Advertisement
Guest User

Untitled

a guest
Jun 13th, 2019
318
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 8.20 KB | None | 0 0
  1. Jun 13 10:54:50 box postfix/anvil[24487]: statistics: max connection rate 1/60s for (smtp:83.235.171.146) at Jun 13 10:47:11
  2. Jun 13 10:54:50 box postfix/anvil[24487]: statistics: max connection count 1 for (smtp:83.235.171.146) at Jun 13 10:47:11
  3. Jun 13 10:54:50 box postfix/anvil[24487]: statistics: max cache size 1 at Jun 13 10:47:11
  4. Jun 13 10:58:53 box postfix/submission/smtpd[25272]: connect from c-73-186-201-77.hsd1.ma.comcast.net[73.186.201.77]
  5. Jun 13 10:58:53 box postfix/submission/smtpd[25272]: lost connection after CONNECT from c-73-186-201-77.hsd1.ma.comcast.net[73.186.201.77]
  6. Jun 13 10:58:53 box postfix/submission/smtpd[25272]: disconnect from c-73-186-201-77.hsd1.ma.comcast.net[73.186.201.77] commands=0/0
  7. Jun 13 11:00:03 box postfix/submission/smtpd[25272]: connect from c-73-186-201-77.hsd1.ma.comcast.net[73.186.201.77]
  8. Jun 13 11:00:03 box postfix/submission/smtpd[25272]: lost connection after CONNECT from c-73-186-201-77.hsd1.ma.comcast.net[73.186.201.77]
  9. Jun 13 11:00:03 box postfix/submission/smtpd[25272]: disconnect from c-73-186-201-77.hsd1.ma.comcast.net[73.186.201.77] commands=0/0
  10. Jun 13 11:00:15 box postfix/smtpd[25654]: connect from r256-pw-maquine.ibys.com.br[187.18.127.153]
  11. Jun 13 11:00:15 box postfix/smtpd[25654]: lost connection after HELO from r256-pw-maquine.ibys.com.br[187.18.127.153]
  12. Jun 13 11:00:15 box postfix/smtpd[25654]: disconnect from r256-pw-maquine.ibys.com.br[187.18.127.153] helo=1 commands=1
  13. Jun 13 11:00:56 box postfix/submission/smtpd[25272]: connect from c-73-126-38-42.hsd1.ma.comcast.net[73.126.38.42]
  14. Jun 13 11:00:56 box postfix/submission/smtpd[25272]: B349B3EA7C: client=c-73-126-38-42.hsd1.ma.comcast.net[73.126.38.42], sasl_method=LOGIN, sasl_username=pfsense@company.net
  15. Jun 13 11:00:57 box postfix/cleanup[25800]: B349B3EA7C: replace: header Received: from 10.16.22.250 (c-73-126-38-42.hsd1.ma.comcast.net [73.126.38.42])??(using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))??(No client certificate requested)??by box.savio from c-73-126-38-42.hsd1.ma.comcast.net[73.126.38.42]; from=<pfsense@company.net> to=<support@company.com> proto=ESMTP helo=<10.16.22.250>: Received: from authenticated-user (box.company.net [45.33.69.193])??(using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))??(No client certificate requested)??by box.company.net (Postfix) with ESMTPSA id B349B3EA7C??for <support@company.com>; Thu, 13 Jun 2019 11:00:56 -0400 (EDT)
  16. Jun 13 11:00:57 box postfix/cleanup[25800]: B349B3EA7C: message-id=<7280941e075e62c2b5780a9e0015a18d@company.net>
  17. Jun 13 11:01:09 box postfix/submission/smtpd[25801]: connect from c-73-186-201-77.hsd1.ma.comcast.net[73.186.201.77]
  18. Jun 13 11:01:09 box postfix/submission/smtpd[25801]: lost connection after CONNECT from c-73-186-201-77.hsd1.ma.comcast.net[73.186.201.77]
  19. Jun 13 11:01:09 box postfix/submission/smtpd[25801]: disconnect from c-73-186-201-77.hsd1.ma.comcast.net[73.186.201.77] commands=0/0
  20. Jun 13 11:01:39 box opendkim[11584]: company.net: key data is not secure: /home/user-data is writeable and owned by uid 1000 which is not the executing uid (118) or the superuser
  21. Jun 13 11:01:55 box postfix/submission/smtpd[25801]: connect from c-73-186-201-77.hsd1.ma.comcast.net[73.186.201.77]
  22. Jun 13 11:01:55 box postfix/submission/smtpd[25801]: lost connection after CONNECT from c-73-186-201-77.hsd1.ma.comcast.net[73.186.201.77]
  23. Jun 13 11:01:55 box postfix/submission/smtpd[25801]: disconnect from c-73-186-201-77.hsd1.ma.comcast.net[73.186.201.77] commands=0/0
  24. Jun 13 11:02:01 box postfix/qmgr[16785]: B349B3EA7C: from=<pfsense@company.net>, size=32133372, nrcpt=1 (queue active)
  25. Jun 13 11:02:01 box postfix/smtp[25899]: initializing the client-side TLS engine
  26. Jun 13 11:02:01 box postfix/submission/smtpd[25272]: disconnect from c-73-126-38-42.hsd1.ma.comcast.net[73.126.38.42] ehlo=2 starttls=1 auth=1 mail=1 rcpt=1 data=1 quit=1 commands=8
  27. Jun 13 11:02:02 box postfix/smtp[25899]: setting up TLS connection to company-com.mail.protection.outlook.com[104.47.42.36]:25
  28. Jun 13 11:02:02 box postfix/smtp[25899]: company-com.mail.protection.outlook.com[104.47.42.36]:25: TLS cipher list "aNULL:-aNULL:HIGH:MEDIUM:+RC4:@STRENGTH:!aNULL:!RC4"
  29. Jun 13 11:02:02 box postfix/smtp[25899]: looking for session smtp&company.com&company-com.mail.protection.outlook.com&104.47.42.36&&9144B8180B74BFCD5E3F6A5F076BCBDD41FFEFF74A41A3B65A1D9C2AA484441E in smtp cache
  30. Jun 13 11:02:02 box postfix/tlsmgr[16857]: lookup smtp session id=smtp&company.com&company-com.mail.protection.outlook.com&104.47.42.36&&9144B8180B74BFCD5E3F6A5F076BCBDD41FFEFF74A41A3B65A1D9C2AA484441E
  31. Jun 13 11:02:02 box postfix/smtp[25899]: SSL_connect:before SSL initialization
  32. Jun 13 11:02:02 box postfix/smtp[25899]: SSL_connect:SSLv3/TLS write client hello
  33. Jun 13 11:02:02 box postfix/smtp[25899]: SSL_connect:SSLv3/TLS write client hello
  34. Jun 13 11:02:02 box postfix/smtp[25899]: SSL_connect:SSLv3/TLS read server hello
  35. Jun 13 11:02:02 box postfix/smtp[25899]: company-com.mail.protection.outlook.com[104.47.42.36]:25: depth=2 verify=1 subject=/C=BE/O=GlobalSign nv-sa/OU=Root CA/CN=GlobalSign Root CA
  36. Jun 13 11:02:02 box postfix/smtp[25899]: company-com.mail.protection.outlook.com[104.47.42.36]:25: depth=1 verify=1 subject=/C=BE/O=GlobalSign nv-sa/CN=GlobalSign Organization Validation CA - SHA256 - G3
  37. Jun 13 11:02:02 box postfix/smtp[25899]: company-com.mail.protection.outlook.com[104.47.42.36]:25: depth=0 verify=1 subject=/C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=mail.protection.outlook.com
  38. Jun 13 11:02:02 box postfix/smtp[25899]: SSL_connect:SSLv3/TLS read server certificate
  39. Jun 13 11:02:02 box postfix/smtp[25899]: SSL_connect:SSLv3/TLS read server key exchange
  40. Jun 13 11:02:02 box postfix/smtp[25899]: SSL_connect:SSLv3/TLS read server certificate request
  41. Jun 13 11:02:02 box postfix/smtp[25899]: SSL_connect:SSLv3/TLS read server done
  42. Jun 13 11:02:02 box postfix/smtp[25899]: SSL_connect:SSLv3/TLS write client certificate
  43. Jun 13 11:02:02 box postfix/smtp[25899]: SSL_connect:SSLv3/TLS write client key exchange
  44. Jun 13 11:02:02 box postfix/smtp[25899]: SSL_connect:SSLv3/TLS write change cipher spec
  45. Jun 13 11:02:02 box postfix/smtp[25899]: SSL_connect:SSLv3/TLS write finished
  46. Jun 13 11:02:02 box postfix/smtp[25899]: SSL_connect:SSLv3/TLS write finished
  47. Jun 13 11:02:02 box postfix/smtp[25899]: SSL_connect:SSLv3/TLS read change cipher spec
  48. Jun 13 11:02:02 box postfix/smtp[25899]: SSL_connect:SSLv3/TLS read finished
  49. Jun 13 11:02:02 box postfix/smtp[25899]: save session smtp&company.com&company-com.mail.protection.outlook.com&104.47.42.36&&9144B8180B74BFCD5E3F6A5F076BCBDD41FFEFF74A41A3B65A1D9C2AA484441E to smtp cache
  50. Jun 13 11:02:02 box postfix/tlsmgr[16857]: put smtp session id=smtp&company.com&company-com.mail.protection.outlook.com&104.47.42.36&&9144B8180B74BFCD5E3F6A5F076BCBDD41FFEFF74A41A3B65A1D9C2AA484441E [data 2027 bytes]
  51. Jun 13 11:02:02 box postfix/tlsmgr[16857]: write smtp TLS cache entry smtp&company.com&company-com.mail.protection.outlook.com&104.47.42.36&&9144B8180B74BFCD5E3F6A5F076BCBDD41FFEFF74A41A3B65A1D9C2AA484441E: time=1560438122 [data 2027 bytes]
  52. Jun 13 11:02:02 box postfix/smtp[25899]: company-com.mail.protection.outlook.com[104.47.42.36]:25: subject_CN=mail.protection.outlook.com, issuer_CN=GlobalSign Organization Validation CA - SHA256 - G3, fingerprint=FE:DC:1F:64:49:17:77:7A:53:61:1F:C9:3A:9D:73:3E, pkey_fingerprint=E3:F0:96:57:FF:0C:E9:3D:B0:44:C5:4C:B4:1C:45:C1
  53. Jun 13 11:02:02 box postfix/smtp[25899]: Trusted TLS connection established to company-com.mail.protection.outlook.com[104.47.42.36]:25: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
  54. Jun 13 11:02:06 box postfix/smtp[25899]: B349B3EA7C: to=<support@company.com>, relay=company-com.mail.protection.outlook.com[104.47.42.36]:25, delay=70, delays=65/0.07/0.94/3.9, dsn=2.6.0, status=sent (250 2.6.0 <7280941e075e62c2b5780a9e0015a18d@company.net> [InternalId=26057566585172, Hostname=DM5PR08MB3387.namprd08.prod.outlook.com] 32143229 bytes in 2.921, 10742.647 KB/sec Queued mail for delivery)
  55. Jun 13 11:02:06 box postfix/qmgr[16785]: B349B3EA7C: removed
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement