View Issue Details

IDProjectCategoryView StatusLast Update
0000014ShelterMailspublic2019-05-05 14:27
ReporterAxelTerizaki Assigned ToSestren  
PriorityhighSeveritymajorReproducibilityunable to reproduce
Status closedResolutionfixed 
Product Versionv2 
Summary0000014: Spam vers Outlook
DescriptionSuite à 0000010 je nous ai inscrits sur le Junk reporting de MS donc on reçoit les mails en spam dirigés vers outlook.

Là on en a eu un justement et dans le slogs j'arrive pas trop à voir comment ça s'est connecté (j'avoue c'est pas évident à lire les logs de postfix)

Voir les headers en pièce jointe


TagsNo tags attached.
Attached Files
headers.txt (7,536 bytes)   
Sujet : 
It will be very nice for me to know such a wonderful person.
De : 
"stegukk1@umanitoba.ca" <info@cooperativaceposs.com>
Date : 
17/04/2019 � 02:12
Pour : 
Undisclosed recipients:;
X-HmXmrOriginalRecipient: 
<nardini@hotmail.ca>
X-MS-Exchange-EOPDirect: 
true
Received: 
from BL2NAM06HT027.Eop-nam06.prod.protection.outlook.com (2603:10b6:208:fc::44) by MN2PR06MB5520.namprd06.prod.outlook.com with HTTPS via MN2PR02CA0031.NAMPRD02.PROD.OUTLOOK.COM; Wed, 17 Apr 2019 00:13:37 +0000
Received: 
from BL2NAM06FT012.Eop-nam06.prod.protection.outlook.com (10.152.106.60) by BL2NAM06HT027.Eop-nam06.prod.protection.outlook.com (10.152.107.17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384) id 15.20.1813.12; Wed, 17 Apr 2019 00:13:36 +0000
Authentication-Results: 
spf=none (sender IP is 176.31.224.90) smtp.mailfrom=cooperativaceposs.com; hotmail.ca; dkim=none (message not signed) header.d=none;hotmail.ca; dmarc=none action=none header.from=cooperativaceposs.com;
Received-SPF: 
None (protection.outlook.com: cooperativaceposs.com does not designate permitted sender hosts)
Received: 
from mail.mahoro-net.org (176.31.224.90) by BL2NAM06FT012.mail.protection.outlook.com (10.152.107.7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.1813.12 via Frontend Transport; Wed, 17 Apr 2019 00:13:36 +0000
X-IncomingTopHeaderMarker: 
OriginalChecksum:C08A803D9AD713C5D3659505D2AEC00C22AED3F517315B63C7F3ABB8CE9F4C64;UpperCasedChecksum:F81DA66CBD80AA84711BCEC27655A99BA253B9D93486EC710BE92A92ED9CF4D3;SizeAsReceived:1474;Count:14
Received: 
from localhost (localhost [127.0.0.1]) by dawn.mahoro-net.org (Postfix) with ESMTP id 44D311A0C93; Wed, 17 Apr 2019 02:13:35 +0200 (CEST)
Received: 
from mail.mahoro-net.org ([127.0.0.1]) by localhost (shelterv2.mahoro-net.org [127.0.0.1]) (amavisd-new, port 10024) with LMTP id ZaHY19GbYjhF; Wed, 17 Apr 2019 02:13:35 +0200 (CEST)
Received: 
from 194.156.126.50 (mx-ll-180.183.243-61.dynamic.3bb.co.th [180.183.243.61]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) (Authenticated sender: postmaster@haruhi.fr) by mail.mahoro-net.org (Postfix) with ESMTPSA id 609991A0C4D; Wed, 17 Apr 2019 02:12:10 +0200 (CEST)
ID du message : 
<9F9A2C7F74A08FBC60652C94E096616F@cooperativaceposs.com>
R�pondre � : 
"stegukk1@umanitoba.ca" <stegukk1@umanitoba.ca>
Content-Type: 
multipart/mixed; boundary="9502000dd821b8e55326189964df"
X-Spam-Flag: 
YES
X-Spam-Status: 
Yes, score=7.1 required=5.0 tests=HTML_MESSAGE,MISSING_HEADERS, PDS_FROM_2_EMAILS,REPLYTO_WITHOUT_TO_CC,TO_NO_BRKTS_HTML_IMG, TVD_RCVD_IP,TVD_RCVD_IP4,UNPARSEABLE_RELAY,URIBL_ABUSE_SURBL autolearn=no autolearn_force=no version=3.4.2
X-Spam-Level: 
*******
X-Spam-Checker-Version: 
SpamAssassin 3.4.2 (2018-09-13) on shelterv2.mahoro-net.org
X-IncomingHeaderCount: 
14
Return-Path: 
info@cooperativaceposs.com
X-MS-Exchange-Organization-ExpirationStartTime: 
17 Apr 2019 00:13:36.2236 (UTC)
X-MS-Exchange-Organization-ExpirationStartTimeReason: 
OriginalSubmit
X-MS-Exchange-Organization-ExpirationInterval: 
2:00:00:00.0000000
X-MS-Exchange-Organization-ExpirationIntervalReason: 
OriginalSubmit
X-MS-Exchange-Organization-Network-Message-Id: 
28f021db-8b81-4086-99b2-08d6c2c98900
X-EOPAttributedMessage: 
0
X-EOPTenantAttributedMessage: 
84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa:0
X-MS-Exchange-Organization-MessageDirectionality: 
Incoming
X-Forefront-Antispam-Report: 
EFV:NLI;
X-MS-Exchange-Organization-AuthSource: 
BL2NAM06FT012.Eop-nam06.prod.protection.outlook.com
X-MS-Exchange-Organization-AuthAs: 
Anonymous
X-MS-PublicTrafficType: 
Email
X-MS-Office365-Filtering-Correlation-Id: 
28f021db-8b81-4086-99b2-08d6c2c98900
X-Microsoft-Antispam: 
BCL:6;PCL:0;RULEID:(2390118)(5000112)(711020)(4605104)(610169)(8291501072);SRVR:BL2NAM06HT027;
X-MS-TrafficTypeDiagnostic: 
BL2NAM06HT027:
X-MS-Exchange-PUrlCount: 
1
X-MS-Exchange-Diag-Persisted-Urls-ChunkCount: 
1
X-MS-Exchange-Diag-Persisted-Urls-0: 
[{"ID":1,"OU":"https://cuu.su/mxq/","IBT":false,"U":"https://cuu.su/mxq/","DNR":false,"IAR":false,"LI":{"TN":"a","IC":true,"BF":0,"SI":1346,"EndIndex":1412},"SRCI":1,"CannonicalizedUrl":"https://cuu.su/mxq","NormalizedUrl":"https://cuu.su/mxq/","DPD":{"UF":"256","OCH":"17567108108410359606","CNT":"1","SL":"1"},"PROC":[{"T":2,"PU":"https://cuu.su/mxq/","CR":null,"OR":[{"OC":8,"RC":2,"EX":false},{"OC":16384,"RC":3,"EX":false},{"OC":1,"RC":2,"EX":false},{"OC":512,"RC":3,"EX":false},{"OC":262144,"RC":2,"EX":false},{"OC":256,"RC":2,"EX":false},{"OC":4,"RC":3,"EX":false},{"OC":16,"RC":2,"EX":false},{"OC":1024,"RC":3,"EX":false},{"OC":32,"RC":2,"EX":false}],"UrlOperationFlag":17924},{"T":1,"PU":"https://cuu.su/mxq","CR":null,"OR":[{"OC":8,"RC":2,"EX":false},{"OC":16384,"RC":3,"EX":false},{"OC":1,"RC":2,"EX":false},{"OC":512,"RC":3,"EX":false},{"OC":262144,"RC":2,"EX":false},{"OC":256,"RC":2,"EX":false},{"OC":4,"RC":3,"EX":false},{"OC":16,"RC":2,"EX":false},{"OC":1024,"RC":3,"EX":false},{"OC":32,"RC":2,"EX":false},{"OC":4096,"RC":2,"EX":false}],"UrlOperationFlag":17924}]}]
X-MS-Exchange-Diag-PUrlInfoCount: 
1
X-MS-Exchange-EOPDirect: 
true
X-Sender-IP: 
176.31.224.90
X-SID-PRA: 
INFO@COOPERATIVACEPOSS.COM
X-SID-Result: 
NONE
X-MS-Exchange-Organization-PCL: 
8
X-OriginatorOrg: 
outlook.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 
17 Apr 2019 00:13:36.0454 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 
28f021db-8b81-4086-99b2-08d6c2c98900
X-MS-Exchange-CrossTenant-Id: 
84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa
X-MS-Exchange-CrossTenant-FromEntityHeader: 
Internet
X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 
00000000-0000-0000-0000-000000000000
X-MS-Exchange-Transport-CrossTenantHeadersStamped: 
BL2NAM06HT027
X-MS-Exchange-Transport-EndToEndLatency: 
00:00:01.1314628
X-MS-Exchange-Processed-By-BccFoldering: 
15.20.1792.016
X-Microsoft-Antispam-Mailbox-Delivery: 
abwl:0;wl:0;pcwl:0;kl:0;iwl:0;dwl:0;dkl:0;rwl:0;ucf:0;jmr:0;ex:0;psp:0;auth:0;dest:J;OFR:SpamFilterAuthJ;ENG:(5062000261)(5061607266)(5061608174)(4900115)(4920090)(6375004)(4950130)(4990090)(9140004);RF:JunkEmail;
X-Message-Info: 
qoGN4b5S4yp61bh2o1W2jetqR/z3d/FZ9kuS/b8ZjYKqeOQj+UQZd+102BMGBC8C0lakVlzENi6AAHT92GmPoC/rIKgd2hbVBu7gzCpIWtp82a6ZepPAcUQ1EMCyUAfAKgasT1hTF+0YI4rrt9rgWIRk9idEDv1+x2tX4SYI27Pm7x9XpwZkqDzGQVdSafMA0I+DmcdGoWtisgE0LnWIuw==
X-Message-Delivery: 
Vj0xLjE7dXM9MDtsPTA7YT0wO0Q9MjtHRD0yO1NDTD02
X-Microsoft-Antispam-Message-Info: 
7fXl9Uc/JYKRmVmD4c5zHHbwrPC7Pc3INi/15f/iUiFc98BMZNVQ7MLfab+rabEvw67Dmt7RGg9EVPQV3dnFEXGrvYWy+x98+TYnUsPvsqELwuLG1T96gQ1dl5h0KuuBLHvC967VmQ4LxFdsFZ291cDoAsy/e/MHhXK3FYMbuNyEwtTtLIbHVyFmGgaK+R8QgqJ42x2neCZH2DLxzF3v/65EoGlcuK80d9IkZU0i9fRObW1MxUWLKaEnobJu8aB/w57vVIbP3lk5Ezzr0DO21ONvSWPfJeH1owE3+jvWayGyoSg6ylvaEEWA4W35L+XtYqRASAUJdxW++d7vMiDogjMaMo/mTN6748fkc9D0aZVvE2FN242RkAh4kuZC4fkLLQkWLG4c3acn9wYdVvF1U1BrNBNovYxVCSWBrNvbXe4mL3K0PzWpuKIXa1Li/T2D8qMm3C1D5nDjdDyoANyEePG7BWOHMswwtDFrXpSIW2b0NPIzMNxczfA2qJIjLUDTSA+DM8ZGMkHvxWuqHbv1rpUvALPRdX9cjoC+V5X+obJP+i1At3AQXGrJNq/YFurPcsEnc4j7XXwmGvMs4UCYbIuYoQw3RuK29rX+pRHdcSLs0qszuNfsq3gIOvpzbYvCZSt1gexCRMdzp60oCpTi2VRF8M/JVK3v29MjIbL1rvbwjYvE2HMzlfFa1fQGbjKFjIKTZYyI6vwKmMUggy4DeMfJ+xpWEQsLgorj0jwrJinVKrTip14BHj49JN7CfVuTmKxte0VDq2OGrnG0DSP97nI9dSTweZOh5lGx34C/z7oHV18a2LLcUV89Eln3m6TDRMWmVOgQf63rtjIRS7TzAsh9870ghwlnxEd9H5bJ4UekxWNi78b32sF63pntKgCG
Version de MIME: 
1.0
headers.txt (7,536 bytes)   

Relationships

related to 0000016 closedAxelTerizaki Impossible d'envoyer des mails vers Yahoo.fr 
related to 0000017 closedAxelTerizaki Ménage dans les comptes mails en forward only 

Activities

Sestren

Sestren

2019-04-23 21:38

administrator   ~0000032

C'est passé parce que le mec s'est log avec le compte suivant:
sasl_method=LOGIN, sasl_username=postmaster@haruhi.fr
AxelTerizaki

AxelTerizaki

2019-04-23 21:51

administrator   ~0000033

T'as fait le lien comment? J e vais changer le mdp immédiatement.
Sestren

Sestren

2019-04-23 21:56

administrator   ~0000034

J'ai regardé les logs postfix
Sestren

Sestren

2019-04-23 21:57

administrator   ~0000035

grep mail source et mail dest, grep ID de la transaction postfix et voilà
AxelTerizaki

AxelTerizaki

2019-04-23 22:00

administrator   ~0000036

Je me note ça pour la documentation. J'avais essayé de regarder à l'oeil nu à partir de la destination mais j'avais pas retrouvé le mail source.
AxelTerizaki

AxelTerizaki

2019-04-25 18:16

administrator   ~0000044

L'issue n'était pas close, un problème avec postfixadmin m'a en fait empêché de changer le mot de passe.

Le souci vient du fait qu'une version antérieure de postfixadmin du temps de shelterv1/twilight avait mal MAJ les comtpes et du coup ils étaient pas modifiables à cause d'une entrée dans la BDD qui manquait.

Il va falloir faire un peu de ménage pour fixer tout ça domaine par domaine.

Issue History

Date Modified Username Field Change
2019-04-23 19:26 AxelTerizaki New Issue
2019-04-23 19:26 AxelTerizaki File Added: headers.txt
2019-04-23 21:38 Sestren Note Added: 0000032
2019-04-23 21:38 Sestren Assigned To => Sestren
2019-04-23 21:38 Sestren Status new => confirmed
2019-04-23 21:51 AxelTerizaki Note Added: 0000033
2019-04-23 21:53 AxelTerizaki Status confirmed => resolved
2019-04-23 21:53 AxelTerizaki Resolution open => fixed
2019-04-23 21:56 Sestren Note Added: 0000034
2019-04-23 21:57 Sestren Note Added: 0000035
2019-04-23 22:00 AxelTerizaki Note Added: 0000036
2019-04-25 11:38 AxelTerizaki Relationship added related to 0000016
2019-04-25 18:16 AxelTerizaki Note Added: 0000044
2019-04-25 18:18 AxelTerizaki Relationship added related to 0000017
2019-05-05 14:27 Sestren Status resolved => closed