Class
  • Tip&Tech
[¼­¹ö¿î¿µ] Sendmail ·Î±×ºÐ¼® ½ºÆÔ ŽÁö °ü·Ã »ðÁú
±Û¾´ÀÌ ±â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§µ¶°Åû³â ³¯ Â¥ 11-12-02 18:39 Á¶ ȸ 2932
°£ÆíURL http://www.phpschool.com/link/tipntech/74657 º¹»ç

SyntaxHighlight·Î º¸±â

################################################################3
### ¾´°Í : Sendmail ·Î±×ºÐ¼® ½ºÆÔ ŽÁö °ü·Ã »ðÁú
### ¾´ÀÌ : ±Ç¼ºÀç(nonots@hanmail.net, http://www.badaweb.co.kr)
### ¾´¶§ : 2011-12-02
################################################################3

1. °³¿ä

¼­¹ö°ü¸®Àڵ鿡°Ô À־ ½ºÆÔ¸ÞÀÏ º¸³»´Â Àΰ£µéÀº ¶§·ÁÁ×ÀÌ°í ½ÍÀº Ãæµ¿À»
ºÒ·¯ÀÏÀ¸Åµ´Ï´Ù.
´Ù¸¥ ÇØÅ·°ú ´Þ¸® ½ºÆÔ°ø°ÝÇÏ´Â °Ç ·Î±×ºÐ¼®Çؼ­ ã±âµµ, ¸·±âµµ ¾î·Æ½À´Ï´Ù.
´õ±¸³ª, ¸¹Àº ½ºÆÔÀÌ ÇѸÞÀÏÀ̳ª ³×À̹ö,±¸±Û ¸ÞÀϼ­¹ö·Î º¸³»Áö´Ù º¸´Ï,
ÇѸÞÀÏÀ̳ª ³×À̹ö ¸ÞÀϼ­¹ö Ãø¿¡¼­ ¸ÖÂÄÇÑ ¸ÞÀϼ­¹ö ip ¸¦ Â÷´ÜÇØ¼­
¼±·®ÇÑ ÀÏ¹Ý ¸ÞÀÏ »ç¿ëÀÚµéÀÌ ¸ÞÀÏÀÌ ¹ß¼ÛµÇÁö ¾Ê¾Æ ÇÇÇØ¸¦ ÀÔ½À´Ï´Ù.
¾Æ·¡¿¡,
¸®´ª½º ¼­¹ö¿¡¼­ sendmail µ¥¸ó °ü·ÃÇØ¼­ »ðÁúÇϸ鼭 ¾Ë°Ô µÈ Á¤º¸¸¦ °ø°³ÇÕ´Ï´Ù.
ÇãÁ¢ÇÕ´Ï´Ù¸¸, ³ªº¸´Ù ´õ ÇãÁ¢ÇÑ °ü¸®Àڵ鿡°Ô Á¶±ÝÀ̳ª¸¶ µµ¿òÀÌ µÇ¾úÀ¸¸é ÇÕ´Ï´Ù.


2. ¼­¹öȯ°æ
- OS : CentOs 5.x (·¹µåÇÞ °è¿­)
- Sendmail ¹öÀü : 12.x, 13.x
- POP3 µ¥¸ó : dovecot, qpopper µî
- ¸ÞÀÏ ·Î±× ÆÄÀÏ : /var/log/maillog


3. À¥¼Ò½º ÅëÇÑ ½ºÆÔ ¹ß¼Û °ü·Ã

- ±×´©º¸µå³ª Á¦·Îº¸µåµî À¥»çÀÌÆ® °Ô½ÃÆÇÀÇ Ã·ºÎÆÄÀÏ ¾÷·Îµå ±â´ÉÀÇ ÇêÁ¡À»
ÀÌ¿ëÇØ¼­ ¼­¹ö¿¡ .php °°Àº ½ÇÇàÆÄÀÏÀ» ÀúÀåÇÑ ÈÄ ¿ÜºÎ¿¡¼­ ÀÌ ÆÄÀÏÀ» ÅëÇØ¼­
½ºÆÔÀ» ¹ß¼ÛÇÏ´Â ¹æ¹ýÀÔ´Ï´Ù.
¹®Á¦´Â, ÀÌ·¸°Ô À¥°æ·Î¿¡ ¾÷·ÎµåÇÑ ÈÄ ½ºÆÔ¸ÞÀÏÀ» º¸³»¸é ÇØ´ç ¼­¹ö¿¡ ÀÖ´Â sendmail
·Î±×¿¡ Àß ±â·ÏÀÌ ¾ÈµË´Ï´Ù.
php ¸ðµâÀÌ À¥¼­¹ö±ÇÇÑÀ» ÀÌ¿ëÇØ¼­ ¸·¹Ù·Î º¸³»¹Ç·Î ƯÁ¤ »ç¿ëÀÚ °èÁ¤À»
¾Ë¼ö°¡ ¾ø½À´Ï´Ù. ¶Ç ÇÑ ¿ÜºÎ ¼­¹ö¿¡ Æ÷Æ® Á¢¼ÓÇØ¼­ ¹ß¼ÛÇÑ´Ù¸é ³»ºÎ ¸ÞÀϼ­¹ö¿¡´Â
±â·ÏÀÌ ³²Áö ¾Ê°ÔµË´Ï´Ù.
ÀÌ°Ç maillog ºÐ¼®À¸·Î´Â ¾Ë±â¾î·Æ°í, ¹Ýµå½Ã ¹«´ÜÀ¸·Î ¾÷·ÎµåµÈ ÇØÅ· ÆÄÀÏÀ»
ã¾Æ¼­ »èÁ¦ÇØ¾ß ÇÕ´Ï´Ù.
¿©±â¼­´Â °£´ÜÇÑ ¹æ¹ý¸¸ ¼Ò°³ÇÕ´Ï´Ù.

¸¸¾à À¥·ÎÆ®°¡ /home/mywebsite_home/public_html ÀÎ °÷¿¡ ±×´©º¸µå°¡ ¼³Ä¡µÆ°í
freeboard ¶ó´Â °Ô½ÃÆÇ¾ÆÀ̵𸦠»ç¿ëÇß´Ù¸é
/home/mywebsite_home/public_html/data/file/freeboard À̰÷¿¡ ÷ºÎÆÄÀÏÀÌ
ÀúÀåµÇ¹Ç·Î º¸Åë ÀÌ·± °÷¿¡ ÇØÅ·ÆÄÀÏÀÌ ¾÷·Îµå µË´Ï´Ù.

# pwd
/home/mywebsite_home/public_html/data/file/freeboard
# ls *.php
Iist.php corp.php meixia.php each.php dm.php yh.php lele.php  mem.php

¿Í °°ÀÌ °Ô½ÃÆÇ ÀúÀå°æ·Î¿¡ ÀÌ»óÇÑ php ÆÄÀÏÀÌ ÀúÀåµÇ¾î ÀÖÀ¸¸é ÇØÅ·´çÇѰ̴ϴÙ.
ÆÄÀÏ À̸§°ú È®ÀåÀÚ´Â ¼ö½Ã·Î ¹Ù²î´õ±º¿ä.
http://mywebsite.co.kr/data/file/freeboard/lele.php
°°ÀÌ À¥Á¢¼Ó ÇØ¼­ ºÒ¼øÇÑ ÁþÀ» Áãµµ»õµµ ¸ð¸£°Ô ÇÏ°Ô µË´Ï´Ù.

- ÀÏ´Ü http://www.krcert.or.kr/index.jsp ¿¡ ÀÖ´Â whistl °°Àº µµ±¸·Î
À¥·çÆ® µð·ºÅ丮ÀÇ Àüü ¼Ò½º¸¦ Á¡°ËÇØ¼­ ÇØÅ·µÈ ÆÄÀÏÀ» Á¡°ËÇØ º¸´Â °ÍÀÌ
ÁÁ½À´Ï´Ù.  »ç¿ë¹ýÀº À§ »çÀÌÆ®¸¦ ÂüÁ¶ÇϽñ⠹ٶø´Ï´Ù.

- °¡Àå °­·ÂÇÑ ÇØ°áÃ¥Àº À§ ÷ºÎÆÄÀÏÀÌ ÀúÀåµÇ´Â À¥¼­¹öÀÇ data °°Àº µð·ºÅ丮¿¡¼­
php °°Àº ¼­¹ö »çÀÌµå ½ºÅ©¸³Æ®°¡ ½ÇÇàÀÌ ¾ÈµÇ°Ô ÇØ¾ß ÇÕ´Ï´Ù.
data µð·ºÅ丮 ¾È¿¡ .htaccess ÆÄÀÏÀ» ¾Æ·¡¿Í ºñ½ÁÇÏ°Ô ½ÃÇà¾ÈµÉ È®ÀåÀÚ¸¦ ÁöÁ¤Çؼ­
»ý¼ºÇÕ´Ï´Ù.

# cat .htaccess
<FILES ~ "\.ph(p[2-6]?|tml)$|\.htm$|\.html$|\.inc$">
Order allow,deny
Deny from all
</Files>
¿Í °°ÀÌ ³Ö¾îµÎ¸é À§¿¡ ³ª¿­µÈ È®ÀåÀÚ ÆÄÀÏ¿¡ ´ëÇÑ Á¢±ÙÀÌ °ÅºÎµÇ¾î ½ÇÇàÀÌ ¾ÈµË´Ï´Ù.
ÇѰ¡Áö ÁÖÀÇÇÒ °Ç
¾ÆÆÄÄ¡ À¥¼­¹ö ¼³Á¤ÆÄÀÏ httpd.conf µî¿¡¼­ php ½ºÅ©¸³Æ®°¡ ½ÇÇàµÉ È®ÀåÀÚ¿¡ ¸Â°Ô
³ª¿­ÇؾßÇÕ´Ï´Ù.
httpd.conf ÆÄÀÏ¿¡

AddType application/x-httpd-php .html .htm .php .php3 .php4 .php5 .phtml .cgi .inc
ÀÌ·± ¹æ½ÄÀ̳ª ȤÀº
<FilesMatch "\.ph(p[2-6]?|tml)$|\.htm$|\.html$|\.inc$">
SetHandler application/x-httpd-php
</FilesMatch>
¿Í °°Àº ¹æ½ÄÀ¸·Î php ½ÇÇà È®ÀåÀÚ¸¦ ³Ö´Âµ¥, ÀÌ·¸°Ô httpd.conf ¿¡¼­ ÁöÁ¤µÈ È®ÀåÀÚ¸¦
¸ðµÎ .htaccess ÆÄÀÏ¿¡¼­ ÁöÁ¤À» ÇØÁà¾ß php ÆÄÀÏ ½ÇÇàÀ» ¸·À» ¼ö ÀÖ½À´Ï´Ù.
ÀÌ·± Â÷À̸¦ ÀÌ¿ëÇØ¼­ Á» »ý¼ÒÇÑ .phtml À̳ª php2 µîÀ¸·Î È®ÀåÀÚ¸¦ ¹Ù²Ù¾î¼­ ÀúÀåÇÏ¿©
°ø°ÝÇÏ´Â °æ¿ìµµ ÀÖ½À´Ï´Ù.
ÀÚ½ÅÀÇ À¥¼­¹ö ¼³Á¤¿¡ µû¶ó¼­ .htaccess ÆÄÀÏÀÇ ³»¿ëÀÌ ´Þ¶óÁú°Ì´Ï´Ù.



4. POP Á¢¼ÓÀ» ÀÌ¿ëÇÑ sendmail °ø°Ý

1) ¾ÆÀ̵ð ºñ¹ø ÇØÅ·
ÇØÄ¿´Â ½ºÆÔÀ» º¸³»±â À§ÇØ ¼­¹öÀÇ ¸ÞÀÏ °èÁ¤ ¾ÆÀ̵ð ºñ¹øÀ»
Å»ÃëÇÏ·Á°íÇÕ´Ï´Ù.
ºñ¹Ð¹øÈ£¸¦ 1234 ³ª 1111 ȤÀº ¾ÆÀ̵𳡿¡ 1234 µîÀ» ºÙÀÌ´Â µî ´Ü¼øÇÏ°Ô Çϸé
¹«Â÷º° ´ëÀÔ°ø°ÝÀ¸·Î ½±°Ô ¾Ë¾Æ³¾ ¼ö ÀÖ½À´Ï´Ù.
ÀÌ·± °ø°ÝÀº ssh ³ª ftp, telnet µîÀ» ÅëÇØ¼­µµ  ÀÚÁÖ ÀÌ·ç¾î Áý´Ï´Ù.
/var/log/message ³ª ,/var/log/secure ÆÄÀϵ¼­ °¡²û ¹«Áö¸·ÁöÇÑ ±â·ÏÀ» º¼ ¼ö
ÀÖÀ»°Ì´Ï´Ù.
¿©±â¼­´Â pop3 ¸¦ ÅëÇØ ½ÃµµÇÑ °ø°ÝÈçÀûÀ»  maillog ÆÄÀÏ¿¡¼­ ã¾Æº¸°Ú½À´Ï´Ù.

- POP3 µ¥¸óÀ¸·Î dovecot À» »ç¿ëÇÒ °æ¿ì

# grep "Aborted login:" /var/log/maillog
...
9861 Nov 28 09:39:18 home7 dovecot: pop3-login: Aborted login: user=<chung>, method=PLAIN, rip=64.31.40.137, lip=222.122.server.ip
9862 Nov 28 09:39:18 home7 dovecot: pop3-login: Aborted login: user=<hwan>, method=PLAIN, rip=64.31.40.137, lip=222.122.server.ip
9863 Nov 28 09:39:18 home7 dovecot: pop3-login: Aborted login: user=<choi>, method=PLAIN, rip=64.31.40.137, lip=222.122.server.ip
9864 Nov 28 09:39:19 home7 dovecot: pop3-login: Login: user=<chung>, method=PLAIN, rip=64.31.40.137, lip=222.122.server.ip
9865 Nov 28 09:39:19 home7 dovecot: POP3(chung): Disconnected: Logged out top=0/0, retr=0/0, del=0/2, size=11095
9866 Nov 28 09:39:20 home7 dovecot: pop3-login: Aborted login: user=<chen>, method=PLAIN, rip=64.31.40.137, lip=222.122.server.ip
9867 Nov 28 09:39:20 home7 dovecot: pop3-login: Aborted login: user=<sung>, method=PLAIN, rip=64.31.40.137, lip=222.122.server.ip

¸ÞÀϷα׿¡¼­ "Aborted login:" ¹®±¸·Î grep ÇßÀ»¶§ µ¿ÀÏÇÑ rip= °ªÀ¸·Î ¼ö¹é
¼öõ ÁÙÀÌ ±æ°Ô  ³ª¿Â´Ù¸é ÀÌ°Ç ºñ¹Ð¹øÈ£ ÇØÅ·ÀÌ ÀÌ·ç¾î Áø°Ì´Ï´Ù.
º¸Åë ÀÚÁÖ ¾²´Â ¾ÆÀ̵ðÀÎ web, admin, root,webmaster °°Àº °èÁ¤À̳ª ȤÀº
Çѱ¹¿¡¼­ ÀÚÁÖ ¾²´Â sung,yong,choi °°ÀÌ ÃßÃø °¡´ÉÇÑ ¾ÆÀ̵𸦠ÀÌ¿ëÇØ¼­
ºñ¹øÀÌ 1234 °°ÀÌ °£´ÜÇÑ°É ¹«ÀÛÀ§·Î ¿¬¼Ó ´ëÀÔÇØ¼­ ¾Ë¾Æ³»´Â °Ì´Ï´Ù.
À§ ·Î±×¿¡¼­´Â 64.31.40.137 ¶ó´Â µèº¸Àâ ip ¿¡¼­ °ø°ÝÇÑ ¿¹ÀÔ´Ï´Ù.
9864 ¶óÀο¡ chung ¶ó´Â °èÁ¤ÀÌ °á±¹ Àç¼ö¾ø°Ô ¶Õ·Á¼­ Á¤»ó ·Î±×ÀΠó¸®µÈ °É È®ÀÎÇÒ
¼ö ÀÖ½À´Ï´Ù.
³ªÁß¿¡ È®ÀÎÇØ º¸´Ï ÀÌ »ç¿ëÀÚ´Â ºñ¹Ð¹øÈ£·Î chung1234 ¸¦ »ç¿ëÇϰí ÀÖ¾ú´Ù°í ÇÕ´Ï´Ù.

- POP3 µ¥¸óÀ¸·Î qpopper À» »ç¿ëÇÒ °æ¿ì
¸¸¾à pop3 ·Î qpopper ¸¦ »ç¿ëÇÑ´Ù¸é ¾Æ·¡¿Í °°ÀÌ "Password supplied" ¶ó´Â °É·Î
grep ÇÏ¸é ºñ½ÁÇÏ°Ô È®ÀÎ °¡´ÉÇÕ´Ï´Ù.
¿©±â¼­´Â  222.179.203.46 ¿¡¼­ ¼öõ¹øÀÇ ºñ¹Ð¹øÈ£ ³Ñ°Ü¤À¸·Á´Â ½Ãµµ°¡ ÀÖ¾ú½À´Ï´Ù.

# zgrep "Password supplied" ./maillog.1.gz 
...
Nov 21 14:21:33 home3 popper[20898]: web at 46.203.179.222.broad.cq.cq.dynamic.163data.com.cn (222.179.203.46): -ERR [AUTH] Password supplied for "web" is incorrect.
Nov 21 14:21:33 home3 popper[20899]: user at 46.203.179.222.broad.cq.cq.dynamic.163data.com.cn (222.179.203.46): -ERR [AUTH] Password supplied for "user" is incorrect.
Nov 21 14:21:35 home3 popper[20906]: admin at 46.203.179.222.broad.cq.cq.dynamic.163data.com.cn (222.179.203.46): -ERR [AUTH] Password supplied for "admin" is incorrect.
Nov 21 14:21:37 home3 popper[20911]: webmaster at 46.203.179.222.broad.cq.cq.dynamic.163data.com.cn (222.179.203.46): -ERR [AUTH] Password supplied for "webmaster" is incorrect.


2) pop3 Ŭ¶óÀÌ¾ðÆ® »ç¿ë½Ã ·Î±× ÇüÅÂ
- ÀϹÝÀûÀ¸·Î »ç¿ëÇÏ´Â ¾Æ¿ô·è°ú °°Àº ¸ÞÀÏ Å¬¶óÀÌ¾ðÆ®·Î Á¢¼ÓÇØ¼­ ¸ÞÀÏÀ» ¹ß¼ÛÇÒ °æ¿ì
sendmail ·Î±×¿¡ ¾î¶»°Ô ±â·ÏµÇ´ÂÁö ¸ÕÀú º¸°Ú½À´Ï´Ù.

## POP ¾Æ¿ô·è ¿¬°á
..
Dec  1 16:35:59 home5 sendmail[31579]: AUTH=server, relay=[112.187.xxx.xx], authid=nonots, mech=LOGIN, bits=0
Dec  1 16:35:59 home5 sendmail[31579]: pB17ZvAS031579: from=<nonots@home5.myhome.co.kr>, size=1272, class=0, nrcpts=1, msgid=<777699E70A5C4270BEEF016962B9C39F@mycom>, proto=ESMTP, daemon=MTA, relay=[112.187.xxx.xx]
Dec  1 16:35:59 home5 sendmail[31579]: pB17ZvAS031579: Milter add: header: X-Virus-Scanned: clamav-milter 0.97.2 at home5.myhome.co.kr
Dec  1 16:35:59 home5 sendmail[31579]: pB17ZvAS031579: Milter add: header: X-Virus-Status: Clean
Dec  1 16:35:59 home5 sendmail[31583]: pB17ZvAS031579: to=<nonots@hanmail.net>, ctladdr=<nonots@home5.myhome.co.kr> (501/501), delay=00:00:00, xdelay=00:00:00, mailer=esmtp, pri=121272, relay=mx9.hanmail.net. [211.43.198.80], dsn=2.0.0, stat=Sent (fB1GZwhE5580598200 Message accepted for delivery)

³»°¡ »ç¿ëÇÏ´Â PC ¾ÆÀÌÇÇÀΠ 112.187.xxx.xx ¿¡¼­ nonots ¾ÆÀ̵ð·Î home5.myhome.co.kr
¼­¹ö¿¡ Á¢¼ÓÇØ¼­, ÇѸÞÀÏ nonots@hanmail.net ÁÖ¼Ò·Î ¸ÞÀÏ º¸³½ ±â·ÏÀÔ´Ï´Ù.
ÇѸÞÀϼ­¹ö mx9.hanamil.net À¸·Î ¸ÞÀÏÀ» º¸³»¼­ stat=Sent °¡ ³ª¿Í¼­
Á¤»óÀûÀ¸·Î ¹ß¼ÛµÆÀ½À» ¾Ë ¼ö ÀÖ½À´Ï´Ù.
ù ¶óÀο¡ authid=nonots ¶ó´Â Á¢¼Ó ±â·ÏÀÌ º¸À̰í, Á¢¼ÓÇÑ sendmail ÇÁ·Î¼¼½º
¹øÈ£°¡ [31579] ¹øÀÔ´Ï´Ù.
ÀÌ ÇÁ·Î¼¼½º¿¡ ÀÇÇØ ½Äº°ÀÚ  pB17ZvAS031579 °¡ ºÎ¿©µÇ´Âµ¥, ÀÌ ½Äº°ÀÚÀÇ ¸¶Áö¸· ºÎºÐ¿¡
31579 ¶ó´Â ÇÁ·Î¼¼½º ¾ÆÀ̵ð°ªÀ» »ç¿ëÇÑ´Ù´Â Á¡À» À¯ÀÇÇØ¾ß ÇÕ´Ï´Ù.
ÀÌ ½Äº°ÀÚ¿¡ ÀÇÇØ¼­ /var/spool/mqueue ¿¡ ¸ÞÀÏ Çì´õÆÄÀÏÀÎ hfpB17ZvAS031579 ¿Í
µ¥ÀÌŸÆÄÀÏÀÎ dfpB17ZvAS031579 °¡ ÀϽÃÀûÀ¸·Î »ý±â°í, ¹ß¼Û ¿Ï·áÇÑ ÈÄ¿¡´Â mqueue
¿¡¼­ ÀÏÁ¤±â°£ ÈÄ ÀÚµ¿À¸·Î »èÁ¦°¡ µË´Ï´Ù.
ÀÌÁ¦ ÀÌ Æ¯Â¡À» ÀÌ¿ëÇØ¼­ ¸ÞÀϼ­¹ö ÇØÅ· ¿©ºÎ¸¦ Á¡°ËÇØ º¸°Ú½À´Ï´Ù.


3) maillog Á¡°Ë
- º¸Åë sendmail ·Î±×´Â /var/log¿¡ ÀúÀåµÇ°í 1 ÁÖÀϸ¶´Ù ¼­¹ö logrotate cron ¿¡ ÀÇÇØ
¹é¾÷ÀÌ µË´Ï´Ù.
maillog.1, maillog.2,maillog.3 ¿Í °°ÀÌ ¹é¾÷µÇ´Âµ¥, ¾î¶² ¼­¹ö¿¡¼­´Â
¾ÐÃà¹é¾÷À» ÇØ¼­, maillog.1.gz, maillog.2.gz.. ¿Í °°ÀÌ gz ¾ÐÃàµÇ¾î
ÀúÀåµÇ±âµµ ÇÕ´Ï´Ù.
·Î±× ºÐ¼®À» À§Çؼ­´Â Áö³­ ¹é¾÷ÆÄÀϱîÁö Àüü¸¦ °Ë»öÇϱâ À§ÇØ /var/log/maillog* ¿Í
°°ÀÌ ¿É¼ÇÀ» ÁÖ´Â °ÍÀÌ ÁÁ½À´Ï´Ù.
¾Æ·¡ grep ÀÌ ¾Æ´Ï¶ó zgrep À» »ç¿ëÇÑ ÀÌÀ¯´Â gz ·Î ¾ÐÃàµÈ°Ç ÀÚµ¿À¸·Î Ç®¾î¼­
°Ë»öÇϱâ À§ÇØ zgrep À» »ç¿ëÇß½À´Ï´Ù.
¸¸¾à ¹é¾÷ÆÄÀÏÀÌ ¾÷ÃàµÇÁö ¾Ê¾Ò´Ù¸é ±×³É grep À» »ç¿ëÇØµµ µË´Ï´Ù.

# zgrep "authid=" /var/log/maillog* | awk '{print $8}' | sort | uniq -c | grep authid | sort -r
  2972 authid=chung,
20 authid=kmlee,
13 authid=aychoi,
  8 authid=keom,
  7 authid=hyseong,
  6 authid=tsshyang,
...
ÀÌ ¸í·É¾î´Â ¾Æ¿ô·è °°Àº ¸ÞÀÏŬ¶óÀÌ¾ðÆ®¿¡¼­ Á¤»óÀûÀ¸·Î °èÁ¤¿¡ ·Î±×ÀÎÇÑ Á¤º¸¸¦
¸ÞÀϷα׿¡¼­  ÃßÃâÇÏ¿©¼­ °¢ ¾ÆÀ̵𠺰·Î Åë°è¸¦ ³½ °Ì´Ï´Ù.
auth=?? ¿Í °°ÀÌ ·Î±×ÀÎ ¼º°øÇÑ ¶óÀο¡¼­ °ø¹é¹®ÀÚ¸¦ ±âÁØÀ¸·Î cut À» ÇØ¼­ 8 ¹øÂ°
Çʵ带 »Ì¾Æ³½ ÈÄ °°Àº ¾ÆÀ̵𸦠ÇÕ»êÇÑ ÈÄ Á¤·ÄÇѰ̴ϴÙ.
À§¿¡¼­, ÇØÅ·´çÇÑ chung ¶ó´Â °èÁ¤ÀÌ 2972¹øÀ¸·Î °¡Àå ¸¹ÀÌ Á¢¼ÓÇßÀ½À» ¾Ë ¼ö ÀÖ½À´Ï´Ù.
±×¸®°í ¸ÞÀÏÀ» ¹ß¼ÛÇÑ ip º°·Î º¸·Á¸é

# zgrep "authid=" /var/log/maillog* |  awk '{print $7}' | sort | grep relay |  uniq -c | sort -r
  2972 relay=[194.51.238.89],
23 relay=[121.166.xxx.xxx],
19 relay=[112.158.73.131],
12 relay=[183.98.111.130],
  8 relay=[116.121.255.202],
...
¿Í °°ÀÌ 194.51.238.89 ¾ÆÀÌÇÇ¿¡¼­ Á¦ÀÏ ¸¹ÀÌ Á¢¼ÓÇÑ°É ¾Ë¼ö ÀÖ½À´Ï´Ù.
ÀÌ ¾ÆÀÌÇǰ¡ chung °èÁ¤À» ÀÌ¿ëÇÑ °ÍÀ¸·Î ÃßÃøÇÒ ¼ö ÀÖ½À´Ï´Ù.
½ÇÁ¦·Î maillog ÆÄÀÏÀ» ¿¡µðÅÍ·Î ¿­¾î¼­ authid=chung ³ª 194.51.238.89 µîÀ»
°Ë»öÇØ¼­ º¸¸é
..
41628 Nov 28 20:07:23 home7 sendmail[15541]: AUTH=server, relay=[194.51.238.89], authid=chung, mech=LOGIN, bits=0 41629 Nov 28 20:07:23 home7 sendmail[15539]: AUTH=server, relay=[194.51.238.89], authid=chung, mech=LOGIN, bits=0
41630 Nov 28 20:07:23 home7 sendmail[15540]: AUTH=server, relay=[194.51.238.89], authid=chung, mech=LOGIN, bits=0  41631 Nov 28 20:07:23 home7 sendmail[15554]: AUTH=server, relay=[194.51.238.89], authid=chung, mech=LOGIN, bits=0
41632 Nov 28 20:07:23 home7 sendmail[15555]: AUTH=server, relay=[194.51.238.89], authid=chung, mech=LOGIN, bits=0
41633 Nov 28 20:08:13 home7 sendmail[15540]: pASB7Bop015540: from=<co@e-lupeni.ro>, size=596, class=0, nrcpts=50, msgid=<201111281107.pASB7Bop01554      0@home7.myhome.co.kr>, proto=ESMTP, daemon=MTA, relay=[194.51.238.89]
41634 Nov 28 20:08:13 home7 sendmail[15540]: pASB7Bop015540: Milter add: header: X-Virus-Scanned: clamav-milter 0.97.2 at home7.myhome.co.kr
41635 Nov 28 20:08:13 home7 sendmail[15540]: pASB7Bop015540: Milter add: header: X-Virus-Status: Clean
41636 Nov 28 20:08:14 home7 sendmail[15542]: pASB7Bi0015542: from=<co@e-lupeni.ro>, size=596, class=0, nrcpts=50, msgid=<201111281107.pASB7Bi001554      2@home7.myhome.co.kr>, proto=ESMTP, daemon=MTA, relay=[194.51.238.89]
..
¿Í °°ÀÌ µÇ¾î ÀÖ½À´Ï´Ù.
11¿ù 28ÀÏ 20½Ã 7ºÐ¿¡ Á¢¼ÓÇØ¼­ co@e-lupeni.ro ¸¦ ¹ß¼ÛÀÚ·Î ÇØ¼­ ½ºÆÔ¸ÞÀÏÀ»
¹ß¼ÛÇÑ°É ¾Ë ¼ö ÀÖ½À´Ï´Ù.
¾Æ¸¶ ÀÌ·± ¹ß¼ÛÀÌ ¼ö¹é ¼öõ°ÇÀÌ º¸Àϰ̴ϴÙ. ºô¾î¸ÔÀ»..


3) ½Ç½Ã°£ ½ºÆÔ ¹ß¼Û ´ëÀÀ
- ¸¸¾à ÇöÀç ½Ã°¢À¸·Î ¼­¹ö¿¡¼­ ½ºÆÔÀÌ ¿­³ª°Ô ¹ß¼ÛµÇ°í ÀÖÀ» °æ¿ì
¿ì¼± ¾Æ·¡¿Í °°ÀÌ ps ¸í·É¾î·Î º¸¸é ¾Æ·¡¿Í °°Àº sendmail ÇÁ·Î¼¼½º°¡ º¸ÀÔ´Ï´Ù.

# ps aux
...
root      6839  0.0  0.1  69232  2996 ?        S    15:14  0:00 sendmail: ./pB26E7mm006835 from queue
...
ÀÌ °æ¿ì ½Äº°ÀÚ pB26E7mm006835 ¿¡¼­ ³¡ºÎºÐ ¼ýÀÚ 6835 ¹ø ÇÁ·Î¼¼½º¿¡ ÀÇÇØ¼­
¹ß¼ÛµÆÀ½À» ¾Ë ¼ö ÀÖ½À´Ï´Ù.
À§¿¡¼­ ¸»ÇßµíÀÌ /var/spool/mqueue ¿¡ dfpB26E7mm006835, hfpB26E7mm006835 ÆÄÀÏÀÌ ÀÖÀ» °Ì´Ï´Ù.
·Î±×ÆÄÀÏ¿¡¼­ ÀÌ ¹øÈ£·Î ¹ß¼Û±â·ÏÀ» ã¾Æº¸¸é

# grep "\[6835\]" /var/log/maillog
..
Dec  2 15:14:10 home7 sendmail[6835]: AUTH=server, relay=[121.166.xxx.xxx], authid=jychoi, mech=LOGIN, bits=0
Dec  2 15:14:10 home7 sendmail[6835]: pB26E7mm006835: from=<jychoi@aaabbb.com>, size=90127, class=0, nrcpts=1, msgid=<000001ccb0b9$9b14ed20$d13ec760$@com>, proto=ESMTP, daemon=MTA, relay=[121.166.xxx.xxx]
Dec  2 15:14:10 home7 sendmail[6835]: pB26E7mm006835: Milter add: header: X-Virus-Scanned: clamav-milter 0.97.2 at home7.myhome.co.kr
Dec  2 15:14:10 home7 sendmail[6835]: pB26E7mm006835: Milter add: header: X-Virus-Status: Clean
..
¿Í °°ÀÌ °Ë»öÀÌ µÉ°Ì´Ï´Ù
grep °Ë»ö¿¡¼­ [, ] ¹®ÀÚ¸¦ »ç¿ëÇÏ·Á¸é À§¿Í °°ÀÌ ¿ª½½·¡½Ã·Î ó¸®ÇØ Áà¾ß ÇÕ´Ï´Ù.
¸¸¾à ³Ê¹« ±æ¾î¼­ º¸±â Èûµé´Ù¸é authid= ºÎºÐ¸¸ °Ë»öÇØ¼­ ¾î´À °èÁ¤À¸·Î
¹ß¼Û ÁßÀÎÁö ¾Ë ¼ö ÀÖ½À´Ï´Ù.

# grep "\[6835\]" /var/log/maillog | grep authid
Dec  2 15:14:10 home7 sendmail[6835]: AUTH=server, relay=[121.166.xxx.xxx], authid=jychoi, mech=LOGIN, bits=0
..
¿Í °°ÀÌ jychoi ¶ó´Â °èÁ¤À¸·Î 121.166.xxx.xxx ¿¡¼­ Á¢¼ÓÇØ¼­ ¸ÞÀÏÀ»
¹ß¼Û ÁßÀÔ´Ï´Ù.
¸¸¾à ÀÌ ¹ß¼ÛÀÌ Á¤»óÀÌ ¾Æ´Ï¶ó ½ºÆÔ ÀǽÉÀÌ µÈ´Ù¸é À§¿¡¼­ °Ë»öÇÑ
# zgrep "authid=" /var/log/maillog* | awk '{print $8}' | sort | uniq -c | grep authid | sort -r
ÀÇ °á°ú¸¦ º¸°Å³ª ±âŸ ¹æ¹ýÀ¸·Î ½ºÆÔ ¿©ºÎ¸¦ ÆÇ´ÜÇÏ¸é µË´Ï´Ù.
½ÇÁ¦ jychoi »ç¿ëÀÚ¿¡°Ô ÀüÈ­ÇØ¼­ Áö±Ý ¸ÞÀÏ ¹ß¼ÛÁßÀÎÁö ¹°¾îº¼ ¼öÀÖ´Ù¸é Á¦ÀÏ Á¤È®ÇϰÚÁÒ.
±×¸®°í º¸Åë ½ºÆÔÀº ´ÊÀº¹ãÀ̳ª »õº® ½Ã°£´ë¿¡ º¸³»¹Ç·Î ¹ß¼Û ½Ã°£À» º¸°í
¾î´ÀÁ¤µµ ÃßÁ¤ÇÒ ¼öµµ ÀÖ½À´Ï´Ù.


5) ½ºÆÔ¹ß¼ÛÀÏ °æ¿ì ´ëó ¹æ¹ý
- Àå³­ÀÌ ¾Æ´Ï¶ó¸é ¸ðµç ¸ÞÀϷα׸¦ ¾ÐÃàÇØ¼­ º¸°üÇϰí "±â°ü"¿¡ ½Å°íÇÏ¸é µË´Ï´Ù.
  ±ÍÂú¾Æ¼­ ±×³É ÀÚü ÇØ°áÇÏ·Á¸é,

(0) sendmail µ¥¸óÀ» ÁßÁöÇÕ´Ï´Ù.

(1) ¿ì¼± ½ºÆÔ ¹ß¼ÛÇÑ ID °èÁ¤À» Æó¼âÇϰųª, ȤÀº ½ÇÁ¦ »ç¿ëÀÚ¿¡°Ô ¿¬¶ôÇØ¼­
ºñ¹Ð¹øÈ£¸¦ ¼öÁ¤Çϵµ·Ï °­Á¦ÇÕ´Ï´Ù.

(2) ÇØÅ· ÀǽɵǴ IP ¸¦ Â÷´ÜÇÕ´Ï´Ù. ¾Æ·¡¿Í °°ÀÌ iptables ·Î ÇØµµ µÇ°í
# iptables -I INPUT -s 194.51.238.89 -j DROP
# iptables -I OUTPUT -s 194.51.238.89 -j DROP
/etc/mail/access ÆÄÀÏÀ̳ª, /etc/hosts.deny µîÀ» ÀÌ¿ëÇϰųª
ÇÏ¿©Æ°, ¹æÈ­º®¿¡¼­ ¸·À» ¼ö ÀÖ´Â ¸ðµç ¼ö´ÜÀ» µ¿¿øÇØ ¸·½À´Ï´Ù.

(3) /var/spool/mqueue ¸¦ û¼ÒÇÕ´Ï´Ù.
¾ÆÀ̵𳪠¾ÆÀÌÇǸ¦ Â÷´ÜÇØµµ sendmail µ¥¸óÀÇ Å¥¿¡ ÀúÀåµÈ °Ç ÀÏÁ¤½Ã°£ °è¼Ó
¹ß¼ÛÇÏ·Á°í ½ÃµµÇÏ°Ô µË´Ï´Ù.
194.51.238.89 ÀÌ ¾ÆÀÌÇÇ·Î »ý¼ºµÈ Å¥ÀÇ ÀÓ½ÃÆÄÀÏÀ»
¾Æ·¡¿Í °°ÀÌ Àϰý »èÁ¦ °¡´ÉÇÕ´Ï´Ù.
# grep -l 194.51.238.89 /var/spool/mqueue/* | xargs -i rm -f {}

(4) sendmail µ¥¸óÀ» Àç½ÃÀÛÇÕ´Ï´Ù.
¾Æ¸¶ Àç½ÃÀÛÇØµµ ÀÏÁ¤½Ã°£ µ¿¾È  Å¥¿¡ ÀÖ´Â ÆÄÀÏ ¶§¹®¿¡ ÀϺΠ½ºÆÔ ¹ß¼Û
½Ãµµ°¡ ÀÖÀ»¼ö ÀÖ½À´Ï´Ù. ±×°Ç ¼öµ¿À¸·Î Å¥ÆÄÀÏ À̸§À» È®ÀÎÇØ¼­
»èÁ¦ÇØ ÁÖ¸é µË´Ï´Ù.



5. ¸¶¹«¸®

ÁøÀλç´ëõ¸íÇß´Â µ¥µµ °è¼Ó ½ºÆÔ¸ÞÀÏÀÌ ¹ß¼ÛµÈ´Ù¸é
±×³É Áñ.±â.½Ã.±æ. -_-;;

Àüü´ñ±Û¼ö 5

  • ±â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§Ç®ÀÙ 11-12-03 03:57

    ¼Ò½ºº¸±â

  • ¸¶¹«¸®°¡.............. ³Ê¹« ½½ÇÅ´Ï´Ù.... ¤£
  • ±â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§Çϴûç¶û 11-12-05 10:18

    ¼Ò½ºº¸±â

  • ÁÁÀº ÀÚ·á °¨»çÇÕ´Ï´Ù.
    ²Ù¹÷~
  • ±â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§µ¶°Åû³â 11-12-05 18:33

    ¼Ò½ºº¸±â

  • cut À¸·Î ·Î±×ÆÄÀÏ ºÐ¼®ÇÏ´ø°É awk ·Î º¯°æÇß½À´Ï´Ù.
  • ±â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§¼ÒÇÁƼ 11-12-11 14:39

    ¼Ò½ºº¸±â

  • ÁÁÀº ÀÚ·á °¨»çÇÕ´Ï´Ù.
  • ±â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§¿ìÁÖ±«¹° 12-04-20 09:17

    ¼Ò½ºº¸±â

  • ÁÁÀº Á¤º¸ Àß ÀÐ°í °©´Ï´Ù.
  • °Ô½Ã¹° 12,482°Ç RSS
¹øÈ£ºÐ·ùÁ¦¸ñ±Û¾´À̳¯Â¥Á¶È¸
12,422 HTML È¿À²ÀûÀÎ CSS ÀÛ¼ºÇϱâ [6] ¸µÅ© Àα⠱â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§Æø½ºÅ׸®¾î 13-03-04 1235
12,421 Á¤º¸ Editor tool Ç÷¯±×ÀÎ emmet (±¸, ZenCoding) [9] ¸µÅ© ±â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§Æø½ºÅ׸®¾î 13-03-01 906
12,420 ±âŸ °¡·Î¼¼·Î ³¹¸»¸ÂÃ߱⠸µÅ© ±â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§Æø½ºÅ׸®¾î 13-03-01 598
12,419 ºê¶ó¿ìÀú CSS Browser Selector IE 10 ´ëÀÀ [10] ±â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§¼ÛÈ¿Áø 13-02-28 975
12,418 HTML scss (sass) ¼Ò°³ ¹× À©µµ ¼³Á¤ ¹æ¹ý [5] ¸µÅ© ±â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§¼ÛÈ¿Áø 13-02-27 648
12,417 ½ºÅ©¸³Æ® Restful API¸¦ Á¦°øÇϴµ¥ ¾µ¸¸ÇÑ framework ¸µÅ© ±â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§Æø½ºÅ׸®¾î 13-02-27 649
12,416 Á¤º¸ µµ·Î¸í ¿ìÆíÁÖ¼Ò (¾÷µ¥ÀÌÆ®, À¥È£½ºÆÃ, ¿µ¹® »ç¿ë°¡´É) [2] ÷ºÎÆÄÀÏ ±â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§casis 13-02-26 755
12,415 ¼­¹ö¿î¿µ ÁÖ±âÀûÀÎ ·ÎÄÃ>¸®¸ðÆ® rsync ½Ã mtime °Ë»ç·Î ¿äû ÁÙÀ̱â [1] ±â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§¼ÛÈ¿Áø 13-02-26 482
12,414 HTML Google Chrome 25 CSS ¹ö±×. inline-block Ç¥½Ã [1] ¸µÅ© ±â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§Æø½ºÅ׸®¾î 13-02-26 571
12,413 HTML À¥ÆùÆ® ¾ÆÀÌÄÜ Font Awesome [6] ¸µÅ© Àα⠱â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§¼ÛÈ¿Áø 13-02-22 1102
12,412 ½ºÅ©¸³Æ® ¼­¹ö¿¡¼­ ºê¶ó¿ìÀú¸¦ ¸¾´ë·Î ÄÁÆ®·ÑÇÏ´Â casper.js [3] Àα⠱â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§Å©¾î¾ï123 13-02-22 1064
12,411 ½ºÅ©¸³Æ® ÀÚ¹Ù½ºÅ©¸³Æ® ¹®ÀÚ¿­ ¿¬»êÇÒ ¶§ ÃÖ°í ºü¸¥°Í [2] ¸µÅ© ±â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§Æø½ºÅ׸®¾î 13-02-22 745
12,410 ½ºÅ©¸³Æ® NodeJS ±â¹ÝÀÇ NET ¸ðµâ·Î ±¸ÇöÇÑ À¥ ¼­¹ö [7] ¸µÅ© ±â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§¹®ÇÐû³â 13-02-20 880
12,409 ½ºÅ©¸³Æ® JavaScript Garden, ¾Ë½ö´Þ½öÇÑ ÀÚ½º ¹®¹ýÀ» ±ò²ûÈ÷ [8] ¸µÅ© ±â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§Æø½ºÅ׸®¾î 13-02-20 774
12,408 ½ºÅ©¸³Æ® ¼ø¼ö ÀÚ¹Ù½ºÅ©¸³Æ®·Î ±¸ÇöÇÑ Simple jQuery [10] ¸µÅ© Àα⠱â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§¹®ÇÐû³â 13-02-19 1185
12,407 ±âŸ ÇÁ¸®Ã§ °Ô½ÃÆÇ °¡Á®¿À±â ¼Ò½º [2] ÷ºÎÆÄÀÏ Àα⠱â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§¾Æ´Ï¿À 13-02-14 1715
12,406 Á¤º¸ À¥ÆùÆ® ¾øÀÌ ¿¹»Û ÇÑ±Û ±Û²Ã »ç¿ëÇϱâ (À̹ÌÁö ÀÚµ¿»ý¼º) [14] ¸µÅ© Àα⠱â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§°õÅÊÀÌǪ 13-02-12 1521
12,405 ±âŸ ¿µ¹® ¿Â¶óÀÎ Çʱâ ÀÎ½Ä [2] ¸µÅ© ÷ºÎÆÄÀÏ ±â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§wkpark 13-02-09 888
12,404 DBMS mysql bin log º¹±¸ [6] ±â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§¼ÛÈ¿Áø 13-02-07 902
12,403 DBMS [mssql] group by + case¿Í where+group byÀÇ ºñ±³ [7] ¸µÅ© ±â¼ú·¹º§Ä¿¹Â´ÏƼ·¹º§º½µ¹#3141 13-02-06 714
 
12345678910