邮件服务器被当跳板,怎么办?
时间:2010-08-17
来源:互联网
我们有一台邮件服务器 是Sun Java(tm) System Messaging Server 6的
运行在solaris上
从日志中发现有人使用我们的邮件服务器转发邮件,导致我们自己发送邮件的速度很慢。
找了好久也不知道如何关闭open relay
现在我只想确认是否真的开启了open relay(匿名转发)
有测试结果了,我就奇怪了,我也没开open relay,为什么有人用我们邮件服务器转发呢
Relay Tester:
Testing email.szns.gov.cn...
Connecting to email.szns.gov.cn ...
<<< 220 email-2.szns.gov.cn -- Server ESMTP (Sun Java(tm) System Messaging Server 6.3-6.03 (built Mar 14 2008; 32bit))
>>> HELO godfather.mob.net
<<< 250 email-2.szns.gov.cn OK, [207.191.217.113].
>>> MAIL FROM:
<<< 250 2.5.0 Address Ok.
>>> RCPT TO:
<<< 550 5.7.1 Relaying not allowed: [email protected]
log如下:
16-Aug-2010 17:31:11.76 process D 58 rfc822;[email protected] [email protected]
16-Aug-2010 17:31:12.48 tcp_local DE 59 rfc822;[email protected] [email protected] dns;mx3.qq.com (newmx42.qq.com MX
QQ Mail Server) smtp;250 Ok
16-Aug-2010 17:31:38.00 ims-ms Q 80 rfc822;[email protected] rdeasy@ims-ms-daemon Over quota Over quota
16-Aug-2010 17:31:39.47 tcp_auth tcp_local EEAC 4 [email protected] rfc822;[email protected] [email protected]
16-Aug-2010 17:31:39.61 tcp_auth tcp_local EEAC 4 [email protected] rfc822;[email protected] [email protected]
et.net
16-Aug-2010 17:31:39.65 tcp_auth tcp_local EEAC 4 [email protected] rfc822;[email protected] [email protected]
16-Aug-2010 17:31:39.65 tcp_auth tcp_local EEAC 4 [email protected] rfc822;[email protected] [email protected]
m.tw
16-Aug-2010 17:31:39.65 tcp_auth tcp_local EEAC 4 [email protected] rfc822;[email protected] [email protected]
16-Aug-2010 17:31:39.65 tcp_auth tcp_local EEAC 4 [email protected] rfc822;[email protected] pallashuang2004@yaho
o.com.tw
16-Aug-2010 17:31:39.65 tcp_auth tcp_local EEAC 4 [email protected] rfc822;[email protected] [email protected]
16-Aug-2010 17:31:39.65 tcp_auth tcp_local EEAC 4 [email protected] rfc822;[email protected] [email protected]
16-Aug-2010 17:31:39.65 tcp_auth tcp_local EEAC 4 [email protected] rfc822;[email protected] [email protected]
16-Aug-2010 17:31:39.65 tcp_auth tcp_local EEAC 4 [email protected] rfc822;[email protected] [email protected]
16-Aug-2010 17:31:39.65 tcp_auth tcp_local EEAC 4 [email protected] rfc822;[email protected] [email protected]
16-Aug-2010 17:31:55.02 tcp_local DE 4 [email protected] rfc822;[email protected] [email protected] dns;ms6a.
hinet.net (msx-sg1-14.hinet.net ESMTP Sendmail 8.8.8/8.8.8; Mon, 16 Aug 2010 16:44:49 +0800 [CST]) smtp;250 <[email protected]>..
. Recipient ok
运行在solaris上
从日志中发现有人使用我们的邮件服务器转发邮件,导致我们自己发送邮件的速度很慢。
找了好久也不知道如何关闭open relay
现在我只想确认是否真的开启了open relay(匿名转发)
有测试结果了,我就奇怪了,我也没开open relay,为什么有人用我们邮件服务器转发呢
Relay Tester:
Testing email.szns.gov.cn...
Connecting to email.szns.gov.cn ...
<<< 220 email-2.szns.gov.cn -- Server ESMTP (Sun Java(tm) System Messaging Server 6.3-6.03 (built Mar 14 2008; 32bit))
>>> HELO godfather.mob.net
<<< 250 email-2.szns.gov.cn OK, [207.191.217.113].
>>> MAIL FROM:
<<< 250 2.5.0 Address Ok.
>>> RCPT TO:
<<< 550 5.7.1 Relaying not allowed: [email protected]
log如下:
16-Aug-2010 17:31:11.76 process D 58 rfc822;[email protected] [email protected]
16-Aug-2010 17:31:12.48 tcp_local DE 59 rfc822;[email protected] [email protected] dns;mx3.qq.com (newmx42.qq.com MX
QQ Mail Server) smtp;250 Ok
16-Aug-2010 17:31:38.00 ims-ms Q 80 rfc822;[email protected] rdeasy@ims-ms-daemon Over quota Over quota
16-Aug-2010 17:31:39.47 tcp_auth tcp_local EEAC 4 [email protected] rfc822;[email protected] [email protected]
16-Aug-2010 17:31:39.61 tcp_auth tcp_local EEAC 4 [email protected] rfc822;[email protected] [email protected]
et.net
16-Aug-2010 17:31:39.65 tcp_auth tcp_local EEAC 4 [email protected] rfc822;[email protected] [email protected]
16-Aug-2010 17:31:39.65 tcp_auth tcp_local EEAC 4 [email protected] rfc822;[email protected] [email protected]
m.tw
16-Aug-2010 17:31:39.65 tcp_auth tcp_local EEAC 4 [email protected] rfc822;[email protected] [email protected]
16-Aug-2010 17:31:39.65 tcp_auth tcp_local EEAC 4 [email protected] rfc822;[email protected] pallashuang2004@yaho
o.com.tw
16-Aug-2010 17:31:39.65 tcp_auth tcp_local EEAC 4 [email protected] rfc822;[email protected] [email protected]
16-Aug-2010 17:31:39.65 tcp_auth tcp_local EEAC 4 [email protected] rfc822;[email protected] [email protected]
16-Aug-2010 17:31:39.65 tcp_auth tcp_local EEAC 4 [email protected] rfc822;[email protected] [email protected]
16-Aug-2010 17:31:39.65 tcp_auth tcp_local EEAC 4 [email protected] rfc822;[email protected] [email protected]
16-Aug-2010 17:31:39.65 tcp_auth tcp_local EEAC 4 [email protected] rfc822;[email protected] [email protected]
16-Aug-2010 17:31:55.02 tcp_local DE 4 [email protected] rfc822;[email protected] [email protected] dns;ms6a.
hinet.net (msx-sg1-14.hinet.net ESMTP Sendmail 8.8.8/8.8.8; Mon, 16 Aug 2010 16:44:49 +0800 [CST]) smtp;250 <[email protected]>..
. Recipient ok
作者: h4x0r 发布时间: 2010-08-17
别人没有你的邮件帐号也能用。是不是被黑了。
作者: renxiao2003 发布时间: 2010-08-17
相关阅读 更多
热门阅读
-
office 2019专业增强版最新2021版激活秘钥/序列号/激活码推荐 附激活工具
阅读:74
-
如何安装mysql8.0
阅读:31
-
Word快速设置标题样式步骤详解
阅读:28
-
20+道必知必会的Vue面试题(附答案解析)
阅读:37
-
HTML如何制作表单
阅读:22
-
百词斩可以改天数吗?当然可以,4个步骤轻松修改天数!
阅读:31
-
ET文件格式和XLS格式文件之间如何转化?
阅读:24
-
react和vue的区别及优缺点是什么
阅读:121
-
支付宝人脸识别如何关闭?
阅读:21
-
腾讯微云怎么修改照片或视频备份路径?
阅读:28