황당한 경험 - 특정 메일이 이상하게 수신됩니다.
아웃룩을 사용하려고 pop3 세팅을 완료하였습니다.
처음엔 메일 발송/수신이 잘 되다가 갑자기 사용자 이름과 암호를 입력하라고 나옵니다.
비밀번호를 바꾼적이 없는데...
왜 그런지 한참을 헤맨 끝에
#> telnet localhost pop3
Trying 127.0.0.1...
Connected to localhost.
Escape character is '^]'.
+OK ready
user test
+OK Password required for test.
pass xxxx
-ERR [SYS/PERM] Unable to process From lines (envelopes) in /var/mail/test; change recognition mode or check for corrupted mail drop.
+OK Pop server at mydomain.com signing off.
Connection closed by foreign host.
이렇게 뜨는군요.
그래서 /var/spool/mail/test 파일을 열어봤더니...
----------------------------------------------------------------------
FPEhUTUw+PEhFQUQ+DQo8TUVUQSBjb250ZW50PSJNU0hUTUwgNi4wMC4yOTAwLjMxNTciIG5hbWU9
R0VORVJBVE9SPg0KPFNUWUxFPlAgew0KCU1BUkdJTjogNXB4IDBweA0KfQ0KPC9TVFlMRT4NCjwv
SEVBRD4NCjxCT0RZIHN0eWxlPSJGT05ULVNJWkU6IDEwcHQ7IENPTE9SOiBibGFjazsgRk9OVC1G
QU1JTFk6ILG8uLI7IEJBQ0tHUk9VTkQtQ09MT1I6ICNmZmZmZmYiPjxGT05UIHN0eWxlPSJGT05U
LVNJWkU6IDEwcHQ7IEZPTlQtRkFNSUxZOiCxvLiyIj4NCjxQPsXXvbrGri4uLjwvUD48L0ZPTlQ+
Cgo8c3R5bGU+Cgl0YWJsZSx0cix0ZCB7Zm9udC1mYW1pbHk6sby4sjtmb250LXNpemU6MTJweDtj
b2xvcjojMTMxQjI2O30KCWEub3Zlcmxpbmsge2NvbG9yOiMxMzFCMjY7dGV4dC1kZWNvcmF0aW9u
Om5vbmUgfQlhLm92ZXJsaW5rOmhvdmVye2NvbG9yOiMxMzFCMjY7dGV4dC1kZWNvcmF0aW9uOnVu
ZGVybGluZTt9Cjwvc3R5bGU+CgoKPGJyPjxicj4KPHRhYmxlIGJvcmRlcj0wIGNlbGxwYWRkaW5n
PTAgY2VsbHNwYWNpbmc9MCB3aWR0aD03ODA+Cjx0cj48dGQgaGVpZ2h0PScyJyBiZ2NvbG9yPScj
RDlERUUyJyBjb2xzcGFuPScyJz48L3RkPjwvdHI+Cjx0cj48dGQgaGVpZ2h0PScxMCcgY29sc3Bh
bj0nMic+PC90ZD48L3RyPgo8dHI+Cjx0ZCB2YWxpZ249J3RvcCc+PGEgaHJlZj0naHR0cDovL3d3
dy5lbXBhcy5jb20nIHRhcmdldD1fYmxhbms+PGltZyBzcmM9J2h0dHA6Ly9pYi5lbWltZy5jb20v
ZW1wYWwvc2xvZ2FuL2xvZ29fYWRtYWlsLmdpZicgd2lkdGg9JzEwMScgaGVpZ2h0PScxNicgYm9y
ZGVyPScwJz48L2E+PC90ZD4KPHRkIHZhbGlnbj0ndG9wJyBhbGlnbj0ncmlnaHQnPjxhIGhyZWY9
J2h0dHA6Ly9maWxlYm94LmVtcGFzLmNvbScgdGFyZ2V0PV9ibGFuaz48aW1nIHNyYz0naHR0cDov
L2liLmVtaW1nLmNvbS9lbXBhbC9zbG9nYW4vZmlsZWJveF8yMjdfNDdfMi5naWYnIGJvcmRlcj0n
MCc+PC9hPjwvdGQ+CjwvdHI+CjwvdGFibGU+IDwvQk9EWT48L0hUTUw+PGltZyB3aWR0aD0xIGhl
aWdodD0xIHNyYz0iaHR0cDovL21haWwuZW1wYXMuY29tL3JzZC9lbXBhbHJjcHQuaHRtbC95M2Zn
TUd4dWNHaHFhQS8yNmJ5X3hNamsyTWovUTZHd2JjR2h2Wlc1cGVFQnNjR2x1Wm05MFpXTm9iaU52
YlUvZm9vLmdpZiI+DQoNCg==
From Hannukainendbwe@alcopaving.com Tue Oct 9 15:13:16 2007
Return-Path:
Received: from [83.157.6.104] (dyn-83-157-2-70.ppp.tiscali.fr [83.157.2.70])
by mydomain.com (8.11.6/8.11.6) with ESMTP id l996D9i24057
for ; Tue, 9 Oct 2007 15:13:15 +0900
Received: from nom-eb85c523610 ([151.194.22.124]:22478 "EHLO nom-eb85c523610"
smtp-auth: TLS-CIPHER: TLS-PEER-CN1: )
by [83.157.6.104] with ESMTP id S22WXPRIYVHZDDCT (ORCPT
);
Tue, 9 Oct 2007 08:30:02 +0200
Message-ID: <000901c80a3d$cb814a70$68069d53@nomeb85c523610>
From: "Bubba Hannukainen"
To: test@mydomain.com
Subject: lesseert
Date: Tue, 9 Oct 2007 08:29:50 +0200
Message-ID: <000901c80a3d$cb814a70$68069d53@nomeb85c523610>
MIME-Version: 1.0
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.6626
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2962
X-Antivirus: avast! (VPS 000779-0, 08/10/2007), Outbound message
X-Antivirus-Status: Clean
Wazzup test
I mend my love relationship over eight months but it all takes just one night to lose her to a another guy who got bigger than my penis
Bubba Hannukainen
http://www.nicny.com/
...
------------------------------------------------------------------
이렇게 나옵니다. 그래서 처음 나오는 From 윗부분을 삭제하고 나니 아웃룩에서
별 일 없었던 것처럼 수신이 됩니다.
현재까지 테스트한 바로는 해당 서버에서 smtp로 보낸 메일 및 네이트/네이버/천리안 등에서 보낸 메일,
그리고 터미널에서 보낸 메일까지 수신이 정상적으로 되는데
유독 엠팔에서 보낸 메일만은 위와 같이 수신이 되는군요.
엠팔에서 발송된 메일을 수신한 경우 /var/spool/mail/test 파일에 위와 같이 이상한 내용이 들어오고
그렇게 되면 아웃룩에서는 자꾸 비밀번호 또 물어보고
110 포트로 telnet 접속하면 Unable to process From lines (envelopes) in /var/mail/test.. 이란
메시지만 뜹니다.
혹시 이런 경험을 해보신 분이 있다면 도움 부탁드립니다.


댓글 달기