[Wolves] Virgin Mail Servers, was Re: CHRISTMAS BASH

Adam Sweet adam at adamsweet.org
Thu Dec 16 00:26:48 UTC 2010


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Following on from discussion with Peter Oliver regarding outgoing mail
delays through Virgin's mail servers.

I guess you already know this Pete, since you spoke to them about it,
but the problem is clear from this snippet in the mail headers (for the
uneducated, start at the bottom noting the timestamp and read upwards):

Received: from [172.23.170.141] (helo=anti-virus02-08)
	by smtp-out4.blueyonder.co.uk with smtp (Exim 4.52)
	id 1PSz7C-0001ZZ-0s
	for wolves at mailman.lug.org.uk; Wed, 15 Dec 2010 21:42:26 +0000
Received: from [77.102.154.60] (helo=froglet.home.mavit.org.uk)
	by asmtp-out3.blueyonder.co.uk with esmtp (Exim 4.72)
	(envelope-from <p.d.oliver at mavit.org.uk>) id 1PSs7O-0001pT-Ik
	for wolves at mailman.lug.org.uk; Wed, 15 Dec 2010 14:14:10 +0000

Bet your mail was sitting queued on their AV scanner waiting to be
scanned for nearly 7 and a half hours.

I also notice that all of their mail relays are Exim and the AV scanner
is at a version which is vulnerable to the recent remote code execution
and root privilege escalation exploits, unless they patched it...

Regards,

Adam Sweet

- -- 

http://blog.adamsweet.org/

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAk0JXK8ACgkQRi1ZcmvD37dIXgCgjFJCBYgTu4DfDFHeOraQaQpu
eWIAoLzAq0oty5WgA4jnNc0/OxDAuHDf
=eOUo
-----END PGP SIGNATURE-----



More information about the Wolves mailing list