Re: Deadly embrace.

"Julian H. Stacey" <[email protected]> Thu, 27 Jan 2011 14:04:31 +0100
Newsgroups gmane.mail.majordomo.general,gmane.spam.detected
Organization http://www.berklix.com BSD Unix Linux Consultancy, Munich Germany
Message-ID <[email protected]>
Hi Majordomo users,
I wrote last night:

> My majordomo server (which has been working fine for years) was
> in a deadly embrace with a mailer-daemon on the net.  Several
> times a minute they errored to each other, here's a sample.
> 
> It was presumably caused by a spammer masquerading as the remote
> server domain.
> 
> [email protected] did not answer this morning (& gone
> midnight on a weekday in my TZ when I temprorarily stopped this occurence.
> 
> A test mail to [email protected] just gave Russian,
> no idea what it means.
> 
> Here's what's sent to me as majordomo-owner:
>   ----------------------
>   From MAILER-DAEMON Wed Jan 26 23:45:20 2011
>   Received: from park.js.berklix.net (park.js.berklix.net [192.168.91.31])
>   	by fire.js.berklix.net (8.14.3/8.14.3) with ESMTP id p0QMjKO4001025
>   	for <[email protected]>; Wed, 26 Jan 2011 23:45:20 +0100 (CET)
>   Received: from park.js.berklix.net (localhost.js.berklix.net [127.0.0.1])
>   	by park.js.berklix.net (8.13.8/8.13.8) with ESMTP id p0QMj4Fd005355
>   	for <jhs@localhost>; Wed, 26 Jan 2011 23:45:20 +0100 (CET)
>   Received: from tower.berklix.org [83.236.223.114]
>   	by park.js.berklix.net with POP3 (fetchmail-6.3.4)
>   	for <jhs@localhost> (single-drop); Wed, 26 Jan 2011 23:45:20 +0100 (CET)
>   Received: from te.net.ua (Te.NeT.UA [195.138.80.34])
>   	by tower.berklix.org (8.14.2/8.14.2) with ESMTP id p0QMikWE039708
>   	for <[email protected]>; Wed, 26 Jan 2011 22:44:47 GMT
>   Subject: Undeliverable mail: Majordomo results: Re: Majordomo results: Re: Majordomo res
>   From: <[email protected]>
>   To: <[email protected]>
>   Date: Thu, 27 Jan 2011 00:44:46 +0200
>   Message-ID: <[email protected]>
>   X-MAPI-Message-Class: REPORT.IPM.Note.NDR
>   MIME-Version: 1.0
>   Content-Type: multipart/report; report-type="delivery-status"; boundary="_===234350153====te.net.ua===_"
>   
>   
>   --_===234350153====te.net.ua===_
>   Content-Type: text/plain; charset="utf-8"
>   
>   Failed to deliver to '<[email protected]>'
>   LOCAL module(account skrudge) reports:
>    account is full (quota exceeded)
>   
>   
>   --_===234350153====te.net.ua===_
>   Content-Type: message/delivery-status
>   
>   Reporting-MTA: dns; te.net.ua
>   
>   Original-Recipient: rfc822;<[email protected]>
>   Final-Recipient: LOCAL;<skrudge>
>   Action: failed
>   Status: 5.0.0
>   
>   --_===234350153====te.net.ua===_
>   Content-Type: text/rfc822-headers
>   
>   Received: from tower.berklix.org ([83.236.223.114] verified)
>     by te.net.ua (CommuniGate Pro SMTP 5.1.16)
>     with ESMTPS id 234350199 for [email protected]; Thu, 27 Jan 2011 00:44:43 +0200
>   Received-SPF: none
>    receiver=te.net.ua; client-ip=83.236.223.114; [email protected]
>   Received: from tower.berklix.org (localhost [127.0.0.1])
>   	by tower.berklix.org (8.14.2/8.14.2) with ESMTP id p0QMiZai039704
>   	for <[email protected]>; Wed, 26 Jan 2011 22:44:35 GMT
>   	(envelope-from [email protected])
>   Received: (from majordom@localhost)
>   	by tower.berklix.org (8.14.2/8.14.2/Submit) id p0QMiZdD039703;
>   	Wed, 26 Jan 2011 22:44:35 GMT
>   	(envelope-from [email protected])
>   Date: Wed, 26 Jan 2011 22:44:35 GMT
>   Message-Id: <[email protected]>
>   X-Authentication-Warning: tower.berklix.org: majordom set sender to [email protected] using -f
>   To: [email protected]
>   From: [email protected]
>   Subject: Majordomo results: Re: Majordomo results: Re: Majordomo res
>   Reply-To: [email protected]
>   
>   --_===234350153====te.net.ua===_--
>   
>   ----------------------
> 
> Though the above only shows their mailer-daemon talking to my
> Majordomo-owner@ I can see from my sendmail /var/log/maillog that 
> they are actually also sending to my majordomo@, hence the loop:
> 
>   <-- MAIL FROM:<[email protected]> SIZE=448
>   --- 250 2.1.0 <[email protected]>... Sender ok
>   <-- RCPT TO:<[email protected]> NOTIFY=NEVER
>   --- 250 2.1.5 <[email protected]>... Recipient ok
>   ....
>   p0QNSOcF042427: clone: owner=majordomo-owner
> 
> I had in majordomo.cf (for maybe last year or so):
> 
>   $majordomo_dont_reply = '(_dhcp|_pflogd|abuse|admin|apache|avahi|bind|bin|copyright|cups|cyrus|daemon|dhcpd|dumper|exmh-bug-master|faxmanager|faxmaster|fetchmail|ftp-admin|ftp-bugs|ftpmaster|ftp|games|haldaemon|hostmaster|kmem|listproc|listserv|mailer-daemon|mailman|mailnull|majordomo-h|majordomo-owner|majordomo1|majordomo2|majordomo3|majordomo|majordom|man|messagebus|msgs|nagios|newsmaster|news|nobody|null-notify|operator|owner-majordomo|polkit|pop|postmaster|proxy|release|root|saned|smmsp|squid|sshd|subscribe|system|toor|tty|usenet|uucp|webmaster|www-test|www|xten)\@';
> 
> OK, maybe that was too much for some limit so I reduced to:
> 
>   $majordomo_dont_reply = '(abuse|daemon|listproc|listserv|mailer-daemon|mailman|majordomo-h|majordomo-owner|majordomo1|majordomo2|majordomo3|maj
> ordomo|majordom|owner-majordomo|postmaster|root|smmsp|system|uucp)\@';
> 
> (the 1 2 3 are some multi server (semi) resilience hooks I've had in there
>  for years, done no harm till now, if even now )
> 
> Even editing majordomo.cf down to default
>   $majordomo_dont_reply = '(mailer-daemon|uucp|listserv|majordomo|listproc)\@';
> does not stop my majordomo Log keep addding lines:
> 
> Jan 27 00:47:23 berklix.org majordomo[47199] {<[email protected]>} help
> Jan 27 00:47:38 berklix.org majordomo[47216] {<[email protected]>} help
> 
> ( It presumably sends help because no recognised commands,
> I dont see the word help in what I receive.

> Putting
>   /failed\s*to\s*deliver\s*to/i
> into
>   global_taboo_body 
> doesnt stop it.
> 
> As an emergency fix I just did:
>   cd /var/spool/mqueue ; rm -f `grep -l [email protected]`
> 
> But that of course does not make our majordomos safe from a repeat
> thats bound to occur sometime.
> 
> Any ideas ?

--------------------------

The loop storm started again overnight, another 2000 mails, so 
	cd /etc/mail; echo "te.net.ua REJECT" >> access; make access.db

& I invited postmaster to mail me from another domain or phone me,
(but no reply & cyrillic alphabet, so little chance with that), & got back:
	(reason: 550 5.2.1 <[email protected]>... Mailbox disabled
	for this recipient)
No one there, so.
	http://www.te.net.ua	-->
	http://www.tenet.ua
	After clicking "Translate" (within browser), 
	it's a telecoms company portal for end users.

telnet te.net.ua 25
	220 te.net.ua ESMTP CommuniGate Pro 5.1.16
	quit

telnet tower.berklix.org 25		# my majordomo host
	220 tower.berklix.org ESMTP Sendmail 8.14.2/8.14.2; 

my source majordomo-1.94.5.tgz.

my system: uname -a
FreeBSD tower.berklix.org 6.3-RELEASE FreeBSD 6.3-RELEASE #0: Fri Feb 15 20:16:36 CET 2008     [email protected]:/usr/src/sys/i386/compile/TOWER.small  i386

Our (yours & my) majordomos remain susceptible until we track this
down.  If any spammer masquerades his send address as a system that
has the same characteristics as @te.net.ua & happens to spam your
majordomo@, you too will likely suffer a mail storm.

Rather than hope it doesnt happen, (& by Murphys lawm find it does
when least convenient),  better we track it down while we're
at desks to analyse & figure how to stop it.

One way to trigger the problem to diagnose it:
	Send your majordomo a request to subscribe <[email protected]>
	( or perhaps more sociably, <[email protected]> )
	to your test@ list, & watch your majordomo send  @te.net.ua
	to confirm request, & the loop will start (I got 2 or 3 a minute).

Suggestions welcome.

Cheers,
Julian
-- 
Julian Stacey, BSD Unix Linux C Sys Eng Consultants Munich http://berklix.com
 Mail plain text;  Not quoted-printable, Not HTML, Not base 64.
 Reply below text sections not at top, to avoid breaking cumulative context.