今天tail -f /var/log/maillog 发现,不停的在产生记录,不停地往外发邮件。
通过log文件中的一条记录,取得其中的一条任务id:39E46C6D4B
使用postcat -q 39E46C6D4B获取到详细信息,如下:
1 *** ENVELOPE RECORDS active/39E46C6D4B *** 2 message_size: 1458 4815 50 0 1458 3 message_arrival_time: Thu Oct 6 20:34:49 2016 4 create_time: Thu Oct 6 20:34:49 2016 5 named_attribute: log_ident=39E46C6D4B 6 named_attribute: rewrite_context=remote 7 named_attribute: sasl_method=LOGIN 8 named_attribute: sasl_username=test@test.com #被破解的stmp账号 9 sender: petermhmith@comcast.net #伪造的发件人 10 named_attribute: log_client_name=unknown 11 named_attribute: log_client_address=52.175.17.187 #入侵者ip,我就不隐藏了 12 named_attribute: log_client_port=61991 13 named_attribute: log_message_origin=unknown[52.175.17.187] 14 named_attribute: log_helo_name=User 15 named_attribute: log_protocol_name=ESMTP 16 named_attribute: client_name=unknown 17 named_attribute: reverse_client_name=unknown 18 named_attribute: client_address=52.175.17.187 19 named_attribute: client_port=61991 20 named_attribute: helo_name=User 21 named_attribute: protocol_name=ESMTP 22 named_attribute: client_address_type=2 23 named_attribute: dsn_orig_rcpt=rfc822;rads60@aol.com 24 original_recipient: rads60@aol.com 25 recipient: rads60@aol.com 26 named_attribute: dsn_orig_rcpt=rfc822;radsal@yahoo.com 27 original_recipient: radsal@yahoo.com #一大群收件人 28 recipient: radsal@yahoo.com 29 named_attribute: dsn_orig_rcpt=rfc822;radsar562@aol.com 30 original_recipient: radsar562@aol.com 31 recipient: radsar562@aol.com 32 named_attribute: dsn_orig_rcpt=rfc822;radscrapbookz@yahoo.com 33 original_recipient: radscrapbookz@yahoo.com 34 recipient: radscrapbookz@yahoo.com 35 named_attribute: dsn_orig_rcpt=rfc822;radscream@cox.net 36 original_recipient: radscream@cox.net 37 recipient: radscream@cox.net 38 named_attribute: dsn_orig_rcpt=rfc822;radsk84mad@gmail.com 39 original_recipient: radsk84mad@gmail.com 40 done_recipient: radsk84mad@gmail.com 41 named_attribute: dsn_orig_rcpt=rfc822;radskadork@aol.com 42 original_recipient: radskadork@aol.com 43 recipient: radskadork@aol.com 44 named_attribute: dsn_orig_rcpt=rfc822;radsmomma@aol.com 45 original_recipient: radsmomma@aol.com 46 recipient: radsmomma@aol.com 47 named_attribute: dsn_orig_rcpt=rfc822;radsmsm27@aol.com 48 original_recipient: radsmsm27@aol.com 49 recipient: radsmsm27@aol.com 50 named_attribute: dsn_orig_rcpt=rfc822;radsosa@sbcglobal.net 51 original_recipient: radsosa@sbcglobal.net 52 done_recipient: radsosa@sbcglobal.net 53 named_attribute: dsn_orig_rcpt=rfc822;radsoudi@yahoo.com 54 original_recipient: radsoudi@yahoo.com 55 recipient: radsoudi@yahoo.com 56 named_attribute: dsn_orig_rcpt=rfc822;radstang89@yahoo.com 57 original_recipient: radstang89@yahoo.com 58 recipient: radstang89@yahoo.com 59 named_attribute: dsn_orig_rcpt=rfc822;radstyle@yahoo.com 60 original_recipient: radstyle@yahoo.com 61 recipient: radstyle@yahoo.com 62 named_attribute: dsn_orig_rcpt=rfc822;radsxegrl21@yahoo.com 63 original_recipient: radsxegrl21@yahoo.com 64 recipient: radsxegrl21@yahoo.com 65 named_attribute: dsn_orig_rcpt=rfc822;radsyscorp@worldnet.att.net 66 original_recipient: radsyscorp@worldnet.att.net 67 done_recipient: radsyscorp@worldnet.att.net 68 named_attribute: dsn_orig_rcpt=rfc822;radtad44@msn.com 69 original_recipient: radtad44@msn.com 70 done_recipient: radtad44@msn.com 71 named_attribute: dsn_orig_rcpt=rfc822;radtad90@yahoo.com 72 original_recipient: radtad90@yahoo.com 73 recipient: radtad90@yahoo.com 74 named_attribute: dsn_orig_rcpt=rfc822;radtadd@hotmail.com 75 original_recipient: radtadd@hotmail.com 76 done_recipient: radtadd@hotmail.com 77 named_attribute: dsn_orig_rcpt=rfc822;radtanline@aol.com 78 original_recipient: radtanline@aol.com 79 recipient: radtanline@aol.com 80 named_attribute: dsn_orig_rcpt=rfc822;radtaz77@yahoo.com 81 original_recipient: radtaz77@yahoo.com 82 recipient: radtaz77@yahoo.com 83 named_attribute: dsn_orig_rcpt=rfc822;radtec@hotmail.com 84 original_recipient: radtec@hotmail.com 85 done_recipient: radtec@hotmail.com 86 named_attribute: dsn_orig_rcpt=rfc822;radtechmay@earthlink.com 87 original_recipient: radtechmay@earthlink.com 88 done_recipient: radtechmay@earthlink.com 89 named_attribute: dsn_orig_rcpt=rfc822;radtek53@aol.com 90 original_recipient: radtek53@aol.com 91 recipient: radtek53@aol.com 92 named_attribute: dsn_orig_rcpt=rfc822;radtke@juno.com 93 original_recipient: radtke@juno.com 94 recipient: radtke@juno.com 95 named_attribute: dsn_orig_rcpt=rfc822;radtke1@worldnet.att.net 96 original_recipient: radtke1@worldnet.att.net 97 done_recipient: radtke1@worldnet.att.net 98 named_attribute: dsn_orig_rcpt=rfc822;radtogo2@aol.com 99 original_recipient: radtogo2@aol.com 100 recipient: radtogo2@aol.com 101 named_attribute: dsn_orig_rcpt=rfc822;radtoys@aol.com 102 original_recipient: radtoys@aol.com 103 recipient: radtoys@aol.com 104 named_attribute: dsn_orig_rcpt=rfc822;radtrans05@yahoo.com 105 original_recipient: radtrans05@yahoo.com 106 recipient: radtrans05@yahoo.com 107 named_attribute: dsn_orig_rcpt=rfc822;radu.oancea@onsaleonline.com 108 original_recipient: radu.oancea@onsaleonline.com 109 done_recipient: radu.oancea@onsaleonline.com 110 named_attribute: dsn_orig_rcpt=rfc822;radu@op.net 111 original_recipient: radu@op.net 112 recipient: radu@op.net 113 named_attribute: dsn_orig_rcpt=rfc822;radu_henegar@yahoo.com 114 original_recipient: radu_henegar@yahoo.com 115 recipient: radu_henegar@yahoo.com 116 named_attribute: dsn_orig_rcpt=rfc822;radu_rengle@yahoo.com 117 original_recipient: radu_rengle@yahoo.com 118 recipient: radu_rengle@yahoo.com 119 named_attribute: dsn_orig_rcpt=rfc822;radu123@hotmail.com 120 original_recipient: radu123@hotmail.com 121 done_recipient: radu123@hotmail.com 122 named_attribute: dsn_orig_rcpt=rfc822;raduariton@yahoo.com 123 original_recipient: raduariton@yahoo.com 124 recipient: raduariton@yahoo.com 125 named_attribute: dsn_orig_rcpt=rfc822;raducerbu@worldnet.att.net 126 original_recipient: raducerbu@worldnet.att.net 127 done_recipient: raducerbu@worldnet.att.net 128 named_attribute: dsn_orig_rcpt=rfc822;raducristian30@yahoo.com 129 original_recipient: raducristian30@yahoo.com 130 recipient: raducristian30@yahoo.com 131 named_attribute: dsn_orig_rcpt=rfc822;radue77@hotmail.com 132 original_recipient: radue77@hotmail.com 133 done_recipient: radue77@hotmail.com 134 named_attribute: dsn_orig_rcpt=rfc822;radum94@hotmail.com 135 original_recipient: radum94@hotmail.com 136 done_recipient: radum94@hotmail.com 137 named_attribute: dsn_orig_rcpt=rfc822;radumond@aol.com 138 original_recipient: radumond@aol.com 139 recipient: radumond@aol.com 140 named_attribute: dsn_orig_rcpt=rfc822;radumps@gmail.com 141 original_recipient: radumps@gmail.com 142 recipient: radumps@gmail.com 143 named_attribute: dsn_orig_rcpt=rfc822;rae_lbc@yahoo.com 144 original_recipient: rae_lbc@yahoo.com 145 recipient: rae_lbc@yahoo.com 146 named_attribute: dsn_orig_rcpt=rfc822;rae_liu2002@yahoo.com 147 original_recipient: rae_liu2002@yahoo.com 148 recipient: rae_liu2002@yahoo.com 149 named_attribute: dsn_orig_rcpt=rfc822;rae_lynnette@hotmail.com 150 original_recipient: rae_lynnette@hotmail.com 151 done_recipient: rae_lynnette@hotmail.com 152 named_attribute: dsn_orig_rcpt=rfc822;rae_of_sunlight@hotmail.com 153 original_recipient: rae_of_sunlight@hotmail.com 154 done_recipient: rae_of_sunlight@hotmail.com 155 named_attribute: dsn_orig_rcpt=rfc822;rae_rae33@hotmail.com 156 original_recipient: rae_rae33@hotmail.com 157 done_recipient: rae_rae33@hotmail.com 158 named_attribute: dsn_orig_rcpt=rfc822;rae_scheer@yahoo.com 159 original_recipient: rae_scheer@yahoo.com 160 recipient: rae_scheer@yahoo.com 161 named_attribute: dsn_orig_rcpt=rfc822;rae090785@yahoo.com 162 original_recipient: rae090785@yahoo.com 163 recipient: rae090785@yahoo.com 164 named_attribute: dsn_orig_rcpt=rfc822;rae0fsun23@hotmail.com 165 original_recipient: rae0fsun23@hotmail.com 166 done_recipient: rae0fsun23@hotmail.com 167 named_attribute: dsn_orig_rcpt=rfc822;rae11455@aol.com 168 original_recipient: rae11455@aol.com 169 recipient: rae11455@aol.com 170 named_attribute: dsn_orig_rcpt=rfc822;rae12@aol.com 171 original_recipient: rae12@aol.com 172 recipient: rae12@aol.com 173 *** MESSAGE CONTENTS active/39E46C6D4B *** 174 Received: from User (unknown [52.175.17.187]) 175 by mail.lejucd.com (Postfix) with ESMTPA id 39E46C6D4B; 176 Thu, 6 Oct 2016 20:34:49 +0800 (CST) 177 Reply-To: <petermm111@1email.eu> 178 From: "Mr. Hikmet"<petermhmith@comcast.net> 179 Subject: <<WESTERN UNION COMPENSATION > 180 Date: Thu, 6 Oct 2016 12:34:49 -0000 181 MIME-Version: 1.0 182 Content-Type: text/html; 183 charset="Windows-1251" 184 Content-Transfer-Encoding: 7bit 185 X-Priority: 3 186 X-MSMail-Priority: Normal 187 X-Mailer: Microsoft Outlook Express 6.00.2600.0000 188 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000 189 #一篇诈骗邮件,翻译过来大致就是说要退款,然后来联系进行诈骗 190 <p>Attn:<br /><br />We are writing you from the desk of Mr. Hikmet Ersek, Chief<br />Executive Officer and President of The Western Union<br />Company,this letter is to notify you about your compensation<br />as one of the scam victim that sent money via our<br />service(Western Union Money Transfer)and (Money Gram) to<br />fraudsters.<br /><br />We found your email Address in our data base,that is why we<br />are contacting you.This have been agreed upon and have been<br />approved by Pamela H. Patsley Chief Executive Officer of<br />Money gram International Inc to compensate you as one of the<br />scam victim.<br /><br />You are here by advised to acknowledge this mail and help us<br />to reconfirm your identity for security reasons.<br /><br />Kindly acknowledge the receipt of this email as soon<br />as you receive it.<br /><br />Yours faithfully,<br />Mr. Hikmet Ersek,</p> 191 *** HEADER EXTRACTED active/39E46C6D4B *** 192 *** MESSAGE FILE END active/39E46C6D4B ***
从详细信息中我们看到,stmp中的test账号被破解了,使用test账号登录之后伪造成其他发件人不断向大量的收件人发送诈骗邮件,登录者的ip是 52.175.17.187 ,查看其他任务id,得到的依然是此结果。
解决:
1.将此ip拉入服务器黑名单:iptables -I INPUT -s 52.175.17.187 -j DROP (要解封使用 :iptables -D INPUT -s 52.175.17.187 -j DROP )
2.删除stmp中test账号并重启postfix:
saslpasswd2 -d test@test.com
service postfix reload
3.清除所有缓存垃圾邮件,阻止邮件服务器继续偿试外发
查看邮件缓存目录:du -sh /var/spool/postfix/*
1.1G /var/spool/postfix/defer
1.7G /var/spool/postfix/deferred
延迟发送的邮件占用了2.8个g的空间!
清除邮件中的所有队列:postsuper -d ALL
再次查看缓存目录,容量终于恢复正常值。
du -sh /var/spool/postfix/*
4K /var/spool/postfix/defer
4K /var/spool/postfix/deferred
4.禁止认证用户假冒发信人外发
vim /etc/postfix/main.cf
mynetworks = 127.0.0.0/8
smtpd_sender_restrictions =
permit_mynetworks,
reject_sender_login_mismatch,
reject_non_fqdn_sender,
reject_authenticated_sender_login_mismatch,
reject_unauthenticated_sender_login_mismatch,
reject_non_fqdn_recipient,
reject_invalid_hostname,
reject_unknown_sender_domain,
check_sender_access hash:/etc/postfix/sender_access
postfix reload
参考原文地址:http://www.51itstudy.com/34465.html
感谢此文章帮我解决问题。