Code: Select all
250 2.1.0 Flushed 35si6742153wra
250 2.0.0 OK 1173624242 35si6742153wra
Same for the 2 values after "OK" ?
Thank you.
Code: Select all
250 2.1.0 Flushed 35si6742153wra
250 2.0.0 OK 1173624242 35si6742153wra

The first value is a UNIX timestamp: 1173624242 -> Sun, 11 Mar 2007 14:44:02 GMT. Can't help you with the second, but your SMTP server's documentation will probably explain the details logged for the 200, 210 and/or 250 error codes.Bornio wrote:I intercepted this from a trojan that infected me, and I am not exactly sure what this means.Does anybody know what ... the 2 values after "OK" [mean]?Code: Select all
250 2.0.0 OK 1173624242 35si6742153wra
Code: Select all
220 smtp.google.com ESMTP
ehlo bla.com
250-smtp.google.com Hello
250-ENHANCEDSTATUSCODES
250-PIPELINING
250-8BITMIME
250-SIZE 20000000
250-STARTTLS
250-DELIVERBY
250 HELP

Bornio wrote:That sniffed traffic is from a trojan, which once I got infected it sends some stuff to some gmail account. the sniffer showed that, while i was (clearly) hoping to get the clear text password.