你好,我有一个 exim 服务器,过去 24 小时内有很多垃圾邮件,我查看了 exim_mainlog 并看到了这个
1SDcCZ-0005DX-JQ-H
mailnull 47 12
<[email protected]>
1333115355 0
-helo_name eicghqfebwyn
-host_address 186.106.221.159.3741
-host_name 186-106-221-159.fastnet.com
-host_auth courier_login
-interface_address 190.38.1.34
-received_protocol smtp
-body_linecount 3
-max_received_linelength 228
-auth_id [email protected]
-deliver_firsttime
XX
10
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
227P Received: from 186-106-221-159.fastnet.com([186.106.221.159] helo=eicghqfebwyn)
by srv.xxx.net with smtp (Exim 4.69)
(envelope-from <[email protected]>)
id 1SDcCZ-0005DX-JQ; Fri, 30 Mar 2012 10:49:16 -0300
015 Subject: jrtmh
229T To: [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected]
041F From: “Sufssb” <[email protected]>
038 Date: Fri, 30 Mar 2012 16:48:13 +0200
018 Mime-Version: 1.0
043 Content-Type: text/plain; charset=us-ascii
1SDcCZ-0005DX-JQ-D
Este es un ejemplo del mensaje :
uwzi http://hxrLF.page.tl rfwy exois
但我无法追踪垃圾邮件发送者,有任何想法可以追踪这个吗?一位朋友说我可能被木马在服务器上发送垃圾邮件
谢谢
答案1
好吧,您已经知道了发送邮件的 IP 地址 (186.106.221.159)。您还想要什么?老实说,“追踪”垃圾邮件发送者(无论您的意思是什么)是一场必败之战。您最好花时间设置 Exim 以使用合理的 RBL 和 Spamassassin 或类似程序。