=head1 NAME check_earlytalker - Check that the client doesn't talk before we send the SMTP banner =head1 DESCRIPTION Checks to see if the remote host starts talking before we've issued a 2xx greeting. If so, we're likely looking at a direct-to-MX spam agent which pipelines its entire SMTP conversation, and will happily dump an entire spam into our mail log even if later tests deny acceptance. Depending on configuration, clients which behave in this way are either immediately disconnected with a deny or denysoft code, or else are issued this on all mail/rcpt commands in the transaction. =head1 CONFIGURATION =over 4 =item wait [integer] The number of seconds to delay the initial greeting to see if the connecting host speaks first. The default is 1. =item action [string: deny, denysoft, log] What to do when matching an early-talker -- the options are I, I or I. If I is specified, the connection will be allowed to proceed as normal, and only a warning will be logged. The default is I. =item defer-reject [boolean] When an early-talker is detected, if this option is set to a true value, the SMTP greeting will be issued as usual, but all RCPT/MAIL commands will be issued a deny or denysoft (depending on the value of I). The default is to react at the SMTP greeting stage by issuing the apropriate response code and terminating the SMTP connection. =back =cut sub register { my ($self, $qp, @args) = @_; if (@args % 2) { $self->log(LOGERROR, "Unrecognized/mismatched arguments"); return undef; } $self->{_args} = { 'wait' => 1, 'action' => 'denysoft', 'defer-reject' => 0, @args, }; $self->register_hook('connect', 'connect_handler'); $self->register_hook('connect', 'connect_post_handler'); $self->register_hook('mail', 'mail_handler') if $self->{_args}->{'defer-reject'}; warn("check_earlytalker registered\n"); 1; } sub connect_handler { my ($self, $transaction) = @_; warn("check early talker"); my $qp = $self->qp; my $conn = $qp->connection; $qp->AddTimer($self->{_args}{'wait'}, sub { read_now($qp, $conn) }); $qp->disable_read(); return CONTINUATION; } sub read_now { my ($qp, $conn) = @_; warn("read now"); $qp->enable_read(); if (my $data = $qp->read(1024)) { if (length($$data)) { $qp->log(LOGNOTICE, 'remote host started talking before we said hello'); $qp->push_back_read($data); $conn->notes('earlytalker', 1); } } $qp->finish_continuation; } sub connect_post_handler { my ($self, $transaction) = @_; my $conn = $self->qp->connection; return DECLINED unless $conn->notes('earlytalker'); return DECLINED if $self->{'defer-reject'}; my $msg = 'Connecting host started transmitting before SMTP greeting'; return (DENY,$msg) if $self->{_args}->{'action'} eq 'deny'; return (DENYSOFT,$msg) if $self->{_args}->{'action'} eq 'denysoft'; return DECLINED; # assume action eq 'log' } sub mail_handler { my ($self, $txn) = @_; my $msg = 'Connecting host started transmitting before SMTP greeting'; return DECLINED unless $self->connection->notes('earlytalker'); my $msg = 'Connecting host started transmitting before SMTP greeting'; return (DENY,$msg) if $self->{_args}->{'action'} eq 'deny'; return (DENYSOFT,$msg) if $self->{_args}->{'action'} eq 'denysoft'; return DECLINED; } 1;