cyberdefenders / email-header-analyzer

E-Mail Header Analyzer
https://mailheaderanalyzer.herokuapp.com/
Other
638 stars 158 forks source link

Errors out depending on the source of the headers... #13

Closed smartsurfer closed 5 years ago

smartsurfer commented 5 years ago

We receive the following error depending on the source of the headers.

"Internal Server Error The server encountered an internal error and was unable to complete your request. Either the server is overloaded or there is an error in the application."

---sample headers--- X-auditid:
a2962c47-fbdff7000001abb1-0a-5c5ca11b80de Received:
from COPDCEXC36.sampledomain.com (copdcmhoutvip.sampledomain.com [96.114.156.147]) (using TLS with cipher AES256-SHA256 (256/256 bits)) (Client did not present a certificate) by copdcmhout01.sampledomain.com (SMTP Gateway) with SMTP id 63.58.43953.B11AC5C5; Thu, 7 Feb 2019 14:20:27 -0700 (MST) Received:
from COPDCEX49.sampledomain.com (147.191.125.148) by COPDCEXC36.sampledomain.com (147.191.125.135) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1466.3; Thu, 7 Feb 2019 16:20:25 -0500 Received:
from feye-as-01p.sys.sampledomain.net (96.114.156.9) by COPDCEX49.sampledomain.com (147.191.125.148) with Microsoft SMTP Server (TLS) id 15.0.1395.4 via Frontend Transport; Thu, 7 Feb 2019 14:20:25 -0700 Received:
from localhost.localdomain (localhost [127.0.0.1]) by feye-as-01p.sys.sampledomain.net (Postfix) with SMTP id 43wWS86WCNz4PWS8 for prd_loop_mx10@sampledomain.com; Thu, 7 Feb 2019 16:20:24 -0500 (EST) Received:
from agari-as-02p.sys.sampledomain.net (ssl01-d-ssl02-d-snatip-254.richmond.va.ndcasbn.sampledomain.net [96.115.73.254]) by feye-as-01p.sys.sampledomain.net (Postfix) with ESMTPS id 43wWS80sd8z4PWDt for prd_loop_mx10@sampledomain.com; Thu, 7 Feb 2019 16:20:24 -0500 (EST) Received:
from fe72fab91eba (localhost [127.0.0.1]) by agari-as-02p.sys.sampledomain.net (Postfix) with ESMTP id 43wWS80qfvz4PXx1 for prd_loop_mx10@sampledomain.com; Thu, 7 Feb 2019 21:20:24 +0000 (UTC) Received:
from copdcmhin01.sampledomain.com (ssl01-d-ssl02-d-snatip-254.richmond.va.ndcasbn.sampledomain.net [96.115.73.254]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by agari-as-02p.sys.sampledomain.net (Postfix) with ESMTPS id 43wWS66ctTz4PXwn for prd_loop_mx10@sampledomain.com; Thu, 7 Feb 2019 21:20:22 +0000 (UTC) X-auditid:
a2962c44-a1bff7000000144d-61-5c5ca1176d6d Received:
from ert.monitis.com (ert.monitis.com [104.200.159.178]) by copdcmhin01.sampledomain.com (SMTP Gateway) with SMTP id 33.C7.05197.711AC5C5; Thu, 7 Feb 2019 14:20:23 -0700 (MST) Content-type:
text/plain; charset="us-ascii" Mime-version:
1.0 Content-transfer-encoding:
7bit X-fireeye:
Clean Message-id: 154957442264.2124.9970859388360246654.1549574422.65@ert.monitis.com X-params:
MTM4ODUwMzR8MTU0OTU3NDQyMi42MXwxNTQ5NTc0NDIyLjY1fDE2Mi4xNTAuNDQuNjg= Authentication-results: comcast.com; spf=neutral smtp.mailfrom=ert@ert.monitis.com smtp.helo=ert.monitis.com; dkim=none X-brightmail-tracker:
H4sIAAAAAAAAA+NgFrrMKsWRmVeSWpSXmKPExsWSUDRnsq70wpgYg1PvpSxebXrH7MDoseHd FvYAxqgGRpuSjKLUxBKX1LTUvOJUOy4FDGCTlJqWX5TqmliUUxmUmpOaiF0ZSGVKak5mWWqR PlZj9LGak7CPKePa1kMsBe4VBzaINzBadjFyckgImEjM+7SNuYuRi0NIYBeTxO6XR6CcJiaJ /l2LmSCcq4wSM05NYgVpERI4xyjRftQEItHNJHH3dBcjhHOcUeLgyansEM4fJomOie/ZYbY8 /3sUqmo/o8S3q30sIAlmAR2JBbs/sYHYvAKCEidnPoGKy0tsfzuHGcQWEdCUuHD4NjPEIAGJ 6/OWgA1lA+r9Oms6C0RvoMT+zevA7mMRUJHoWrWHEaLeT2Lbpn4wW1ggWeLMq7VgNqNApcSL TctYQQ6SEFjJIdE68R7UpYISDzavgFrmIPFv/WOoQRISL+6sgQaAgsSic3fYIOLiEoeP7GCd wCg9C8k/s5D8MwvJPwsYmVcx8hqaGekZmhromZjomRtuYgSmnEXTdNx3MH44H3uIUYCDUYmH V3x6TIwQa2JZcWXuIUYJDmYlEd4Vc4FCvCmJlVWpRfnxRaU5qcWHGH2A3p3ILCWanA9Mh3kl 8YamJuYGZhbmhqbmJkY4hJXEeT9ERscICaQnlqRmp6YWpBbBjGPi4JRqYFwmlxOyd9GVPUvv 6gtM5CwX2XpRLkNp+2JlmWojf6MijcYTCSfkYq8XrN1xNXTn4StOWXUaATyVL3bzt8RVn7rW czchMj8jk7txbp/Zr8gpApNEWy5uqtbs15cP+yo8o5DbfHU+x+uibbOCHRku+x72FNzYWu+z tuBQ0ulTj0V3pKQ/2pXTrsRSnJFoqMVcVJwIAGHjCx5mAwAA X-brightmail-tracker:
H4sIAAAAAAAAA+NgFprLJsWRWlGSWpSXmKPExsWScWL+Jl3xhTExBi+6JS0un3zE4sDocb2z hTmAMaqB0SYlNSezLLVI384mqbIgsbhYNzlNoSA/JzO5UjczxVbJ0MTSxMzE1MjMxNLcUgmo ilT1JRlFqYklLqlpqXnFqXZcCmggYS5LxpJpS1kKPCsObBBvYLTsYuTkkBAwkXj+9ygjiC0k sJdRYmkbN4jNLKAjsWD3JzYQm1dAUOLkzCcsEHF5ie1v5zCD2CICmhIXDt8Gs9mA6r/Oms4C UR8osX/zOlYQm0VAVWJCbwsbxC4/iW2b+sF2CQtESFzc8pcdxGYUqJR4sWkZ6wRGnllIVs9C snoWktULGJlXMfIamhnpGZoa6JmY6JlZbGIEhv6iaTouOxg/XIk9xCjAwajEw5sxPSZGiDWx rLgy9xCjBAezkgjvirlAId6UxMqq1KL8+KLSnNTiQ4zJQFdOZJYSTc7PK0nNK4k3NDUysjQ1 NDIyMzA2QBI2sTQzMrOwtDQ2NLZEUW1pbGJiYGFpZG6qJM6rFxUdIySQnliSmp2aWpBaBLOF iYMdRHCeYpzOKCXO+34+0CUCxQWJuRmlQIOgyqTEeG80AyX4kSSSSnOypWR49bdHxgiJIonn pZYX56SWAJlSCryH5wJtlUSSLS4tLshMzswvLY4vLcoB6j88PRpVf3FpUm5mcXFmfh4s7V5i 9OFg4mAR4imuLI5PzMnJL4/PLAC6Bc5LzU3MzBFiycvPS4WQUsK8jAwMDEI8QI/mZpZAPAEz TqqBMWTHVjZJwzfBEvOa5I3dI47v+DG7KWrHDcFChqUCM7Y+eSfL9CQk0Dt/7QFhQ5OjNz64 Hf70onCy0bvzxbfDO2+sKBDfH+e1eckENTZx8fV71ynILUt0jleru3vGvvbIJXahjtMvc7Jn tG4oTE48M5FN+lRcR/5XBpnaS61WDVpBFoWZF7zXKLEUZyQaajEXFScCANNPFsmwAwAA X-auditstamp:
Yes X-agari-msginfo:
2dcc0248-2b1e-11e9-aa60-0242ac140003;1549574422 X-agari-trust-score:
7.7 Return-path:
ert@ert.monitis.com X-cfilter-loop: Forward X-bmiincident:
10000015,1547068715742,0 X-bmimatch: 10000015,1547068715742,header,To,PRD_LOOP_MX10@sampledomain.com X-bmi-source:
internal To: Recipient PRD_LOOP_MX10@sampledomain.com From:
Email Round-Trip ert@ert.monitis.com Date:
Thursday, Feb 07, 2019 04:20:22 PM EST Subject:
[EXTERNAL] ERT test~MTM4ODUwMzR8MTU0OTU3NDQyMi42MXwxNTQ5NTc0NDIyLjY1fDE2Mi4xNTAuNDQuNjg=

lnxg33k commented 5 years ago

@smartsurfer please upload the raw header to https://pastebin.com to investigate the issue

lnxg33k commented 5 years ago

It seems to work fine for me image