Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

win-nt from the people who invented edlin. -- MaDsen Wikholm, mwikholm@at8.abo.fi


computers / alt.privacy.anon-server / Re: spooled mail for middleman

SubjectAuthor
* spooled mail for middlemanGrant Taylor
+- Re: spooled mail for middlemananon
`* Re: spooled mail for middlemanMiddleman Remailer Administrator
 +- Re: spooled mail for middlemanGrant Taylor
 `* Re: spooled mail for middlemanSEC3
  +- Re: spooled mail for middlemanSEC3
  `- Re: spooled mail for middlemanConan

1
spooled mail for middleman

<ul4kj3$r0i$1@tncsrv09.home.tnetconsulting.net>

  copy mid

https://news.novabbs.com/computers/article-flat.php?id=15980&group=alt.privacy.anon-server#15980

  copy link   Newsgroups: alt.privacy.anon-server
Path: i2pn2.org!i2pn.org!news.samoylyk.net!tncsrv06.tnetconsulting.net!tncsrv09.home.tnetconsulting.net!.POSTED.198.18.1.140!not-for-mail
From: gtay...@tnetconsulting.net (Grant Taylor)
Newsgroups: alt.privacy.anon-server
Subject: spooled mail for middleman
Date: Sun, 10 Dec 2023 09:13:39 -0600
Organization: TNet Consulting
Message-ID: <ul4kj3$r0i$1@tncsrv09.home.tnetconsulting.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Sun, 10 Dec 2023 15:13:39 -0000 (UTC)
Injection-Info: tncsrv09.home.tnetconsulting.net; posting-host="198.18.1.140";
logging-data="27666"; mail-complaints-to="newsmaster@tnetconsulting.net"
User-Agent: Mozilla Thunderbird
Content-Language: en-US
 by: Grant Taylor - Sun, 10 Dec 2023 15:13 UTC

To whom it concerns,

I'm seeing a 100+ messages spooled for middleman.

It looks like it started sometime yesterday after Dizum fixed DNS.

--
Grant. . . .

Re: spooled mail for middleman

<20231210.222334.ee2ca045@mixmin.net>

  copy mid

https://news.novabbs.com/computers/article-flat.php?id=15984&group=alt.privacy.anon-server#15984

  copy link   Newsgroups: alt.privacy.anon-server
Message-Id: <20231210.222334.ee2ca045@mixmin.net>
Date: Sun, 10 Dec 2023 22:23:34 +0000
Subject: Re: spooled mail for middleman
From: nore...@mixmin.net (anon)
References: <ul4kj3$r0i$1@tncsrv09.home.tnetconsulting.net>
Newsgroups: alt.privacy.anon-server
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!news.mixmin.net!news2.arglkargh.de!sewer!news.dizum.net!not-for-mail
Organization: dizum.com - The Internet Problem Provider
X-Abuse: abuse@dizum.com
Injection-Info: sewer.dizum.com - 2001::1/128
 by: anon - Sun, 10 Dec 2023 22:23 UTC

In article <ul4kj3$r0i$1@tncsrv09.home.tnetconsulting.net>
>
> To whom it concerns,
>
> I'm seeing a 100+ messages spooled for middleman.
>
> It looks like it started sometime yesterday after Dizum fixed DNS.

Yep. Dizum has gone steadily downhill ever since.

mixmaster history latency uptime
--------------------------------------------
banana ******** 21:00 100.00%
beaufusil ************ 13:00 100.00%
ipsum *****#****** 11:00 100.00%
shalo ************ 12:00 100.00%
tncmm ##*####***** 5:00 100.00%
frell --+-+-++--++ 4:38:59 99.01%
frell2 ----------++ 5:23:59 98.84%
paranoia ********+*** 33:00 96.21%
middleman ********** 9:30 85.18%
slow ________.--- 82:27:00 74.60%
dizum **++*** 36:30 39.75%

Re: spooled mail for middleman

<ul690j$2qjnu$1@paganini.bofh.team>

  copy mid

https://news.novabbs.com/computers/article-flat.php?id=15986&group=alt.privacy.anon-server#15986

  copy link   Newsgroups: alt.privacy.anon-server
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!eternal-september.org!paganini.bofh.team!not-for-mail
From: middlema...@protonmail.com (Middleman Remailer Administrator)
Newsgroups: alt.privacy.anon-server
Subject: Re: spooled mail for middleman
Date: Mon, 11 Dec 2023 01:08:19 -0500
Organization: To protect and to server
Message-ID: <ul690j$2qjnu$1@paganini.bofh.team>
References: <ul4kj3$r0i$1@tncsrv09.home.tnetconsulting.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Mon, 11 Dec 2023 06:08:19 -0000 (UTC)
Injection-Info: paganini.bofh.team; logging-data="2969342"; posting-host="120uv0Ou7QOYzoLaO26Cow.user.paganini.bofh.team"; mail-complaints-to="usenet@bofh.team"; posting-account="9dIQLXBM7WM9KzA+yjdR4A";
User-Agent: Mozilla Thunderbird
Cancel-Lock: sha256:GWeJEeNfadGhxlcTM/Ltqcx5WHxHImy07+lonPqjlR4=
X-Notice: Filtered by postfilter v. 0.9.3
Content-Language: en-US
 by: Middleman Remailer A - Mon, 11 Dec 2023 06:08 UTC

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On 12/10/23 10:13 AM, Grant Taylor wrote:
> To whom it concerns,
>
> I'm seeing a 100+ messages spooled for middleman.
>
> It looks like it started sometime yesterday after Dizum fixed DNS.

My pfSense setup is running Suricata with a whole bunch of newly-enabled
rules, and it's set to block for 24 hours the source address of any
communication that triggers an alert. So far, the vast majority of
alerts have been classified by Suricata as miscellaneous attacks. I've
suppressed a lot of rules that triggered blocks for protocol related
errors and software that I use on a regular basis.

I have the IP addresses of remailers in a pass list:

2a01:4f8:200:60a6::2
2a03:4000:3f:24b:14a1:1eff:fe82:32d1
5.181.51.40
45.33.28.24
45.66.35.221
77.1.130.120
84.173.194.212
88.80.28.20
91.228.53.8
107.161.26.232
144.76.182.167
2600:3c00:e000:1e9::8849

This list may very well be out of date, which is probably why there is
a lot of mail queued up on your remailer for middleman, and also why
middleman is dropping in the reliability stats. I've been monitoring
the stats, and I'm continuing to adjust Suricata so that it doesn't
block the IP addresses that are sending stuff that needs to get through.

-----BEGIN PGP SIGNATURE-----

iHUEARYIAB0WIQT1kQVuxVq5rUrWjocRLhFEVzoxhQUCZXamcAAKCRARLhFEVzox
hRb5AQCIOpXroofRjEl09njipbjqnaPaRaZ9badIS7NtdLrbGAEAzzs7Z8IKjAPv
GEMSBIIq8tbe3ySlJBc0mD3yzBBKuQY=
=tFwa
-----END PGP SIGNATURE-----

Re: spooled mail for middleman

<ul77mo$66j$1@tncsrv09.home.tnetconsulting.net>

  copy mid

https://news.novabbs.com/computers/article-flat.php?id=15997&group=alt.privacy.anon-server#15997

  copy link   Newsgroups: alt.privacy.anon-server
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!tncsrv06.tnetconsulting.net!tncsrv09.home.tnetconsulting.net!.POSTED.198.18.1.140!not-for-mail
From: gtay...@tnetconsulting.net (Grant Taylor)
Newsgroups: alt.privacy.anon-server
Subject: Re: spooled mail for middleman
Date: Mon, 11 Dec 2023 08:52:08 -0600
Organization: TNet Consulting
Message-ID: <ul77mo$66j$1@tncsrv09.home.tnetconsulting.net>
References: <ul4kj3$r0i$1@tncsrv09.home.tnetconsulting.net>
<ul690j$2qjnu$1@paganini.bofh.team>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Mon, 11 Dec 2023 14:52:08 -0000 (UTC)
Injection-Info: tncsrv09.home.tnetconsulting.net; posting-host="198.18.1.140";
logging-data="6355"; mail-complaints-to="newsmaster@tnetconsulting.net"
User-Agent: Mozilla Thunderbird
Content-Language: en-US
In-Reply-To: <ul690j$2qjnu$1@paganini.bofh.team>
 by: Grant Taylor - Mon, 11 Dec 2023 14:52 UTC

On 12/11/23 00:08, Middleman Remailer Administrator wrote:
> My pfSense setup is running Suricata with a whole bunch of newly-enabled
> rules, and it's set to block for 24 hours the source address of any
> communication that triggers an alert. So far, the vast majority of
> alerts have been classified by Suricata as miscellaneous attacks. I've
> suppressed a lot of rules that triggered blocks for protocol related
> errors and software that I use on a regular basis.

I can understand and appreciate that.

I've run into similar with my security systems.

> I have the IP addresses of remailers in a pass list:

I'm getting the impression that something may not be working as desired
/ configured.

> 45.33.28.24

I say that because tncmm (45.33.28.24) is unable to establish a
connection with middleman (108.196.79.212) on TCP port 25, nor is tncmm
able to ping (ICMP) middleman.

% tcpdump -nni eth0 host 45.33.28.24 and host 108.196.79.212 and proto
TCP and port 25
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes
08:46:36.859849 IP 45.33.28.24.51266 > 108.196.79.212.25: Flags [S], seq
1305365682, win 64240, options [mss 1460,sackOK,TS val 1096625498 ecr
0,nop,wscale 7], length 0
08:46:37.863288 IP 45.33.28.24.51266 > 108.196.79.212.25: Flags [S], seq
1305365682, win 64240, options [mss 1460,sackOK,TS val 1096626502 ecr
0,nop,wscale 7], length 0
08:46:39.916627 IP 45.33.28.24.51266 > 108.196.79.212.25: Flags [S], seq
1305365682, win 64240, options [mss 1460,sackOK,TS val 1096628555 ecr
0,nop,wscale 7], length 0
08:46:43.969933 IP 45.33.28.24.51266 > 108.196.79.212.25: Flags [S], seq
1305365682, win 64240, options [mss 1460,sackOK,TS val 1096632608 ecr
0,nop,wscale 7], length 0
08:46:52.076682 IP 45.33.28.24.51266 > 108.196.79.212.25: Flags [S], seq
1305365682, win 64240, options [mss 1460,sackOK,TS val 1096640715 ecr
0,nop,wscale 7], length 0

Here's a trace route:

% traceroute -4 middleman.remailer.online
traceroute to middleman.remailer.online (108.196.79.212), 30 hops max,
60 byte packets
1 * * *
2 * * *
3 * * *
4 * * *
5 lo0-0.gw1.rin1.us.linode.com (45.79.12.101) 0.485 ms
lo0-0.gw2.rin1.us.linode.com (45.79.12.102) 0.403 ms
lo0-0.gw1.rin1.us.linode.com (45.79.12.101) 0.389 ms
6 ae60.r11.dfw01.ien.netarch.akamai.com (23.203.147.38) 1.286 ms
ae62.r12.dfw01.ien.netarch.akamai.com (23.203.147.40) 1.260 ms
ae60.r11.dfw01.ien.netarch.akamai.com (23.203.147.38) 1.290 ms
7 12.127.60.13 (12.127.60.13) 1.967 ms 12.127.229.25 (12.127.229.25)
1.603 ms 12.244.76.17 (12.244.76.17) 1.639 ms
8 * * *
9 * * *
10 * * *
11 * 32.130.17.83 (32.130.17.83) 35.670 ms 35.123 ms
12 12.123.241.213 (12.123.241.213) 33.520 ms 32.130.17.83
(32.130.17.83) 39.654 ms 12.123.241.213 (12.123.241.213) 37.459 ms
13 12.123.241.213 (12.123.241.213) 33.509 ms * 33.444 ms
14 * * *
15 75.26.64.202 (75.26.64.202) 32.932 ms 31.424 ms 32.952 ms
16 71.151.199.75 (71.151.199.75) 32.515 ms * 32.465 ms
17 71.151.199.75 (71.151.199.75) 33.658 ms 31.877 ms *
18 * * *
19 * * *
20 * * *
21 * * *
22 * * *
23 * * *
24 * * *
25 * * *
26 * * *
27 * * *
28 * * *
29 * * *
30 * * *

> This list may very well be out of date,

Possibly. I know that I have to spend a little bit of time caring for
and feeding similar filters on tncmm.

> which is probably why there is a lot of mail queued up on your remailer
> for middleman,

Given that you have a correct IP for tncmm, I don't think that's the
problem this time.

> and also why
> middleman is dropping in the reliability stats. I've been monitoring
> the stats, and I'm continuing to adjust Suricata so that it doesn't
> block the IP addresses that are sending stuff that needs to get through.

I trust that you will get it figured out.

Please let me know if you need any additional data from tncmm or if
there is something I can do to help diagnose, extra tests, etc.

--
Grant. . . .

Re: spooled mail for middleman

<dXLAbVrmiPHJmJkWxLmMRYplrREEmwVx@news.usenet.farm>

  copy mid

https://news.novabbs.com/computers/article-flat.php?id=16011&group=alt.privacy.anon-server#16011

  copy link   Newsgroups: alt.privacy.anon-server
Subject: Re: spooled mail for middleman
Newsgroups: alt.privacy.anon-server
Message-Id: <dXLAbVrmiPHJmJkWxLmMRYplrREEmwVx@news.usenet.farm>
User-Agent: Mozilla Thunderbird
From: adm...@sec3.net (SEC3)
Content-Transfer-Encoding: 7bit
Organization: Usenet.Farm
Mime-Version: 1.0
References: <ul4kj3$r0i$1@tncsrv09.home.tnetconsulting.net> <ul690j$2qjnu$1@paganini.bofh.team>
Content-Language: en-US
In-Reply-To: <ul690j$2qjnu$1@paganini.bofh.team>
Date: Tue, 12 Dec 23 16:11:48 UTC
X-Ufhash: %2B8r5rsWcLkgIVNEIIb1w7EnMNloydCHJZfGSeevKs6Z%2FcgNGZWWFUt2WIq3EqHmJfEn16ZfWI8n5ZpaJihLNFyn%2FuHszjTzExN5kbzdqnLFPrGPSqJBg8Kid9uWUU7%2BTH33M3CnusqaYgKJUD3K0%2BV%2B%2Fk7D8Ci9byhygpuJQDHFk9ojxoAWQ9bl%2BPYIJP74Mz81sUlyg8rZ0Mib6JKwFLwfx41B1BVw%3D
Path: i2pn2.org!i2pn.org!news.neodome.net!news.mixmin.net!newsreader4.netcologne.de!news.netcologne.de!peer01.ams1!peer.ams1.xlned.com!news.xlned.com!peer01.ams4!peer.am4.highwinds-media.com!news.highwinds-media.com!feeder3.usenet.farm!feeder4.usenet.farm!feed.usenet.farm!news.usenet.farm
Content-Type: text/plain; charset=UTF-8; format=flowed
X-Received-Bytes: 1938
 by: SEC3 - Tue, 12 Dec 2023 16:11 UTC

On 12/11/23 01:08, Middleman Remailer Administrator wrote:

> I have the IP addresses of remailers in a pass list:
>
> 2a01:4f8:200:60a6::2
> 2a03:4000:3f:24b:14a1:1eff:fe82:32d1
> 5.181.51.40
> 45.33.28.24
> 45.66.35.221
> 77.1.130.120
> 84.173.194.212
> 88.80.28.20
> 91.228.53.8
> 107.161.26.232
> 144.76.182.167
> 2600:3c00:e000:1e9::8849
>
> This list may very well be out of date, which is probably why there is
> a lot of mail queued up on your remailer for middleman, and also why
> middleman is dropping in the reliability stats. I've been monitoring
> the stats, and I'm continuing to adjust Suricata so that it doesn't
> block the IP addresses that are sending stuff that needs to get through.

Please whitelist my Shalo mixmaster remailer:
2.58.15.73
2a07:efc0:1001:a213::91

And my SEC3 pinger:
168.235.85.79
2604:180:f4::12b

--
SEC3

YAMN Help Tutorial - https://www.sec3.net/yamnhelp/

Re: spooled mail for middleman

<lCNggNPtrZYGvkaUnoQDOToEtWpPNDrQ@news.usenet.farm>

  copy mid

https://news.novabbs.com/computers/article-flat.php?id=16012&group=alt.privacy.anon-server#16012

  copy link   Newsgroups: alt.privacy.anon-server
User-Agent: Mozilla Thunderbird
Content-Language: en-US
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!newsreader4.netcologne.de!news.netcologne.de!peer01.ams1!peer.ams1.xlned.com!news.xlned.com!peer01.ams4!peer.am4.highwinds-media.com!news.highwinds-media.com!feeder3.usenet.farm!feeder4.usenet.farm!feed.usenet.farm!news.usenet.farm
Newsgroups: alt.privacy.anon-server
In-Reply-To: <dXLAbVrmiPHJmJkWxLmMRYplrREEmwVx@news.usenet.farm>
Message-Id: <lCNggNPtrZYGvkaUnoQDOToEtWpPNDrQ@news.usenet.farm>
From: adm...@sec3.net (SEC3)
Content-Type: text/plain; charset=UTF-8; format=flowed
X-Ufhash: jvbcAb1eUBfa2M7LwlWaXStcmhyneouU9VGy5WAiW%2BbyxqQ6aqTqsLLpAUnkHnO0sRvJkWvtjQIzBPg8Q%2FXEMSrAXZZOmqOPPP5f4OdmRGUwsj7rr12f4O6WhKeuZZz9uBdebCXaC85fNSIEhkdARfDppQyWDUFeIY3uSipPRiWsMiBOMgGWsSFVZPIaftdyKDqGEaX9v4Nh9wmeieNT1CkqTWI40bc%3D
Organization: Usenet.Farm
Date: Tue, 12 Dec 23 16:36:02 UTC
Mime-Version: 1.0
Subject: Re: spooled mail for middleman
References: <ul4kj3$r0i$1@tncsrv09.home.tnetconsulting.net> <ul690j$2qjnu$1@paganini.bofh.team> <dXLAbVrmiPHJmJkWxLmMRYplrREEmwVx@news.usenet.farm>
Content-Transfer-Encoding: 7bit
X-Received-Bytes: 1657
 by: SEC3 - Tue, 12 Dec 2023 16:36 UTC

On 12/12/23 11:11, SEC3 wrote:
> On 12/11/23 01:08, Middleman Remailer Administrator wrote:
>
> > I have the IP addresses of remailers in a pass list:
> >
> > 2a01:4f8:200:60a6::2
> > 2a03:4000:3f:24b:14a1:1eff:fe82:32d1
> > 5.181.51.40
> > 45.33.28.24
> > 45.66.35.221
> > 77.1.130.120
> > 84.173.194.212
> > 88.80.28.20
> > 91.228.53.8
> > 107.161.26.232
> > 144.76.182.167
> > 2600:3c00:e000:1e9::8849

Also missing from this list is Beaufusil, a fairly new mixmaster remailer:

45.86.163.116
2001:1608:1b:7b5::18

--
SEC3

YAMN Help Tutorial - https://www.sec3.net/yamnhelp/

Re: spooled mail for middleman

<20231212.202602.015440a1@mixmin.net>

  copy mid

https://news.novabbs.com/computers/article-flat.php?id=16016&group=alt.privacy.anon-server#16016

  copy link   Newsgroups: alt.privacy.anon-server
References: <ul4kj3$r0i$1@tncsrv09.home.tnetconsulting.net>
<ul690j$2qjnu$1@paganini.bofh.team>
<dXLAbVrmiPHJmJkWxLmMRYplrREEmwVx@news.usenet.farm>
Subject: Re: spooled mail for middleman
Message-Id: <20231212.202602.015440a1@mixmin.net>
Date: Tue, 12 Dec 2023 20:26:02 +0000
From: nore...@mixmin.net (Conan)
Newsgroups: alt.privacy.anon-server
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!news.mixmin.net!news2.arglkargh.de!sewer!news.dizum.net!not-for-mail
Organization: dizum.com - The Internet Problem Provider
X-Abuse: abuse@dizum.com
Injection-Info: sewer.dizum.com - 2001::1/128
 by: Conan - Tue, 12 Dec 2023 20:26 UTC

>
> On 12/12/23 11:11, SEC3 wrote:
>> On 12/11/23 01:08, Middleman Remailer Administrator wrote:
>>
>> > I have the IP addresses of remailers in a pass list:
>> >
>> > 2a01:4f8:200:60a6::2
>> > 2a03:4000:3f:24b:14a1:1eff:fe82:32d1
>> > 5.181.51.40
>> > 45.33.28.24
>> > 45.66.35.221
>> > 77.1.130.120
>> > 84.173.194.212
>> > 88.80.28.20
>> > 91.228.53.8
>> > 107.161.26.232
>> > 144.76.182.167
>> > 2600:3c00:e000:1e9::8849
>
> Also missing from this list is Beaufusil, a fairly new mixmaster
remailer:
>
> 45.86.163.116
> 2001:1608:1b:7b5::18
>
> --
> SEC3
>
> YAMN Help Tutorial - https://www.sec3.net/yamnhelp/
>

trial 2


computers / alt.privacy.anon-server / Re: spooled mail for middleman

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor