/inetd

Tony Wade

-----Original Message-----
From: Denis Voitenko [mailto:[EMAIL PROTECTED]]
Sent: 19 July 1999 09:46
To: [EMAIL PROTECTED]
Subject: relaying setup


I am in a process of setting up my linux box to relay mail for clients on a
192.168.0.X LAN. I am trying to follow the directions from
http://www.palomine.net/qmail/selectiverelay.html and here is something that
gives me trouble.

linux:/etc# tcpserver -x/etc/tcp.smtp.cdb -u1003 -g103 0 smtp
/var/qmail/bin/qma
il-smtpd &
[2] 1405
tcpserver: fatal: unable to bind: address already used

What would that mean exactly?

Also, do I have to add the line
tcpserver -x/etc/tcp.smtp.cdb -u102 -g101 0 smtp /var/qmail/bin/qmail-smtpd
&
to my start up scripts or it is one-time procedure?

Denis Voitenko
O3M Cretative Director
[EMAIL PROTECTED]
215 386-3923





On Mon, Jul 19, 1999 at 03:46:10AM -0400, Denis Voitenko wrote:
> I am in a process of setting up my linux box to relay mail for clients on a
> 192.168.0.X LAN. I am trying to follow the directions from
> http://www.palomine.net/qmail/selectiverelay.html and here is something that
> gives me trouble.
> 
> linux:/etc# tcpserver -x/etc/tcp.smtp.cdb -u1003 -g103 0 smtp
> /var/qmail/bin/qma
> il-smtpd &
> [2] 1405
> tcpserver: fatal: unable to bind: address already used
> 
> What would that mean exactly?

It means that you already have something listening on the SMTP port. You
probably have sendmail running or you have something in /etc/inetd.conf set to
listen on the SMTP port. You'll have to find out what it is and disable it.

> Also, do I have to add the line
> tcpserver -x/etc/tcp.smtp.cdb -u102 -g101 0 smtp /var/qmail/bin/qmail-smtpd
> &
> to my start up scripts or it is one-time procedure?

You need to add it to a startup script.

Chris




This might sound silly, but the line:
tcpserver -x/etc/tcp.smtp.cdb -u1003 -g102 0  smtp /var/qmail/bin/qmail
smtpd &
takes action only if I run it after the system is booted and I logged in as
root. The entry in /etc/rc.d/rc.local does not take effect for some reason.
Has anyone encountered this problem before? How do I solve it?

Denis Voitenko
O3M Cretative Director
[EMAIL PROTECTED]
215 386-3923





On Mon, Jul 19, 1999 at 05:25:54AM -0400, Denis Voitenko wrote:

tcpserver is normally installed in /usr/local/bin. However, this
directory is not usually found the system startup scripts' PATH. Try
using the full pathname in /etc/rc.d/rc.local, like this:

/usr/local/bin/tcpserver -x .........

> This might sound silly, but the line:
> tcpserver -x/etc/tcp.smtp.cdb -u1003 -g102 0  smtp /var/qmail/bin/qmail
> smtpd &
> takes action only if I run it after the system is booted and I logged in as
> root. The entry in /etc/rc.d/rc.local does not take effect for some reason.
> Has anyone encountered this problem before? How do I solve it?

-- 
See complete headers for more info


Reply via email to