|
服务器日志里不断的有被些用户连接进行验证.但是把这些用户删除掉后,还是有.
一般过一晚,在spool里面就会有大量的垃圾邮件
查看queue队列.里面收信人与发信人都不是本地的域名.
服务器是不是被 人利用发送垃圾邮件了啊.
各GGJJ们,指导指导啊.
IMAIL 8.22
以下是日志信息(della,wendy这两个用户早就已经被删除了.)
08:14 10:39 SMTPD(ba7b015b000000c3) [211.154.145.13] connect 42.49.140.137 port 3180
08:14 10:39 SMTPD(ba7b015b000000c3) [42.49.140.137] EHLO qrekfxwxkg
08:14 10:39 SMTPD(ba7b015b000000c3) [42.49.140.137] AUTH
08:14 10:39 SMTPD(ba7b015b000000c3) [42.49.140.137] AUTH
08:14 10:39 SMTPD(ba7b015b000000c3) [42.49.140.137] AUTH
08:14 10:39 SMTPD(ba7b015b000000c3) FAILED authentication della@sunty.cc
08:14 10:39 SMTPD(ba7c0165000000c4) [211.154.145.13] connect 42.49.140.137 port 3186
08:14 10:39 SMTPD(ba7c0165000000c4) [42.49.140.137] EHLO zyttoqkh
08:14 10:39 SMTPD(ba7c0165000000c4) [42.49.140.137] AUTH
08:14 10:39 SMTPD(ba7c0165000000c4) [42.49.140.137] AUTH
08:14 10:39 SMTPD(ba7c0165000000c4) [42.49.140.137] AUTH
08:14 10:39 SMTPD(ba7c0165000000c4) FAILED authentication della@sunty.cc
08:14 10:40 SMTPD(ba900155000000c5) [211.154.145.13] connect 211.154.145.13 port 4997
08:14 10:40 SMTPD(ba900155000000c5) [211.154.145.13] QUIT
08:14 10:41 SMTPD(bacc013e000000c6) [211.154.145.13] connect 211.154.145.13 port 1032
08:14 10:41 SMTPD(bacc013e000000c6) [211.154.145.13] QUIT
08:14 10:41 SMTPD(bad90160000000c7) [211.154.145.13] connect 42.120.10.176 port 58425
08:14 10:41 SMTPD(bad90160000000c7) [42.120.10.176] EHLO rsxtael
08:14 10:41 SMTPD(bad90160000000c7) [42.120.10.176] AUTH
08:14 10:41 SMTPD(bad90160000000c7) [42.120.10.176] AUTH
08:14 10:41 SMTPD(bad90160000000c7) [42.120.10.176] AUTH
08:14 10:41 SMTPD(bad90160000000c7) FAILED authentication wendy@sunty.cc
08:14 10:42 SMTPD(bb08015b000000c8) [211.154.145.13] connect 211.154.145.13 port 1230
08:14 10:42 SMTPD(bb08015b000000c8) [211.154.145.13] QUIT
08:14 10:43 SMTPD(bb440165000000c9) [211.154.145.13] connect 211.154.145.13 port 1249
08:14 10:43 SMTPD(bb440165000000c9) [211.154.145.13] QUIT
08:14 10:43 SMTPD(bb4c0155000000ca) [211.154.145.13] connect 119.117.116.197 port 1590
08:14 10:43 SMTPD(bb4c0155000000ca) [119.117.116.197] EHLO fazed
08:14 10:43 SMTPD(bb4c0155000000ca) [119.117.116.197] AUTH
08:14 10:43 SMTPD(bb4c0155000000ca) [119.117.116.197] AUTH
08:14 10:43 SMTPD(bb4c0155000000ca) [119.117.116.197] AUTH
08:14 10:43 SMTPD(bb4c0155000000ca) FAILED authentication wendy@sunty.cc
============
用自带的分析工具给的报告
|
本帖子中包含更多资源
您需要 登录 才可以下载或查看,没有帐号?会员注册
x
|