Class
- Tip&Tech
| [¼¹ö¿î¿µ] Sendmail ·Î±×ºÐ¼® ½ºÆÔ ŽÁö °ü·Ã »ðÁú | |||||
| ±Û¾´ÀÌ | ³¯ Â¥ | 11-12-02 18:39 | Á¶ ȸ | 2932 | |
|---|---|---|---|---|---|
| °£ÆíURL |
http://www.phpschool.com/link/tipntech/74657
|
||||
|
################################################################3
### ¾´°Í : Sendmail ·Î±×ºÐ¼® ½ºÆÔ ŽÁö °ü·Ã »ðÁú ### ¾´ÀÌ : ±Ç¼ºÀç(nonots@hanmail.net, http://www.badaweb.co.kr) ### ¾´¶§ : 2011-12-02 ################################################################3 1. °³¿ä ¼¹ö°ü¸®Àڵ鿡°Ô ÀÖ¾î¼ ½ºÆÔ¸ÞÀÏ º¸³»´Â Àΰ£µéÀº ¶§·ÁÁ×ÀÌ°í ½ÍÀº Ãæµ¿À» ºÒ·¯ÀÏÀ¸Åµ´Ï´Ù. ´Ù¸¥ ÇØÅ·°ú ´Þ¸® ½ºÆÔ°ø°ÝÇÏ´Â °Ç ·Î±×ºÐ¼®Çؼ ã±âµµ, ¸·±âµµ ¾î·Æ½À´Ï´Ù. ´õ±¸³ª, ¸¹Àº ½ºÆÔÀÌ ÇѸÞÀÏÀ̳ª ³×À̹ö,±¸±Û ¸ÞÀϼ¹ö·Î º¸³»Áö´Ù º¸´Ï, ÇѸÞÀÏÀ̳ª ³×À̹ö ¸ÞÀϼ¹ö Ãø¿¡¼ ¸ÖÂÄÇÑ ¸ÞÀϼ¹ö ip ¸¦ Â÷´ÜÇØ¼ ¼±·®ÇÑ ÀÏ¹Ý ¸ÞÀÏ »ç¿ëÀÚµéÀÌ ¸ÞÀÏÀÌ ¹ß¼ÛµÇÁö ¾Ê¾Æ ÇÇÇØ¸¦ ÀÔ½À´Ï´Ù. ¾Æ·¡¿¡, ¸®´ª½º ¼¹ö¿¡¼ sendmail µ¥¸ó °ü·ÃÇØ¼ »ðÁúÇÏ¸é¼ ¾Ë°Ô µÈ Á¤º¸¸¦ °ø°³ÇÕ´Ï´Ù. ÇãÁ¢ÇÕ´Ï´Ù¸¸, ³ªº¸´Ù ´õ ÇãÁ¢ÇÑ °ü¸®Àڵ鿡°Ô Á¶±ÝÀ̳ª¸¶ µµ¿òÀÌ µÇ¾úÀ¸¸é ÇÕ´Ï´Ù. 2. ¼¹öȯ°æ - OS : CentOs 5.x (·¹µåÇÞ °è¿) - Sendmail ¹öÀü : 12.x, 13.x - POP3 µ¥¸ó : dovecot, qpopper µî - ¸ÞÀÏ ·Î±× ÆÄÀÏ : /var/log/maillog 3. À¥¼Ò½º ÅëÇÑ ½ºÆÔ ¹ß¼Û °ü·Ã - ±×´©º¸µå³ª Á¦·Îº¸µåµî À¥»çÀÌÆ® °Ô½ÃÆÇÀÇ Ã·ºÎÆÄÀÏ ¾÷·Îµå ±â´ÉÀÇ ÇêÁ¡À» ÀÌ¿ëÇØ¼ ¼¹ö¿¡ .php °°Àº ½ÇÇàÆÄÀÏÀ» ÀúÀåÇÑ ÈÄ ¿ÜºÎ¿¡¼ ÀÌ ÆÄÀÏÀ» ÅëÇØ¼ ½ºÆÔÀ» ¹ß¼ÛÇÏ´Â ¹æ¹ýÀÔ´Ï´Ù. ¹®Á¦´Â, ÀÌ·¸°Ô À¥°æ·Î¿¡ ¾÷·ÎµåÇÑ ÈÄ ½ºÆÔ¸ÞÀÏÀ» º¸³»¸é ÇØ´ç ¼¹ö¿¡ ÀÖ´Â sendmail ·Î±×¿¡ Àß ±â·ÏÀÌ ¾ÈµË´Ï´Ù. php ¸ðµâÀÌ À¥¼¹ö±ÇÇÑÀ» ÀÌ¿ëÇØ¼ ¸·¹Ù·Î º¸³»¹Ç·Î ƯÁ¤ »ç¿ëÀÚ °èÁ¤À» ¾Ë¼ö°¡ ¾ø½À´Ï´Ù. ¶Ç ÇÑ ¿ÜºÎ ¼¹ö¿¡ Æ÷Æ® Á¢¼ÓÇØ¼ ¹ß¼ÛÇÑ´Ù¸é ³»ºÎ ¸ÞÀϼ¹ö¿¡´Â ±â·ÏÀÌ ³²Áö ¾Ê°ÔµË´Ï´Ù. ÀÌ°Ç maillog ºÐ¼®À¸·Î´Â ¾Ë±â¾î·Æ°í, ¹Ýµå½Ã ¹«´ÜÀ¸·Î ¾÷·ÎµåµÈ ÇØÅ· ÆÄÀÏÀ» ã¾Æ¼ »èÁ¦ÇØ¾ß ÇÕ´Ï´Ù. ¿©±â¼´Â °£´ÜÇÑ ¹æ¹ý¸¸ ¼Ò°³ÇÕ´Ï´Ù. ¸¸¾à À¥·ÎÆ®°¡ /home/mywebsite_home/public_html ÀÎ °÷¿¡ ±×´©º¸µå°¡ ¼³Ä¡µÆ°í freeboard ¶ó´Â °Ô½ÃÆÇ¾ÆÀ̵𸦠»ç¿ëÇß´Ù¸é /home/mywebsite_home/public_html/data/file/freeboard À̰÷¿¡ ÷ºÎÆÄÀÏÀÌ ÀúÀåµÇ¹Ç·Î º¸Åë ÀÌ·± °÷¿¡ ÇØÅ·ÆÄÀÏÀÌ ¾÷·Îµå µË´Ï´Ù. # pwd /home/mywebsite_home/public_html/data/file/freeboard # ls *.php Iist.php corp.php meixia.php each.php dm.php yh.php lele.php mem.php ¿Í °°ÀÌ °Ô½ÃÆÇ ÀúÀå°æ·Î¿¡ ÀÌ»óÇÑ php ÆÄÀÏÀÌ ÀúÀåµÇ¾î ÀÖÀ¸¸é ÇØÅ·´çÇѰ̴ϴÙ. ÆÄÀÏ À̸§°ú È®ÀåÀÚ´Â ¼ö½Ã·Î ¹Ù²î´õ±º¿ä. http://mywebsite.co.kr/data/file/freeboard/lele.php °°ÀÌ À¥Á¢¼Ó ÇØ¼ ºÒ¼øÇÑ ÁþÀ» Áãµµ»õµµ ¸ð¸£°Ô ÇÏ°Ô µË´Ï´Ù. - ÀÏ´Ü http://www.krcert.or.kr/index.jsp ¿¡ ÀÖ´Â whistl °°Àº µµ±¸·Î À¥·çÆ® µð·ºÅ丮ÀÇ Àüü ¼Ò½º¸¦ Á¡°ËÇØ¼ ÇØÅ·µÈ ÆÄÀÏÀ» Á¡°ËÇØ º¸´Â °ÍÀÌ ÁÁ½À´Ï´Ù. »ç¿ë¹ýÀº À§ »çÀÌÆ®¸¦ ÂüÁ¶ÇϽñ⠹ٶø´Ï´Ù. - °¡Àå °·ÂÇÑ ÇØ°áÃ¥Àº À§ ÷ºÎÆÄÀÏÀÌ ÀúÀåµÇ´Â À¥¼¹öÀÇ data °°Àº µð·ºÅ丮¿¡¼ php °°Àº ¼¹ö »çÀÌµå ½ºÅ©¸³Æ®°¡ ½ÇÇàÀÌ ¾ÈµÇ°Ô ÇØ¾ß ÇÕ´Ï´Ù. data µð·ºÅ丮 ¾È¿¡ .htaccess ÆÄÀÏÀ» ¾Æ·¡¿Í ºñ½ÁÇÏ°Ô ½ÃÇà¾ÈµÉ È®ÀåÀÚ¸¦ ÁöÁ¤Çؼ »ý¼ºÇÕ´Ï´Ù. # cat .htaccess <FILES ~ "\.ph(p[2-6]?|tml)$|\.htm$|\.html$|\.inc$"> Order allow,deny Deny from all </Files> ¿Í °°ÀÌ ³Ö¾îµÎ¸é À§¿¡ ³ª¿µÈ È®ÀåÀÚ ÆÄÀÏ¿¡ ´ëÇÑ Á¢±ÙÀÌ °ÅºÎµÇ¾î ½ÇÇàÀÌ ¾ÈµË´Ï´Ù. ÇѰ¡Áö ÁÖÀÇÇÒ °Ç ¾ÆÆÄÄ¡ À¥¼¹ö ¼³Á¤ÆÄÀÏ httpd.conf µî¿¡¼ php ½ºÅ©¸³Æ®°¡ ½ÇÇàµÉ È®ÀåÀÚ¿¡ ¸Â°Ô ³ª¿ÇؾßÇÕ´Ï´Ù. httpd.conf ÆÄÀÏ¿¡ AddType application/x-httpd-php .html .htm .php .php3 .php4 .php5 .phtml .cgi .inc ÀÌ·± ¹æ½ÄÀ̳ª ȤÀº <FilesMatch "\.ph(p[2-6]?|tml)$|\.htm$|\.html$|\.inc$"> SetHandler application/x-httpd-php </FilesMatch> ¿Í °°Àº ¹æ½ÄÀ¸·Î php ½ÇÇà È®ÀåÀÚ¸¦ ³Ö´Âµ¥, ÀÌ·¸°Ô httpd.conf ¿¡¼ ÁöÁ¤µÈ È®ÀåÀÚ¸¦ ¸ðµÎ .htaccess ÆÄÀÏ¿¡¼ ÁöÁ¤À» ÇØÁà¾ß php ÆÄÀÏ ½ÇÇàÀ» ¸·À» ¼ö ÀÖ½À´Ï´Ù. ÀÌ·± Â÷À̸¦ ÀÌ¿ëÇØ¼ Á» »ý¼ÒÇÑ .phtml À̳ª php2 µîÀ¸·Î È®ÀåÀÚ¸¦ ¹Ù²Ù¾î¼ ÀúÀåÇÏ¿© °ø°ÝÇÏ´Â °æ¿ìµµ ÀÖ½À´Ï´Ù. ÀÚ½ÅÀÇ À¥¼¹ö ¼³Á¤¿¡ µû¶ó¼ .htaccess ÆÄÀÏÀÇ ³»¿ëÀÌ ´Þ¶óÁú°Ì´Ï´Ù. 4. POP Á¢¼ÓÀ» ÀÌ¿ëÇÑ sendmail °ø°Ý 1) ¾ÆÀ̵ð ºñ¹ø ÇØÅ· ÇØÄ¿´Â ½ºÆÔÀ» º¸³»±â À§ÇØ ¼¹öÀÇ ¸ÞÀÏ °èÁ¤ ¾ÆÀ̵ð ºñ¹øÀ» Å»ÃëÇÏ·Á°íÇÕ´Ï´Ù. ºñ¹Ð¹øÈ£¸¦ 1234 ³ª 1111 ȤÀº ¾ÆÀ̵𳡿¡ 1234 µîÀ» ºÙÀÌ´Â µî ´Ü¼øÇÏ°Ô ÇÏ¸é ¹«Â÷º° ´ëÀÔ°ø°ÝÀ¸·Î ½±°Ô ¾Ë¾Æ³¾ ¼ö ÀÖ½À´Ï´Ù. ÀÌ·± °ø°ÝÀº ssh ³ª ftp, telnet µîÀ» ÅëÇØ¼µµ ÀÚÁÖ ÀÌ·ç¾î Áý´Ï´Ù. /var/log/message ³ª ,/var/log/secure ÆÄÀϵ¼ °¡²û ¹«Áö¸·ÁöÇÑ ±â·ÏÀ» º¼ ¼ö ÀÖÀ»°Ì´Ï´Ù. ¿©±â¼´Â pop3 ¸¦ ÅëÇØ ½ÃµµÇÑ °ø°ÝÈçÀûÀ» maillog ÆÄÀÏ¿¡¼ ã¾Æº¸°Ú½À´Ï´Ù. - POP3 µ¥¸óÀ¸·Î dovecot À» »ç¿ëÇÒ °æ¿ì # grep "Aborted login:" /var/log/maillog ... 9861 Nov 28 09:39:18 home7 dovecot: pop3-login: Aborted login: user=<chung>, method=PLAIN, rip=64.31.40.137, lip=222.122.server.ip 9862 Nov 28 09:39:18 home7 dovecot: pop3-login: Aborted login: user=<hwan>, method=PLAIN, rip=64.31.40.137, lip=222.122.server.ip 9863 Nov 28 09:39:18 home7 dovecot: pop3-login: Aborted login: user=<choi>, method=PLAIN, rip=64.31.40.137, lip=222.122.server.ip 9864 Nov 28 09:39:19 home7 dovecot: pop3-login: Login: user=<chung>, method=PLAIN, rip=64.31.40.137, lip=222.122.server.ip 9865 Nov 28 09:39:19 home7 dovecot: POP3(chung): Disconnected: Logged out top=0/0, retr=0/0, del=0/2, size=11095 9866 Nov 28 09:39:20 home7 dovecot: pop3-login: Aborted login: user=<chen>, method=PLAIN, rip=64.31.40.137, lip=222.122.server.ip 9867 Nov 28 09:39:20 home7 dovecot: pop3-login: Aborted login: user=<sung>, method=PLAIN, rip=64.31.40.137, lip=222.122.server.ip ¸ÞÀϷα׿¡¼ "Aborted login:" ¹®±¸·Î grep ÇßÀ»¶§ µ¿ÀÏÇÑ rip= °ªÀ¸·Î ¼ö¹é ¼öõ ÁÙÀÌ ±æ°Ô ³ª¿Â´Ù¸é ÀÌ°Ç ºñ¹Ð¹øÈ£ ÇØÅ·ÀÌ ÀÌ·ç¾î Áø°Ì´Ï´Ù. º¸Åë ÀÚÁÖ ¾²´Â ¾ÆÀ̵ðÀÎ web, admin, root,webmaster °°Àº °èÁ¤À̳ª ȤÀº Çѱ¹¿¡¼ ÀÚÁÖ ¾²´Â sung,yong,choi °°ÀÌ ÃßÃø °¡´ÉÇÑ ¾ÆÀ̵𸦠ÀÌ¿ëÇØ¼ ºñ¹øÀÌ 1234 °°ÀÌ °£´ÜÇÑ°É ¹«ÀÛÀ§·Î ¿¬¼Ó ´ëÀÔÇØ¼ ¾Ë¾Æ³»´Â °Ì´Ï´Ù. À§ ·Î±×¿¡¼´Â 64.31.40.137 ¶ó´Â µèº¸Àâ ip ¿¡¼ °ø°ÝÇÑ ¿¹ÀÔ´Ï´Ù. 9864 ¶óÀο¡ chung ¶ó´Â °èÁ¤ÀÌ °á±¹ Àç¼ö¾ø°Ô ¶Õ·Á¼ Á¤»ó ·Î±×ÀΠó¸®µÈ °É È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù. ³ªÁß¿¡ È®ÀÎÇØ º¸´Ï ÀÌ »ç¿ëÀÚ´Â ºñ¹Ð¹øÈ£·Î chung1234 ¸¦ »ç¿ëÇϰí ÀÖ¾ú´Ù°í ÇÕ´Ï´Ù. - POP3 µ¥¸óÀ¸·Î qpopper À» »ç¿ëÇÒ °æ¿ì ¸¸¾à pop3 ·Î qpopper ¸¦ »ç¿ëÇÑ´Ù¸é ¾Æ·¡¿Í °°ÀÌ "Password supplied" ¶ó´Â °É·Î grep ÇÏ¸é ºñ½ÁÇÏ°Ô È®ÀÎ °¡´ÉÇÕ´Ï´Ù. ¿©±â¼´Â 222.179.203.46 ¿¡¼ ¼öõ¹øÀÇ ºñ¹Ð¹øÈ£ ³Ñ°Ü¤À¸·Á´Â ½Ãµµ°¡ ÀÖ¾ú½À´Ï´Ù. # zgrep "Password supplied" ./maillog.1.gz ... Nov 21 14:21:33 home3 popper[20898]: web at 46.203.179.222.broad.cq.cq.dynamic.163data.com.cn (222.179.203.46): -ERR [AUTH] Password supplied for "web" is incorrect. Nov 21 14:21:33 home3 popper[20899]: user at 46.203.179.222.broad.cq.cq.dynamic.163data.com.cn (222.179.203.46): -ERR [AUTH] Password supplied for "user" is incorrect. Nov 21 14:21:35 home3 popper[20906]: admin at 46.203.179.222.broad.cq.cq.dynamic.163data.com.cn (222.179.203.46): -ERR [AUTH] Password supplied for "admin" is incorrect. Nov 21 14:21:37 home3 popper[20911]: webmaster at 46.203.179.222.broad.cq.cq.dynamic.163data.com.cn (222.179.203.46): -ERR [AUTH] Password supplied for "webmaster" is incorrect. 2) pop3 Ŭ¶óÀÌ¾ðÆ® »ç¿ë½Ã ·Î±× ÇüÅ - ÀϹÝÀûÀ¸·Î »ç¿ëÇÏ´Â ¾Æ¿ô·è°ú °°Àº ¸ÞÀÏ Å¬¶óÀÌ¾ðÆ®·Î Á¢¼ÓÇØ¼ ¸ÞÀÏÀ» ¹ß¼ÛÇÒ °æ¿ì sendmail ·Î±×¿¡ ¾î¶»°Ô ±â·ÏµÇ´ÂÁö ¸ÕÀú º¸°Ú½À´Ï´Ù. ## POP ¾Æ¿ô·è ¿¬°á .. Dec 1 16:35:59 home5 sendmail[31579]: AUTH=server, relay=[112.187.xxx.xx], authid=nonots, mech=LOGIN, bits=0 Dec 1 16:35:59 home5 sendmail[31579]: pB17ZvAS031579: from=<nonots@home5.myhome.co.kr>, size=1272, class=0, nrcpts=1, msgid=<777699E70A5C4270BEEF016962B9C39F@mycom>, proto=ESMTP, daemon=MTA, relay=[112.187.xxx.xx] Dec 1 16:35:59 home5 sendmail[31579]: pB17ZvAS031579: Milter add: header: X-Virus-Scanned: clamav-milter 0.97.2 at home5.myhome.co.kr Dec 1 16:35:59 home5 sendmail[31579]: pB17ZvAS031579: Milter add: header: X-Virus-Status: Clean Dec 1 16:35:59 home5 sendmail[31583]: pB17ZvAS031579: to=<nonots@hanmail.net>, ctladdr=<nonots@home5.myhome.co.kr> (501/501), delay=00:00:00, xdelay=00:00:00, mailer=esmtp, pri=121272, relay=mx9.hanmail.net. [211.43.198.80], dsn=2.0.0, stat=Sent (fB1GZwhE5580598200 Message accepted for delivery) ³»°¡ »ç¿ëÇÏ´Â PC ¾ÆÀÌÇÇÀÎ 112.187.xxx.xx ¿¡¼ nonots ¾ÆÀ̵ð·Î home5.myhome.co.kr ¼¹ö¿¡ Á¢¼ÓÇØ¼, ÇѸÞÀÏ nonots@hanmail.net ÁÖ¼Ò·Î ¸ÞÀÏ º¸³½ ±â·ÏÀÔ´Ï´Ù. ÇѸÞÀϼ¹ö mx9.hanamil.net À¸·Î ¸ÞÀÏÀ» º¸³»¼ stat=Sent °¡ ³ª¿Í¼ Á¤»óÀûÀ¸·Î ¹ß¼ÛµÆÀ½À» ¾Ë ¼ö ÀÖ½À´Ï´Ù. ù ¶óÀο¡ authid=nonots ¶ó´Â Á¢¼Ó ±â·ÏÀÌ º¸À̰í, Á¢¼ÓÇÑ sendmail ÇÁ·Î¼¼½º ¹øÈ£°¡ [31579] ¹øÀÔ´Ï´Ù. ÀÌ ÇÁ·Î¼¼½º¿¡ ÀÇÇØ ½Äº°ÀÚ pB17ZvAS031579 °¡ ºÎ¿©µÇ´Âµ¥, ÀÌ ½Äº°ÀÚÀÇ ¸¶Áö¸· ºÎºÐ¿¡ 31579 ¶ó´Â ÇÁ·Î¼¼½º ¾ÆÀ̵ð°ªÀ» »ç¿ëÇÑ´Ù´Â Á¡À» À¯ÀÇÇØ¾ß ÇÕ´Ï´Ù. ÀÌ ½Äº°ÀÚ¿¡ ÀÇÇØ¼ /var/spool/mqueue ¿¡ ¸ÞÀÏ Çì´õÆÄÀÏÀÎ hfpB17ZvAS031579 ¿Í µ¥ÀÌŸÆÄÀÏÀÎ dfpB17ZvAS031579 °¡ ÀϽÃÀûÀ¸·Î »ý±â°í, ¹ß¼Û ¿Ï·áÇÑ ÈÄ¿¡´Â mqueue ¿¡¼ ÀÏÁ¤±â°£ ÈÄ ÀÚµ¿À¸·Î »èÁ¦°¡ µË´Ï´Ù. ÀÌÁ¦ ÀÌ Æ¯Â¡À» ÀÌ¿ëÇØ¼ ¸ÞÀϼ¹ö ÇØÅ· ¿©ºÎ¸¦ Á¡°ËÇØ º¸°Ú½À´Ï´Ù. 3) maillog Á¡°Ë - º¸Åë sendmail ·Î±×´Â /var/log¿¡ ÀúÀåµÇ°í 1 ÁÖÀϸ¶´Ù ¼¹ö logrotate cron ¿¡ ÀÇÇØ ¹é¾÷ÀÌ µË´Ï´Ù. maillog.1, maillog.2,maillog.3 ¿Í °°ÀÌ ¹é¾÷µÇ´Âµ¥, ¾î¶² ¼¹ö¿¡¼´Â ¾ÐÃà¹é¾÷À» ÇØ¼, maillog.1.gz, maillog.2.gz.. ¿Í °°ÀÌ gz ¾ÐÃàµÇ¾î ÀúÀåµÇ±âµµ ÇÕ´Ï´Ù. ·Î±× ºÐ¼®À» À§Çؼ´Â Áö³ ¹é¾÷ÆÄÀϱîÁö Àüü¸¦ °Ë»öÇϱâ À§ÇØ /var/log/maillog* ¿Í °°ÀÌ ¿É¼ÇÀ» ÁÖ´Â °ÍÀÌ ÁÁ½À´Ï´Ù. ¾Æ·¡ grep ÀÌ ¾Æ´Ï¶ó zgrep À» »ç¿ëÇÑ ÀÌÀ¯´Â gz ·Î ¾ÐÃàµÈ°Ç ÀÚµ¿À¸·Î Ç®¾î¼ °Ë»öÇϱâ À§ÇØ zgrep À» »ç¿ëÇß½À´Ï´Ù. ¸¸¾à ¹é¾÷ÆÄÀÏÀÌ ¾÷ÃàµÇÁö ¾Ê¾Ò´Ù¸é ±×³É grep À» »ç¿ëÇØµµ µË´Ï´Ù. # zgrep "authid=" /var/log/maillog* | awk '{print $8}' | sort | uniq -c | grep authid | sort -r 2972 authid=chung, 20 authid=kmlee, 13 authid=aychoi, 8 authid=keom, 7 authid=hyseong, 6 authid=tsshyang, ... ÀÌ ¸í·É¾î´Â ¾Æ¿ô·è °°Àº ¸ÞÀÏŬ¶óÀÌ¾ðÆ®¿¡¼ Á¤»óÀûÀ¸·Î °èÁ¤¿¡ ·Î±×ÀÎÇÑ Á¤º¸¸¦ ¸ÞÀϷα׿¡¼ ÃßÃâÇÏ¿©¼ °¢ ¾ÆÀ̵𠺰·Î Åë°è¸¦ ³½ °Ì´Ï´Ù. auth=?? ¿Í °°ÀÌ ·Î±×ÀÎ ¼º°øÇÑ ¶óÀο¡¼ °ø¹é¹®ÀÚ¸¦ ±âÁØÀ¸·Î cut À» ÇØ¼ 8 ¹øÂ° Çʵ带 »Ì¾Æ³½ ÈÄ °°Àº ¾ÆÀ̵𸦠ÇÕ»êÇÑ ÈÄ Á¤·ÄÇѰ̴ϴÙ. À§¿¡¼, ÇØÅ·´çÇÑ chung ¶ó´Â °èÁ¤ÀÌ 2972¹øÀ¸·Î °¡Àå ¸¹ÀÌ Á¢¼ÓÇßÀ½À» ¾Ë ¼ö ÀÖ½À´Ï´Ù. ±×¸®°í ¸ÞÀÏÀ» ¹ß¼ÛÇÑ ip º°·Î º¸·Á¸é # zgrep "authid=" /var/log/maillog* | awk '{print $7}' | sort | grep relay | uniq -c | sort -r 2972 relay=[194.51.238.89], 23 relay=[121.166.xxx.xxx], 19 relay=[112.158.73.131], 12 relay=[183.98.111.130], 8 relay=[116.121.255.202], ... ¿Í °°ÀÌ 194.51.238.89 ¾ÆÀÌÇÇ¿¡¼ Á¦ÀÏ ¸¹ÀÌ Á¢¼ÓÇÑ°É ¾Ë¼ö ÀÖ½À´Ï´Ù. ÀÌ ¾ÆÀÌÇǰ¡ chung °èÁ¤À» ÀÌ¿ëÇÑ °ÍÀ¸·Î ÃßÃøÇÒ ¼ö ÀÖ½À´Ï´Ù. ½ÇÁ¦·Î maillog ÆÄÀÏÀ» ¿¡µðÅÍ·Î ¿¾î¼ authid=chung ³ª 194.51.238.89 µîÀ» °Ë»öÇØ¼ º¸¸é .. 41628 Nov 28 20:07:23 home7 sendmail[15541]: AUTH=server, relay=[194.51.238.89], authid=chung, mech=LOGIN, bits=0 41629 Nov 28 20:07:23 home7 sendmail[15539]: AUTH=server, relay=[194.51.238.89], authid=chung, mech=LOGIN, bits=0 41630 Nov 28 20:07:23 home7 sendmail[15540]: AUTH=server, relay=[194.51.238.89], authid=chung, mech=LOGIN, bits=0 41631 Nov 28 20:07:23 home7 sendmail[15554]: AUTH=server, relay=[194.51.238.89], authid=chung, mech=LOGIN, bits=0 41632 Nov 28 20:07:23 home7 sendmail[15555]: AUTH=server, relay=[194.51.238.89], authid=chung, mech=LOGIN, bits=0 41633 Nov 28 20:08:13 home7 sendmail[15540]: pASB7Bop015540: from=<co@e-lupeni.ro>, size=596, class=0, nrcpts=50, msgid=<201111281107.pASB7Bop01554 0@home7.myhome.co.kr>, proto=ESMTP, daemon=MTA, relay=[194.51.238.89] 41634 Nov 28 20:08:13 home7 sendmail[15540]: pASB7Bop015540: Milter add: header: X-Virus-Scanned: clamav-milter 0.97.2 at home7.myhome.co.kr 41635 Nov 28 20:08:13 home7 sendmail[15540]: pASB7Bop015540: Milter add: header: X-Virus-Status: Clean 41636 Nov 28 20:08:14 home7 sendmail[15542]: pASB7Bi0015542: from=<co@e-lupeni.ro>, size=596, class=0, nrcpts=50, msgid=<201111281107.pASB7Bi001554 2@home7.myhome.co.kr>, proto=ESMTP, daemon=MTA, relay=[194.51.238.89] .. ¿Í °°ÀÌ µÇ¾î ÀÖ½À´Ï´Ù. 11¿ù 28ÀÏ 20½Ã 7ºÐ¿¡ Á¢¼ÓÇØ¼ co@e-lupeni.ro ¸¦ ¹ß¼ÛÀÚ·Î ÇØ¼ ½ºÆÔ¸ÞÀÏÀ» ¹ß¼ÛÇÑ°É ¾Ë ¼ö ÀÖ½À´Ï´Ù. ¾Æ¸¶ ÀÌ·± ¹ß¼ÛÀÌ ¼ö¹é ¼öõ°ÇÀÌ º¸Àϰ̴ϴÙ. ºô¾î¸ÔÀ».. 3) ½Ç½Ã°£ ½ºÆÔ ¹ß¼Û ´ëÀÀ - ¸¸¾à ÇöÀç ½Ã°¢À¸·Î ¼¹ö¿¡¼ ½ºÆÔÀÌ ¿³ª°Ô ¹ß¼ÛµÇ°í ÀÖÀ» °æ¿ì ¿ì¼± ¾Æ·¡¿Í °°ÀÌ ps ¸í·É¾î·Î º¸¸é ¾Æ·¡¿Í °°Àº sendmail ÇÁ·Î¼¼½º°¡ º¸ÀÔ´Ï´Ù. # ps aux ... root 6839 0.0 0.1 69232 2996 ? S 15:14 0:00 sendmail: ./pB26E7mm006835 from queue ... ÀÌ °æ¿ì ½Äº°ÀÚ pB26E7mm006835 ¿¡¼ ³¡ºÎºÐ ¼ýÀÚ 6835 ¹ø ÇÁ·Î¼¼½º¿¡ ÀÇÇØ¼ ¹ß¼ÛµÆÀ½À» ¾Ë ¼ö ÀÖ½À´Ï´Ù. À§¿¡¼ ¸»ÇßµíÀÌ /var/spool/mqueue ¿¡ dfpB26E7mm006835, hfpB26E7mm006835 ÆÄÀÏÀÌ ÀÖÀ» °Ì´Ï´Ù. ·Î±×ÆÄÀÏ¿¡¼ ÀÌ ¹øÈ£·Î ¹ß¼Û±â·ÏÀ» ã¾Æº¸¸é # grep "\[6835\]" /var/log/maillog .. Dec 2 15:14:10 home7 sendmail[6835]: AUTH=server, relay=[121.166.xxx.xxx], authid=jychoi, mech=LOGIN, bits=0 Dec 2 15:14:10 home7 sendmail[6835]: pB26E7mm006835: from=<jychoi@aaabbb.com>, size=90127, class=0, nrcpts=1, msgid=<000001ccb0b9$9b14ed20$d13ec760$@com>, proto=ESMTP, daemon=MTA, relay=[121.166.xxx.xxx] Dec 2 15:14:10 home7 sendmail[6835]: pB26E7mm006835: Milter add: header: X-Virus-Scanned: clamav-milter 0.97.2 at home7.myhome.co.kr Dec 2 15:14:10 home7 sendmail[6835]: pB26E7mm006835: Milter add: header: X-Virus-Status: Clean .. ¿Í °°ÀÌ °Ë»öÀÌ µÉ°Ì´Ï´Ù grep °Ë»ö¿¡¼ [, ] ¹®ÀÚ¸¦ »ç¿ëÇÏ·Á¸é À§¿Í °°ÀÌ ¿ª½½·¡½Ã·Î ó¸®ÇØ Áà¾ß ÇÕ´Ï´Ù. ¸¸¾à ³Ê¹« ±æ¾î¼ º¸±â Èûµé´Ù¸é authid= ºÎºÐ¸¸ °Ë»öÇØ¼ ¾î´À °èÁ¤À¸·Î ¹ß¼Û ÁßÀÎÁö ¾Ë ¼ö ÀÖ½À´Ï´Ù. # grep "\[6835\]" /var/log/maillog | grep authid Dec 2 15:14:10 home7 sendmail[6835]: AUTH=server, relay=[121.166.xxx.xxx], authid=jychoi, mech=LOGIN, bits=0 .. ¿Í °°ÀÌ jychoi ¶ó´Â °èÁ¤À¸·Î 121.166.xxx.xxx ¿¡¼ Á¢¼ÓÇØ¼ ¸ÞÀÏÀ» ¹ß¼Û ÁßÀÔ´Ï´Ù. ¸¸¾à ÀÌ ¹ß¼ÛÀÌ Á¤»óÀÌ ¾Æ´Ï¶ó ½ºÆÔ ÀǽÉÀÌ µÈ´Ù¸é À§¿¡¼ °Ë»öÇÑ # zgrep "authid=" /var/log/maillog* | awk '{print $8}' | sort | uniq -c | grep authid | sort -r ÀÇ °á°ú¸¦ º¸°Å³ª ±âŸ ¹æ¹ýÀ¸·Î ½ºÆÔ ¿©ºÎ¸¦ ÆÇ´ÜÇÏ¸é µË´Ï´Ù. ½ÇÁ¦ jychoi »ç¿ëÀÚ¿¡°Ô ÀüÈÇØ¼ Áö±Ý ¸ÞÀÏ ¹ß¼ÛÁßÀÎÁö ¹°¾îº¼ ¼öÀÖ´Ù¸é Á¦ÀÏ Á¤È®ÇϰÚÁÒ. ±×¸®°í º¸Åë ½ºÆÔÀº ´ÊÀº¹ãÀ̳ª »õº® ½Ã°£´ë¿¡ º¸³»¹Ç·Î ¹ß¼Û ½Ã°£À» º¸°í ¾î´ÀÁ¤µµ ÃßÁ¤ÇÒ ¼öµµ ÀÖ½À´Ï´Ù. 5) ½ºÆÔ¹ß¼ÛÀÏ °æ¿ì ´ëó ¹æ¹ý - Àå³ÀÌ ¾Æ´Ï¶ó¸é ¸ðµç ¸ÞÀϷα׸¦ ¾ÐÃàÇØ¼ º¸°üÇϰí "±â°ü"¿¡ ½Å°íÇÏ¸é µË´Ï´Ù. ±ÍÂú¾Æ¼ ±×³É ÀÚü ÇØ°áÇÏ·Á¸é, (0) sendmail µ¥¸óÀ» ÁßÁöÇÕ´Ï´Ù. (1) ¿ì¼± ½ºÆÔ ¹ß¼ÛÇÑ ID °èÁ¤À» Æó¼âÇϰųª, ȤÀº ½ÇÁ¦ »ç¿ëÀÚ¿¡°Ô ¿¬¶ôÇØ¼ ºñ¹Ð¹øÈ£¸¦ ¼öÁ¤Çϵµ·Ï °Á¦ÇÕ´Ï´Ù. (2) ÇØÅ· ÀǽɵǴ IP ¸¦ Â÷´ÜÇÕ´Ï´Ù. ¾Æ·¡¿Í °°ÀÌ iptables ·Î ÇØµµ µÇ°í # iptables -I INPUT -s 194.51.238.89 -j DROP # iptables -I OUTPUT -s 194.51.238.89 -j DROP /etc/mail/access ÆÄÀÏÀ̳ª, /etc/hosts.deny µîÀ» ÀÌ¿ëÇϰųª ÇÏ¿©Æ°, ¹æÈº®¿¡¼ ¸·À» ¼ö ÀÖ´Â ¸ðµç ¼ö´ÜÀ» µ¿¿øÇØ ¸·½À´Ï´Ù. (3) /var/spool/mqueue ¸¦ û¼ÒÇÕ´Ï´Ù. ¾ÆÀ̵𳪠¾ÆÀÌÇǸ¦ Â÷´ÜÇØµµ sendmail µ¥¸óÀÇ Å¥¿¡ ÀúÀåµÈ °Ç ÀÏÁ¤½Ã°£ °è¼Ó ¹ß¼ÛÇÏ·Á°í ½ÃµµÇÏ°Ô µË´Ï´Ù. 194.51.238.89 ÀÌ ¾ÆÀÌÇÇ·Î »ý¼ºµÈ Å¥ÀÇ ÀÓ½ÃÆÄÀÏÀ» ¾Æ·¡¿Í °°ÀÌ Àϰý »èÁ¦ °¡´ÉÇÕ´Ï´Ù. # grep -l 194.51.238.89 /var/spool/mqueue/* | xargs -i rm -f {} (4) sendmail µ¥¸óÀ» Àç½ÃÀÛÇÕ´Ï´Ù. ¾Æ¸¶ Àç½ÃÀÛÇØµµ ÀÏÁ¤½Ã°£ µ¿¾È Å¥¿¡ ÀÖ´Â ÆÄÀÏ ¶§¹®¿¡ ÀϺΠ½ºÆÔ ¹ß¼Û ½Ãµµ°¡ ÀÖÀ»¼ö ÀÖ½À´Ï´Ù. ±×°Ç ¼öµ¿À¸·Î Å¥ÆÄÀÏ À̸§À» È®ÀÎÇØ¼ »èÁ¦ÇØ ÁÖ¸é µË´Ï´Ù. 5. ¸¶¹«¸® ÁøÀλç´ëõ¸íÇß´Â µ¥µµ °è¼Ó ½ºÆÔ¸ÞÀÏÀÌ ¹ß¼ÛµÈ´Ù¸é ±×³É Áñ.±â.½Ã.±æ. -_-;; |
|||||
Àüü´ñ±Û¼ö 5
12345678910


