Received: from localhost (unknown [200.46.204.183]) by mail.postgresql.org (Postfix) with ESMTP id 4901A634086 for ; Thu, 5 Mar 2009 00:20:32 -0400 (AST) Received: from mail.postgresql.org ([200.46.204.86]) by localhost (mx1.hub.org [200.46.204.183]) (amavisd-maia, port 10024) with ESMTP id 67489-01 for ; Thu, 5 Mar 2009 00:20:29 -0400 (AST) Received: from hub.org (hub.org [200.46.204.220]) by mail.postgresql.org (Postfix) with ESMTP id C7455633CA1 for ; Thu, 5 Mar 2009 00:20:29 -0400 (AST) Received: from localhost (unknown [200.46.204.183]) by hub.org (Postfix) with ESMTP id A520853BC96 for ; Thu, 5 Mar 2009 00:20:29 -0400 (AST) Received: from hub.org ([200.46.204.220]) by localhost (mx1.hub.org [200.46.204.183]) (amavisd-maia, port 10024) with ESMTP id 64591-04; Thu, 5 Mar 2009 00:20:23 -0400 (AST) Received: by hub.org (Postfix, from userid 1002) id 84A8E53BC8C; Thu, 5 Mar 2009 00:20:23 -0400 (AST) Received: from localhost (localhost [127.0.0.1]) by hub.org (Postfix) with ESMTP id 8331953BC8B; Thu, 5 Mar 2009 00:20:23 -0400 (AST) Date: Thu, 5 Mar 2009 00:20:23 -0400 (AST) From: "Marc G. Fournier" To: Alvaro Herrera cc: "Marc G. Fournier" , w^3 , pg-sysadmins@alvh.no-ip.org Subject: Re: news gateway malfunctioning? In-Reply-To: <20090304194501.GD12854@alvh.no-ip.org> Message-ID: <20090305001422.O1736@hub.org> References: <20090304194501.GD12854@alvh.no-ip.org> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII; format=flowed X-Virus-Scanned: Maia Mailguard 1.0.1 X-Virus-Scanned: Maia Mailguard 1.0.1 X-Archive-Number: 200903/15 X-Sequence-Number: 16669 On Wed, 4 Mar 2009, Alvaro Herrera wrote: > Hi Marc, > > Lately I have gotten a number of moderation request for -hackers and > other lists that look like the attached message. From the header it > looks to me like they are coming from the USENET gateway; I wonder > what's up with the "RCPT TO" stuff at the top of the body of the > message. Is the gateway getting confused by the mangling done by the > spam checker? I'm a bit lost here, so bare with me ... First question, I guess, is whether there are othe rmessages showing up that RCPT TO stuff, or is it just these types of 'spam' messages ... ? The oddness here is that it almost looks like someone manually connected to the smtp port and tried to inject the message manually ... and ended up injecting the 'formatted message' that has all the SMTP cmds embeded ... The second question is ... mangling done by what spam checker? Our spam checker does nothing except add some X-Spam / X-Virus related headers ... the body isn't touched ... ---- Marc G. Fournier Hub.Org Networking Services (http://www.hub.org) Email . scrappy@hub.org MSN . scrappy@hub.org Yahoo . yscrappy Skype: hub.org ICQ . 7615664