[Raw Msg Headers][Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: rbl problems and questions



On Sat, Jun 15, 2002 at 05:06:55PM -0600, Daryle A. Tilroe wrote:
> Hello?  Anyone on the list this weekend :-).  Anyhow, after looking at my
> logs, it appears that the spamcop block is working fine:

  Besides of midnight oil (being up at 4 am..) I am burning a bit
  of CPU cycles at my home system to process few massive datasets.
  While waiting those to come through, I have a moment to look at this..

> -------------------------------------------------------
> NVQW27874#      connection from [202.101.191.226] ipcnt 1 childs 2 ident: NO-IDENT-SERVICE[2]
> NVQW27874#      Looking up DNS A object: 226.191.101.202.rbl-plus.mail-abuse.org
> NVQW27874#      Looked up DNS A object: 226.191.101.202.bl.spamcop.net -> 127.0.0.2
> NVQW27874w      550-Blocked - see http://spamcop.net/bl.shtml?202.101.191.226
> NVQW27874w      550-If you feel we mistreat you, do contact us.
> NVQW27874w      550 Ask HELP for our contact information.
> NVQW27874#      remote from [202.101.191.226]:57055
> NVQW27874#      -- policyresult=-1 initial policy msg: Blocked - see http://spamcop.net/bl.shtml?202.101.191.226
> -------------------------------------------------------
> 
> The spamcop lookup resolves to 127.0.0.2 (rather than the MAPS 127.1.0.1,
> 127.1.0.2, or 127.1.0.4).  Now I would have thought that any positive lookup
> should result in a block but it appears that zmailer may be looking for
> 127.0.0.2 only/exactly.  I have had a quick peek in the source code
> (policytest.c, mxverify.c, and smtpserver.c) but cannot immediately see
> where this may be hardcoded or set dynamically.  Maaaattiiiiii!  Help
> meeeeeeee! :-)

  The address data verification (at the last routine of  mxverify.c)
  does look (in text form!) that the data is of  "127.0.0."  and
  that it isn't  "127.0.0.4"

  What is that   127.1.0.*  thing ?

  I thought that MAPS RBL was the first who specified that the lookup
  produces valid rejection entry ONLY when it is 127.0.0.2
  It was possibly ORBS, that added ...3 and ...4, very least, into this
  repertoire of data variants.


> -- 
> Daryle A. Tilroe

-- 
/Matti Aarnio	<mea@nic.funet.fi>
-
To unsubscribe from this list: send the line "unsubscribe zmailer" in
the body of a message to majordomo@nic.funet.fi