Hi,

sending the string "X-MailScanner: Found to be clean" in the mail-header to any
of our Qmail-Scanner mailservers, results in a 20 minute hangup of the
corresponding qmail-scanner process and a timeout for the remote side.
The problem seems to exist with the current 1.25 and any older qmail-scanner
version.

Below I attached the output of debugging logs:
I noticed the 20min time gap the qmail-scanner process seems to hang.

Hopefully we can fix this soon, as this bug makes it easy to flood the machines
with DOS attacks...

Best regards,
Florian Fuessl


+++ telnet to qmail-scanner mailserver +++
$ telnet mail.mydemail.de 25
Trying 80.73.96.3...
Connected to pineapple.mydemail.de.
Escape character is '^]'.
220 pineapple.mydemail.de ESMTP
HELO Flo
250 pineapple.mydemail.de
MAIL FROM: [EMAIL PROTECTED]
250 ok
RCPT TO: [EMAIL PROTECTED]
250 ok
DATA
354 go ahead
X-MailScanner: Found to be clean

.
[ timeout of client ]
+++ /// +++

+++ LOGFILE: /var/spool/qmailscan/qmail-queue.log +++
pineapple:/var/spool/qmailscan# grep 7636 qmail-queue.log
Fri, 08 Apr 2005 14:47:29 CEST:7462: all finished. Total of 1.376367 secs
Fri, 08 Apr 2005 14:53:36 CEST:7636: +++ starting debugging for process 7636 by
uid=64011
Fri, 08 Apr 2005 14:53:36 CEST:7636: setting UID to EUID so subprocesses can
access files generated by this script
Fri, 08 Apr 2005 14:53:36 CEST:7636: program name is qmail-scanner-queue.pl,
version 1.22
Fri, 08 Apr 2005 14:53:36 CEST:7636: incoming SMTP connection from via SMTP from
84.146.41.243
Fri, 08 Apr 2005 14:53:36 CEST:7636: w_c: mkdir
/var/spool/qmailscan/tmp/pineapple11129648164787636
Fri, 08 Apr 2005 14:53:36 CEST:7636: w_c: start dumping incoming msg into
/var/spool/qmailscan/working/tmp/pineapple11129648164787636 [1112964816.86263]
Fri, 08 Apr 2005 15:13:38 CEST:7636: w_c: rename new msg from
/var/spool/qmailscan/working/tmp/pineapple11129648164787636 to
/var/spool/qmailscan/working/new/pineapple11129648164787636 [1112966018.88877]
Fri, 08 Apr 2005 15:13:38 CEST:7636: d_m: starting /usr/local/bin/reformime 
-x/var/spool/qmailscan/tmp/pineapple11129648164787636/
</var/spool/qmailscan/working/new/pineapple11129648164787636
[1112966018.88923]
Fri, 08 Apr 2005 15:13:38 CEST:7636: d_m: finished /usr/local/bin/reformime 
-x/var/spool/qmailscan/tmp/pineapple11129648164787636/ [1112966018.90298]
Fri, 08 Apr 2005 15:13:38 CEST:7636: d_m: Checking all attachments to see if
they're MS-TNEF
Fri, 08 Apr 2005 15:13:38 CEST:7636: d_m: is
/var/spool/qmailscan/tmp/pineapple11129648164787636/1112966018.8059-0.pineapple
is a TNEF file?: 256 [1112966018.90503]
Fri, 08 Apr 2005 15:13:38 CEST:7636: d_m: Check for zip files...
Fri, 08 Apr 2005 15:13:38 CEST:7636: d_m: unpacking message took 0.016165
seconds
Fri, 08 Apr 2005 15:13:38 CEST:7636: unsetting QMAILQUEUE env var
Fri, 08 Apr 2005 15:13:38 CEST:7636: g_e_h: no sender and no recips.
Fri, 08 Apr 2005 15:13:38 CEST:7636: cleanup: /bin/rm -rf
/var/spool/qmailscan/tmp/pineapple11129648164787636/
/var/spool/qmailscan/working/new/pineapple11129648164787636




-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now.
http://ads.osdn.com/?ad_id=6595&alloc_id=14396&op=click
_______________________________________________
Qmail-scanner-general mailing list
Qmail-scanner-general@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general

Reply via email to