SMTP: MAIL FROM: [email protected] / * / blocks / expires

First of all, I'm not a customer of Cisco, but a user of a network by a facility of PIX firewall. My username does not mean that I am affiliated with Cisco; It's just a way for me to remember it.

I can't give you more details than the fact that there is a PIX protecting the network. I don't have its version number, unfortunately.

In any case, here's the deal: I think that there is a bug in the way PIX handles SMTP sessions. Specifically, it seems to block/time out when I Specifies an address (MAIL FROM or RCPT TO) that contains a pipe character, ' | '.

Some tests:

(1) mail via localhost: no problem

(2) mail via the internal host: no problem (no not a firewall)

(3) mail via the external host: has a problem, but not systematically

The interesting part is that the bug does not always occur. When I RCPT TO: [email protected]/ * / directly, everything stops and the connection times out. However, if I first RCPT TO: [email protected] / * / and subsequently, * in the same SMTP session *, RCPT TO: [email protected]/ * / he * is * working. Rather peculiar.

Relevant sessions (with netcat):

> [email protected] / * /: ~ $ nc firewalled.example.org smtp

> 220 firewalled.example.org ESMTP Sendmail 8.12.10/8.11.4; Friday 20 August 2004 11:50:30 + 0200

> HELO example.org

> 250 firewalled.example.org Hello [213.196.33.33], the pleasure to meet you

> MAIL FROM: [email protected] / * /

> 250 2.1.0 [email protected] / * /... Sender OK

> RCPT TO: [email protected]/ * /.

My orders starts with a ">", responses from the server with ' > '. As you can see, nothing happens after the RCPT TO command with a ' | '.

> [email protected] / * /: ~ $ nc firewalled.example.org smtp

> 220 firewalled.example.org ESMTP Sendmail 8.12.10/8.11.4; Friday 20 August 2004 11:51:13 + 0200

> HELO example.org

> 250 firewalled.example.org Hello [213.196.33.33], the pleasure to meet you

> MAIL FROM: [email protected] / * /

> 250 2.1.0 [email protected] / * /... Sender OK

> RCPT TO: [email protected] / * /

> 250 2.1.5 [email protected] / * /... Recipient OK

> DATA

> 354 enter mail, end with "." on a line by itself

> Subject: test 2 [email protected] / * /

> .

> 2.0.0 250 i7K9pD9i022438 Message accepted for delivery

> MAIL FROM: [email protected] / * /

> 250 2.1.0 [email protected] / * /... Sender OK

> RCPT TO: [email protected]/ * /.

> 250 2.1.5 [email protected]/ * /... Recipient OK

> DATA

> 354 enter mail, end with "." on a line by itself

> Subject: [email protected]test *.

> .

> 2.0.0 250 i7K9pD9j022438 Message accepted for delivery

> QUIT

> 221 2.0.0 firewalled.example.org closing connection

The first RCPT is to [email protected] / * / and works very well. Then, after the opinion of "message accepted", I begin a new mail and RCPT TO [email protected]/ * / * fact * work.

Is this a bug in the software PIX itself? Network administrators say they have no special rules put in place and suggest that I just have to use an address without a ' | '. The problem is that requires change of address confirmation e-mails, but they never get through. In addition, the syntax of the address is valid.

Anyone can shed light on this issue? You can reproduce it on your installation?

Nice analysis... maybe you should work with the PIX a little more.

In this case, however, no bug in the PIX (except that we through sometimes by your remark above). This behavior is specified. Of http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/config/fixup.htm#wp1103507

"The MAIL and RCPT commands specify who is the sender and the recipient of the mail. The e-mail addresses are analysed for strange characters. The pipeline character (|) is removed (replaced by a white space) and "<" ‚"="">" are allowed if they are used to define an e-mail address ("' >" "must be preceded of '")<>

There was some talk to the command pipelinig user definable, but at this time, no final word.

Sorry for the trouble.

Scott

Tags: Cisco Security

Similar Questions

  • Calls from [email protected] / * / ip addresses

    Hello world

    I get calls from [email protected] / * / IPS on my Highway VCS trying to dial different numbers. I activated a policy rule of local call to reject asterisk@.* to any destination. * but it does not work and I still get the call attempts.

    Someone has encountered this and knows how to stop these calls?

    Thank you

    Maciek

    Maciej,

    try to replace 'origin' with 'non-authenticated-origin' in your CPL, so that it reads as follows:

    CPL 'origin' field has a value of "is not far" If the message that the CPL is run for is not authenticated.

    You can find more information about the field of the 'non-authenticated-origin"in the VCS administration guide.

    Hope this helps,

    Andreas

  • Issue of Windows Live Mail with SPAM and junk e-mail. When I block a sender, I always get an email from them.

    The details are pretty easy. No matter how many times I click to block a source of junk mail I still get mail from the source. In short, the function block-spam does not work. I get the answer that the site has been blocked, but it is not. That's all. How can I get Windows Live Mail to block sources when I click

    the option of block source?

    original title: can not block spam

    Ridicule me. I had installed Windows Live Mail from a "last" Filehippo file. Problem ensued. I uninstalled [with Revo Uninstaller] and reinstalled through "Getting Started" in the start menu. No problem, everything is fine now. I learned my lesson the hard way though.

    I was surprised how much my humble question generated activity. If my mishap and the solution in any case everyone outside, good help for them.
    It's a kind of collateral damage of a reinstallation of the operating system. Installation, I replaced had lasted about a year, a record for me and would probably be still in place, if I had not made the mistake of dabbling with Acronis backup software I used on another computer with XP installed. There, it served a purpose, in Windows 7, it is a serious mistake. It replaces the built-in backup utility, and when inevitably corrupts it... both pis, Charlie.
    Thank you Pa supporter and all those who responded.
    Dave Binko
  • Mail from Apple sending emails of my two accounts

    That's what my title says. Whenever I have email from my yahoo account, it also sends it to my outlook. I had to disable my vision of the app that I could at least send emails correctly. Two emails are the same if this is important btw (eg. ( [email protected] and [email protected]). Is it possible to fix this? I don't really like having to open my outlook on my browser every time. The app is much cleaner and simpler.

    Try mail/preferences/AccountType account information. Select an account, and then access the server of outgoing (SMTP) mail. In the menu drop-down select list server SMPT Edit. Then set up a server for each e-mail account that is associated with the e-mail address. Then go to each account and set this server as the Mail Server outgoing (SMTP). You can click on use only this server if you wish.

    Mail/preferences/writing/sending messages - set to the selected mailbox account.

  • Mail from Apple using incorrect email (typo)

    Hello

    Apple Mail uses invalid (typo) email address Hotmail to send the same mail so correct was provided and is present in the settings.  The user's e-mail address is * [email protected], but when sending mail it tries to connect with the imap server using the * [email protected] (obvious typo).  I checked that the e-mail address is correct in the e-mail settings and address book.  I tried to delete the account and restart the phone and then add the account but this does not solve the problem.

    Mail from this account can not be sent, but is received correctly.  Other mail on telephone accounts, send and receive a fine.  Phone is 6s with installed 9.3.4

    Any advice?

    drusomeIT wrote:

    Mail from this account can not be sent, but is received correctly.

    That has to do with the outgoing SMTP settings. If you can not change this setting, remove and add the account as "Other" type. You will need the following information:

    Incoming mail server

    • Account type: IMAP
    • Username: [email protected]
    • Host name of the server: imap - mail.outlook.com
    • Server port: 993
    • Authentication: password
    • SSL/TLS: Yes

    Outgoing e-mail server

    • User name: _______[email protected]
    • Host name of the server: smtp - mail.outlook.com
    • Server port: 587
    • Authentication: password
    • SSL/TLS: Yes
  • How can I block e-mail from specific senders?

    I'm tired of searching on a large number of emails in my spam folder. A large part of the enamel comes from the sender even. How can I block e-mail from specific senders?

    Junk e-mail is automatically deleted after 30 days > iCloud: manage junk e-mail

  • Permanently BLOCK all E-MAILS FROM RUSSIA ru.

    Remember - this is a public forum so never post private information such as numbers of mail or telephone!

    Ideas: I followed the way Windows to place and permanently BLOCK all e-mails from Russia ru but I get this related sexual SLAM of the Russia.

    • You have problems with programs
    • Error messages
    • Recent changes to your computer
    • What you have already tried to solve the problem

    What email program are you using (name and version) and that is your e-mail provider?

    Most of the programs (including the Web site versions) include the ability to "block" senders, but what that means are really as email is classified as junk and sent mail to the junk e-mail folder.  Outlook and Windows Mail include an option in the junk e-mail options called International where you can 'block' eveything from a specific region (for example, the Russia - I checked my versions and include both programs) and if you have this option I would use it in your case.  Windows Live Hotmail doesn't seem to have this international option but he blocked senders are sent to the folder deleted instead of the junk mail folder and you can block the Russia-specific domain names, but not all of the Russia I could find (if if that's what you use, I'll look at more difficult).

    If sending these e-mails to the junk mail folder is not enough, contact your email provider and they may be able to apply a filter to literally block these emails even never, they appear as junk e-mail (but it depends on the provider).  It's worth a shot.

    I hope this helps.  If this isn't the case, please answer the above questions, then I can concentrate my efforts on your particular situation.

    Good luck!

    Lorien - MCSA/MCSE/network + / has + - if this post solves your problem, please click the 'Mark as answer' or 'Useful' button at the top of this message. Marking a post as answer, or relatively useful, you help others find the answer more quickly.

  • My email was not sent e-mails from 29/11/14.

    My email was not sent e-mails from 29/11/14.  I get the error message:

    An unknown error has occurred.

    Server: 'smtp.gmail.com. '

    Windows Live Mail error ID: 0 x 80070057

    Protocol: SMTP

    Port: 587

    Secure (SSL): Yes

    I also tried port 465 (which was original)

    I get e-mails very well.

    1. Change the port from the server of mail out to 465. This is one recommend gmail.
    2. Delete all the pending messages from the Outbox (below the records of account in the folders pane), and then close Windows Live Mail and wait a few minutes.
    3. Restart the program, compose a new message of test with a single topic and send it to yourself. Post a new message in your response.
  • [Email protected] call blocking *.

    I see a lot of sip calls on my VCSe where [email protected] / * / ip ADDRESS or [email protected] / * / OR [email protected] / * /

    I was looking through the forums and found

    https://supportforums.Cisco.com/message/3401571#3401571

    Source Destination Protocol duration status Peer Type shares at start

    2013-11-15 12:26:27 sip:[email protected] / * / sip:[email protected] / * / <->SIP SIP 32 seconds 408 / Request Timeout view local VCS

    2013-11-15 12:26:23 sip:[email protected] / * / sip:[email protected] / * / <->SIP SIP 32 seconds 408 / Request Timeout view local VCS

    2013-11-15 12:26:20 sip:[email protected] / * / sip:[email protected] / * / <->SIP SIP 32 seconds 408 / Request Timeout view local VCS

    2013-11-15 12:26:16 sip:[email protected] / * / sip:[email protected] / * / <->SIP SIP 32 seconds 408 / Request Timeout view local VCS

    2013-11-15 12:26:13 sip:[email protected] / * / sip:[email protected] / * / <->SIP SIP 32 seconds 408 / Request Timeout view local VCS

    2013-11-15 12:06:56 sip:[email protected] / * / sip:[email protected] / * / <->SIP SIP 32 seconds 408 / Request Timeout view local VCS

    2013-11-15 12:00:53 sip:[email protected] / * / sip:[email protected] / * / <->SIP SIP 33 seconds 408 / Request Timeout view local VCS

    2013-11-15 11:05:26 sip:[email protected] / * / sip:[email protected] / * / <->SIP SIP 32 seconds 408 / Request Timeout view local VCS

    2013-11-15 10:14:14 sip:[email protected] / * / sip:[email protected] / * / <->SIP/SIP 32 seconds 408 / Request Timeout view local VCS

    2013-11-15 10:08:32 sip:[email protected] / * / sip:[email protected] / * / <->SIP SIP 32 seconds 408 / Request Timeout view local VCS

    It's my current CPL

    I now would change to:

    "http://www.Tandberg.net/Cpl-extensions" xmlns: xsi = "http://www.w3.org/2001/XMLSchema-instance" xsi: schemaLocation = "urn: ietf:params:xml:ns:cpl cpl.xsd" > "

    "" [email protected] / * / "destination =". * » >

    "" [email protected] / * / "destination =". * » >

    Is THIS CORRECT?

    It'll work, but you should have the two unathenticated and authenticated covered calls.

    Given that all your calls seems to come from @VCS_IP, then you can block all destinations by using * instead of specifying the address. Below is part of the CPL I use and it works for me.

    You can test if the CPL works or not using the VCS-E "tool to locate."

    In addition, you must disable SIP UDP on the VCS-E unless you really need, as these scanners use UDP to find potential targets.

    (Time only I had to re-activate if I have to make a call using the host name where the VCS-E did a search of A DNS record instead of using "normal" SRV records.)

    If you have ISDN deployed gateways, then you should also seriously consider changing the prefixes you use, i.e. Add # to the prefix to break the dial string. For example if your prefix is 99 and you want to call 9912345678, then you dial 99 #12345678 instead.

    Also see the deployment guide for more information about these issues - step 16, page 41 in particular

    http://www.Cisco.com/en/us/docs/Telepresence/infrastructure/VCs/config_guide/Cisco_VCS_Basic_Configuration_Cisco_VCS_Control_with_Cisco_VCS_Expressway_Deployment_Guide_X7-0.PDF

    /Jens

    Please note the answers and score the questions as "answered" as appropriate.

  • I'm flooded with emails from a site who say they got my e-mail from another site. How can I stop them

    My email in box is flooded with emails of accompany who say they got my address from another site, I don't know. How to stop the Please help

    Original title: I am flooded with emails from a site who say they got my e-mail from another site I know nothing of. Please help, how to stop their
    Moved Vius & malware

    What email program are you using?  There should be a place in the program to block spammers.  Some you can right-click on the message or the sender and block them from there.  Unfortunately this is useful if you are getting emails from one or more senders.

  • This e-mail from the thunderbird support team or a fake email?

    I received an email informing me that my account is almost full and giving me instructions on how to renew my account. I just want to check if this e-mail is really a mozilla thunderbird support or is a fake email.

    the content of the email:

    Subject: [[email protected]] alert low storage limit
    Date: Thu, October 15, 2015 17:00:08-0700
    From: < [email protected] > Service account
    Answer: [email protected]
    To: [email protected]

    Dear [email protected],

    1969-2000 MB

    We noticed that your e-mail account has almost exceeds its limit. And you will not be able to send or receive messages any time now,

    Click here to renew your account.

    NOTICE:
    failure of the renewal of your e-mail account. It will be permanently disabled.

    Thank you
    Service account

    n ' has not clicked on the hyper suggested link again.

    The wording of the messages from the 'provider' is a little off. It may be a phishing attempt.
    Contact your e-mail provider using the details found on an old Bill or use a previous contact address you have used successfully in the past.
    DO NOT CLICK ON LINKS IN THE MESSAGE-UNSUB



    The messages appear to come from - [email protected] , but the reply address is another area - [email protected].

    The address of this last was reported as scam
    http://scammed.by/scam.php?id=77518


    Your question

    This e-mail from the thunderbird support team or a fake email?

    Thunderbird support is not a provider of e-mail and does not send a message like this. I suspect that it is a scam.

    TB - 38, 3 Win10-PC

  • E-mail from Apple in the preferences (El Capitan) settings is not accepting my password for my email provider, once again?

    E-mail from Apple in the preferences (El Capitan) settings is not accepting my password for my email provider, AGAIN?  This happens with google, aol, etc, etc, etc. The password is never wrong, that it's just something that happens with Apple OS from time to time. Why can't they solve this!  He emerges finally upward, but at the same time, relentless and software Apple alerts does not receive your mail via the mail app which is now linked to the mail, notes, reminders, calendar, etc.  Any thoughts on a fix?  Or should I just kill app Apple mail, once and for all?  So annoying! I now have another 45 minutes on this problem with no resolution!

    This message has ended up in Mountain Lion and is coded for Messages (filter just to see the messages on the Messages (the application))

    I asked to be moved for you.

    20:23 on Tuesday. March 1, 2016

     iMac 2.5 Ghz i5 2011 (Mavericks) 10.9
     G4/1GhzDual MDD (Leopard 10.5.8)
     MacBookPro (Snow Leopard 10.6.8) 2 GB
     Mac OS X (10.6.8).
     a few iPhones and an iPad

  • I get e-mail from Windows Live Hotmail saying me that my credit card has expired. They are capable of the ID of the card with the last 4 digits showing.

    phishing scam?

    I receive e-mail from hotmail telling me that my credit card has expired. they are capable of the id of the card with the last 4 digits showing. I checked and the card does not expire for another year. I need to get direct support to verify or deny that billing is accurate or false.

    original title: phishing scam?

    Hello Dougharada

    Please see this link about Phishing scams. A lot of information about the grateful and prevent them. I hope this helps.
  • My old MSN e-mail account was hacked and blocked. I created a new Windows Live Hotmail account. How can I access the emails and blocked my old account contact information?

    My old MSN e-mail account was hacked and blocked. I created a new hotmail account. How can I access the emails and blocked my old account contact information?  Thanks for any help!

    original title: hacked E-mail

    Hi BigByrd,

    I'm afraid it's almost impossible to access the old MSN your Hotmail account is newly created account.
    See you soon ~
  • I am not receiving emails to my original via the address via gmail. Previously, either about a week ago, I received the e-mail from my original address but now am not.

    I am not receiving emails to my original via the address via gmail. Previously, either about a week ago, I received the e-mail from my original address but now am not. Maybe a very simple solution, but as a complete technophobe I don't know where to turn! Any help appreciated. Thank you very much.

    original title: loss of emails

    Try to access the web interface and see if you can see all the messages from there.  Otherwise, you may contact gmail to see if they can solve the problem.

    Steve

Maybe you are looking for