Re: Strange SMTP sessions with 'helo=<large negative number>' syntax
- From: Michel Arboi <michel.arboi@xxxxxxxxx>
- Date: Thu, 29 Dec 2005 10:01:23 +0100
On 28/12/05, max <max@xxxxxxxxxxxxxx> wrote:
> to=<dylanfans-unsubscribe@xxxxxxxxxxxxxxx> proto=SMTP helo=<-1217882552>
> Notice that helo section is a negative number (which is why my postfix rejects the message)
Spammers sometimes hide IP addresses (in URL) by using a 32 bits
integer. And also that they often use buggy tools.<grin>
Maybe they tried to use this trick in the HELO command?
-1217882552+2^32 = 3077084744 = 183.104.150.72
-1218008120+2^32 = 3076959176 = 183.102.171.200
Both addresses seems to be unassigned, my hypothesis looks wrong :-(
> Has anyone noticed this as well?
I don't have this in my logs.
- Follow-Ups:
- RE: Strange SMTP sessions with 'helo=<large negative number>' syntax
- From: David Gillett
- RE: Strange SMTP sessions with 'helo=<large negative number>' syntax
- References:
- Prev by Date: Re: Strange SMTP sessions with 'helo=<large negative number>' syntax
- Next by Date: Re: Strange SMTP sessions with 'helo=<large negative number>' syntax
- Previous by thread: Re: Strange SMTP sessions with 'helo=<large negative number>' syntax
- Next by thread: RE: Strange SMTP sessions with 'helo=<large negative number>' syntax
- Index(es):
Relevant Pages
|