AskOverflow.Dev

AskOverflow.Dev Logo AskOverflow.Dev Logo

AskOverflow.Dev Navigation

  • 主页
  • 系统&网络
  • Ubuntu
  • Unix
  • DBA
  • Computer
  • Coding
  • LangChain

Mobile menu

Close
  • 主页
  • 系统&网络
    • 最新
    • 热门
    • 标签
  • Ubuntu
    • 最新
    • 热门
    • 标签
  • Unix
    • 最新
    • 标签
  • DBA
    • 最新
    • 标签
  • Computer
    • 最新
    • 标签
  • Coding
    • 最新
    • 标签
主页 / server / 问题 / 758165
Accepted
kojow7
kojow7
Asked: 2016-02-19 08:43:49 +0800 CST2016-02-19 08:43:49 +0800 CST 2016-02-19 08:43:49 +0800 CST

打开继电器还是其他问题?

  • 772

我正在运行带有虚拟用户/别名的 dovecot/postfix 服务器。根据http://www.mailradar.com/openrelay/等工具,我没有任何开放中继。但是,我的系统日志中显示了很多记录,这会导致我认为正在访问不应访问的某些内容。这是我的系统日志的一部分(当然更改了自我识别信息):

Feb 18 10:13:42 server1 postfix/pickup[3995]: 1A6413627F: uid=33 from=<www-data>
Feb 18 10:13:42 server1 postfix/cleanup[3826]: 1A6413627F: message-id=<20160218161342.1A6413627F@server1.myserverdomain.com>
Feb 18 10:13:42 server1 opendkim[4285]: 1A6413627F: no signing table match for 'noreply@server1.myserverdomain.com'
Feb 18 10:13:42 server1 opendkim[4285]: 1A6413627F: no signature data
Feb 18 10:13:42 server1 postfix/qmgr[4479]: 1A6413627F: from=<www-data@myemaildomain.com>, size=2153, nrcpt=1 (queue active)
Feb 18 10:13:43 server1 postfix/smtp[4007]: 1A6413627F: to=<a...a@mail.ru>, relay=mxs.mail.ru[217.69.139.150]:25, delay=1.9, delays=0.01/0/0.77/1.1, dsn=2.0.0, status=sent (250 OK id=1aWRD5-0005o9-J0)
Feb 18 10:13:43 server1 postfix/qmgr[4479]: 1A6413627F: removed


Feb 18 10:13:54 server1 postfix/pickup[3995]: 5CF523627F: uid=33 from=<www-data>
Feb 18 10:13:54 server1 postfix/cleanup[3826]: 5CF523627F: message-id=<20160218161354.5CF523627F@server1.myserverdomain.com>
Feb 18 10:13:54 server1 opendkim[4285]: 5CF523627F: no signing table match for 'noreply@server1.myserverdomain.com'
Feb 18 10:13:54 server1 opendkim[4285]: 5CF523627F: no signature data
Feb 18 10:13:54 server1 postfix/qmgr[4479]: 5CF523627F: from=<www-data@myemaildomain.com>, size=2158, nrcpt=1 (queue active)
Feb 18 10:13:55 server1 kernel: iptables denied: IN=eth0 OUT= MAC=a3:5d:83:43:56:f1:97:d4:35:6f:48:b9:08:00 SRC=45.33.58.84 DST=216.58.192.14 LEN=73 TOS=0x00 PREC=0x00 TTL=63 ID=45696 PROTO=UDP SPT=53 DPT=51450 LEN=53 
Feb 18 10:13:55 server1 postfix/smtp[3982]: 5CF523627F: to=<y...s@mail.ru>, relay=mxs.mail.ru[217.69.139.150]:25, delay=1.6, delays=0.01/0/0.55/1, dsn=2.0.0, status=sent (250 OK id=1aWRDH-0003yi-IS)
Feb 18 10:13:55 server1 postfix/qmgr[4479]: 5CF523627F: removed


Feb 18 10:14:02 server1 postfix/pickup[3995]: A72D73627F: uid=33 from=<www-data>
Feb 18 10:14:02 server1 postfix/cleanup[3826]: A72D73627F: message-id=<20160218161402.A72D73627F@server1.myserverdomain.com>
Feb 18 10:14:02 server1 opendkim[4285]: A72D73627F: no signing table match for 'noreply@server1.myserverdomain.com'
Feb 18 10:14:02 server1 opendkim[4285]: A72D73627F: no signature data
Feb 18 10:14:02 server1 postfix/qmgr[4479]: A72D73627F: from=<www-data@myemaildomain.com>, size=2172, nrcpt=1 (queue active)
Feb 18 10:14:02 server1 postfix/smtp[4002]: A72D73627F: to=<c....8@gmail.com>, relay=gmail-smtp-in.l.google.com[2607:f8b0:400e:c03::1b]:25, delay=0.24, delays=0.01/0/0.09/0.14, dsn=2.0.0, status=sent (250 2.0.0 OK 1455812042 u6si8951789par.57 - gsmtp)
Feb 18 10:14:02 server1 postfix/qmgr[4479]: A72D73627F: removed

Feb 18 10:14:44 server1 kernel: iptables denied: IN=eth0 OUT= MAC=a3:5d:83:43:56:f1:97:d4:35:6f:f2:a4:08:00 SRC=181.194.185.98 DST=216.58.192.14 LEN=60 TOS=0x00 PREC=0x00 TTL=52 ID=33433 DF PROTO=TCP SPT=54753 DPT=23 WINDOW=5808 RES=0x00 SYN URGP=0 
Feb 18 10:14:47 server1 kernel: iptables denied: IN=eth0 OUT= MAC=a3:5d:83:43:56:f1:97:d4:35:6f:f2:a4:08:00 SRC=181.194.185.98 DST=216.58.192.14 LEN=60 TOS=0x00 PREC=0x00 TTL=52 ID=33434 DF PROTO=TCP SPT=54753 DPT=23 WINDOW=5808 RES=0x00 SYN URGP=0 
Feb 18 10:14:53 server1 kernel: iptables denied: IN=eth0 OUT= MAC=a3:5d:83:43:56:f1:97:d4:35:6f:f2:a4:08:00 SRC=181.194.185.98 DST=216.58.192.14 LEN=60 TOS=0x00 PREC=0x00 TTL=52 ID=33435 DF PROTO=TCP SPT=54753 DPT=23 WINDOW=5808 RES=0x00 SYN URGP=0 
Feb 18 10:15:01 server1 /USR/SBIN/CRON[4054]: (root) CMD (command -v debian-sa1 > /dev/null && debian-sa1 1 1)

Feb 18 10:15:02 server1 postfix/pickup[3995]: CDA813627F: uid=33 from=<www-data>
Feb 18 10:15:02 server1 postfix/cleanup[3826]: CDA813627F: message-id=<20160218161502.CDA813627F@server1.myserverdomain.com>
Feb 18 10:15:02 server1 opendkim[4285]: CDA813627F: no signing table match for 'noreply@server1.myserverdomain.com'
Feb 18 10:15:02 server1 opendkim[4285]: CDA813627F: no signature data
Feb 18 10:15:02 server1 postfix/qmgr[4479]: CDA813627F: from=<www-data@myemaildomain.com>, size=2141, nrcpt=1 (queue active)
Feb 18 10:15:03 server1 postfix/smtp[4007]: CDA813627F: host mta6.am0.yahoodns.net[98.138.112.35] said: 421 4.7.0 [GL01] Message from (216.58.192.14) temporarily deferred - 4.16.50. Please refer to http://postmaster.yahoo.com/errors/postmaster-21.html (in reply to MAIL FROM command)
Feb 18 10:15:03 server1 postfix/smtp[4007]: CDA813627F: lost connection with mta6.am0.yahoodns.net[98.138.112.35] while sending RCPT TO
Feb 18 10:15:04 server1 postfix/smtp[4007]: CDA813627F: to=<s...6@yahoo.com>, relay=mta6.am0.yahoodns.net[66.196.118.34]:25, delay=1.3, delays=0.02/0/0.49/0.77, dsn=2.0.0, status=sent (250 ok dirdel)
Feb 18 10:15:04 server1 postfix/qmgr[4479]: CDA813627F: removed

任何想法是什么问题?

postfix
  • 1 1 个回答
  • 73 Views

1 个回答

  • Voted
  1. Best Answer
    Michael Hampton
    2016-02-19T09:03:53+08:002016-02-19T09:03:53+08:00

    这些消息源自运行 Web 服务器及其 Web 应用程序的用户 ID。简而言之,您的网站已被黑客入侵,并被用于发送垃圾邮件。

    • 2

相关问题

  • Postfix 在特定端口上接受邮件

  • 让 Postfix 以两种方式处理垃圾邮件

  • Postfix 或 exim:自动/程序化和转发电子邮件设置

  • 后缀电子邮件地址

  • 什么是最好的开源电子邮件解决方案包

Sidebar

Stats

  • 问题 205573
  • 回答 270741
  • 最佳答案 135370
  • 用户 68524
  • 热门
  • 回答
  • Marko Smith

    新安装后 postgres 的默认超级用户用户名/密码是什么?

    • 5 个回答
  • Marko Smith

    SFTP 使用什么端口?

    • 6 个回答
  • Marko Smith

    命令行列出 Windows Active Directory 组中的用户?

    • 9 个回答
  • Marko Smith

    什么是 Pem 文件,它与其他 OpenSSL 生成的密钥文件格式有何不同?

    • 3 个回答
  • Marko Smith

    如何确定bash变量是否为空?

    • 15 个回答
  • Martin Hope
    Tom Feiner 如何按大小对 du -h 输出进行排序 2009-02-26 05:42:42 +0800 CST
  • Martin Hope
    Noah Goodrich 什么是 Pem 文件,它与其他 OpenSSL 生成的密钥文件格式有何不同? 2009-05-19 18:24:42 +0800 CST
  • Martin Hope
    Brent 如何确定bash变量是否为空? 2009-05-13 09:54:48 +0800 CST
  • Martin Hope
    cletus 您如何找到在 Windows 中打开文件的进程? 2009-05-01 16:47:16 +0800 CST

热门标签

linux nginx windows networking ubuntu domain-name-system amazon-web-services active-directory apache-2.4 ssh

Explore

  • 主页
  • 问题
    • 最新
    • 热门
  • 标签
  • 帮助

Footer

AskOverflow.Dev

关于我们

  • 关于我们
  • 联系我们

Legal Stuff

  • Privacy Policy

Language

  • Pt
  • Server
  • Unix

© 2023 AskOverflow.DEV All Rights Reserve