对我们的邮件服务器(不是开放中继服务器)进行 smtp 中继攻击

对我们的邮件服务器(不是开放中继服务器)进行 smtp 中继攻击

帮助,

我们把我们的Exchange 服务器 (10.0.0.125)背后SMTP 代理服务器(如果您听说过的话,请访问 Xeams),但是最近我们的客户抱怨我们回复他们的电子邮件太晚了 - 我们发现我们实际上收到他们的电子邮件时已经晚了几个小时,有时甚至要晚一天!

我们的 Xeams 代理位于 Exchange 前面,使用 IP 10.0.0.10 监听进入我们服务器的所有外部请求防火墙(10.0.0.1)如果它是一个合格的中继(10.0.0.x),它将中继电子邮件,其中包括从我们的 Exchange 服务器(10.0.0.125)中继电子邮件。

我不擅长网络,所以我不知道我是否发现了导致延迟的正确问题:我发现有大量并发连接尝试中继到我们的 Xeams 服务器,其中大多数都来自任何地方,但试图将垃圾邮件发送到“[电子邮件保护]“相似的电子邮件地址,我想是拒绝那些中继请求的工作量延迟了我们的收发电子邮件......有人可以帮忙吗!!

=====以下是我从我们的电子邮件代理中挑选的一些日志=======

2014-03-20 14:58:29,994 - [     74061] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:30,371 - [     74058] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:30,371 - [     74058] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:30,863 - [     74059] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:30,863 - [     74059] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:31,291 - [     74060] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:31,291 - [     74060] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:34,297 - [     74057] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:34,297 - [     74057] C --> DATA
2014-03-20 14:58:34,297 - [     74057] S <-- 503 Send RCPT TO before DATA command
2014-03-20 14:58:35,010 - [     74061] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:35,010 - [     74061] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:35,402 - [     74058] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:35,402 - [     74058] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:35,876 - [     74059] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:35,876 - [     74059] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:36,305 - [     74060] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:36,305 - [     74060] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:36,914 - [     74062] ************ New connection from: 117.141.200.224
2014-03-20 14:58:37,293 - [     74062] C --> EHLO PC-201205080653
2014-03-20 14:58:37,293 - [     74062] S <-- 250-EXCHANGE.webcider.com Hello [10.0.0.20]
2014-03-20 14:58:37,293 - [     74062] S <-- 250-SIZE 377487360
2014-03-20 14:58:37,293 - [     74062] S <-- 250-PIPELINING
2014-03-20 14:58:37,293 - [     74062] S <-- 250-DSN
2014-03-20 14:58:37,293 - [     74062] S <-- 250-ENHANCEDSTATUSCODES
2014-03-20 14:58:37,293 - [     74062] S <-- 250-AUTH NTLM
2014-03-20 14:58:37,293 - [     74062] S <-- 250-8BITMIME
2014-03-20 14:58:37,293 - [     74062] S <-- 250 OK
2014-03-20 14:58:37,685 - [     74062] C --> RSET
2014-03-20 14:58:40,018 - [     74061] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:40,018 - [     74061] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:40,416 - [     74058] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:40,416 - [     74058] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:40,900 - [     74059] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:40,900 - [     74059] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:41,029 - [     74063] ************ New connection from: 117.174.132.109
2014-03-20 14:58:41,312 - [     74060] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:41,312 - [     74060] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:41,500 - [     74063] C --> EHLO PC-201205081432
2014-03-20 14:58:41,500 - [     74063] S <-- 250-EXCHANGE.webcider.com Hello [10.0.0.20]
2014-03-20 14:58:41,500 - [     74063] S <-- 250-SIZE 377487360
2014-03-20 14:58:41,500 - [     74063] S <-- 250-PIPELINING
2014-03-20 14:58:41,500 - [     74063] S <-- 250-DSN
2014-03-20 14:58:41,500 - [     74063] S <-- 250-ENHANCEDSTATUSCODES
2014-03-20 14:58:41,500 - [     74063] S <-- 250-AUTH NTLM
2014-03-20 14:58:41,500 - [     74063] S <-- 250-8BITMIME
2014-03-20 14:58:41,500 - [     74063] S <-- 250 OK
2014-03-20 14:58:41,994 - [     74063] C --> RSET
2014-03-20 14:58:42,697 - [     74062] S <-- 250 2.0.0 Resetting
2014-03-20 14:58:42,697 - [     74062] C --> MAIL FROM:<[email protected]>
2014-03-20 14:58:42,697 - [     74062] S <-- 250 2.1.0 Sender OK
2014-03-20 14:58:42,697 - [     74062] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:45,035 - [     74061] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:45,035 - [     74061] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:45,428 - [     74058] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:45,428 - [     74058] C --> DATA
2014-03-20 14:58:45,428 - [     74058] S <-- 503 Send RCPT TO before DATA command
2014-03-20 14:58:45,905 - [     74059] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:45,905 - [     74059] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:46,319 - [     74060] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:46,319 - [     74060] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:47,001 - [     74063] S <-- 250 2.0.0 Resetting
2014-03-20 14:58:47,001 - [     74063] C --> MAIL FROM:<[email protected]>
2014-03-20 14:58:47,001 - [     74063] S <-- 250 2.1.0 Sender OK
2014-03-20 14:58:47,001 - [     74063] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:47,520 - [     74057] ~~~~~~~~~~~~ Connection Terminated (124353:999999)
2014-03-20 14:58:47,688 - [     74062] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:47,688 - [     74062] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:50,031 - [     74061] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:50,031 - [     74061] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:50,923 - [     74059] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:50,923 - [     74059] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:51,316 - [     74060] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:51,316 - [     74060] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:52,026 - [     74063] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:52,026 - [     74063] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:52,694 - [     74062] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:52,694 - [     74062] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:55,048 - [     74061] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:55,048 - [     74061] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:55,937 - [     74059] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:55,937 - [     74059] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:56,334 - [     74060] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:56,334 - [     74060] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:57,035 - [     74063] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:57,035 - [     74063] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:57,696 - [     74062] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:58:57,696 - [     74062] C --> RCPT TO:<[email protected]>
2014-03-20 14:58:58,944 - [     74058] ~~~~~~~~~~~~ Connection Terminated (126028:999999)
2014-03-20 14:59:00,061 - [     74061] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:00,061 - [     74061] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:00,947 - [     74059] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:00,947 - [     74059] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:01,341 - [     74060] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:01,341 - [     74060] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:02,041 - [     74063] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:02,041 - [     74063] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:02,704 - [     74062] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:02,704 - [     74062] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:05,073 - [     74061] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:05,073 - [     74061] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:05,944 - [     74059] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:05,944 - [     74059] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:06,368 - [     74060] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:06,368 - [     74060] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:07,044 - [     74063] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:07,044 - [     74063] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:07,729 - [     74062] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:07,729 - [     74062] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:10,072 - [     74061] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:10,072 - [     74061] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:10,945 - [     74059] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:10,945 - [     74059] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:11,360 - [     74060] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:11,360 - [     74060] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:12,072 - [     74063] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:12,072 - [     74063] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:12,744 - [     74062] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:12,744 - [     74062] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:15,077 - [     74061] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:15,077 - [     74061] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:15,948 - [     74059] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:15,948 - [     74059] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:16,356 - [     74060] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:16,356 - [     74060] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:16,860 - [     74064] ************ New connection from: 27.18.22.158
2014-03-20 14:59:17,074 - [     74063] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:17,074 - [     74063] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:17,508 - [     74064] C --> EHLO PC-201401110338
2014-03-20 14:59:17,508 - [     74064] S <-- 250-EXCHANGE.webcider.com Hello [10.0.0.20]
2014-03-20 14:59:17,508 - [     74064] S <-- 250-SIZE 377487360
2014-03-20 14:59:17,508 - [     74064] S <-- 250-PIPELINING
2014-03-20 14:59:17,508 - [     74064] S <-- 250-DSN
2014-03-20 14:59:17,508 - [     74064] S <-- 250-ENHANCEDSTATUSCODES
2014-03-20 14:59:17,508 - [     74064] S <-- 250-AUTH NTLM
2014-03-20 14:59:17,508 - [     74064] S <-- 250-8BITMIME
2014-03-20 14:59:17,508 - [     74064] S <-- 250 OK
2014-03-20 14:59:17,751 - [     74062] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:17,751 - [     74062] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:18,175 - [     74064] C --> RSET
2014-03-20 14:59:20,089 - [     74061] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:20,089 - [     74061] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:20,963 - [     74059] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:20,963 - [     74059] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:21,370 - [     74060] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:21,370 - [     74060] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:22,097 - [     74063] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:22,097 - [     74063] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:22,776 - [     74062] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:22,776 - [     74062] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:23,177 - [     74064] S <-- 250 2.0.0 Resetting
2014-03-20 14:59:23,177 - [     74064] C --> MAIL FROM:<[email protected]>
2014-03-20 14:59:23,177 - [     74064] S <-- 250 2.1.0 Sender OK
2014-03-20 14:59:23,177 - [     74064] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:25,112 - [     74061] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:25,112 - [     74061] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:25,956 - [     74059] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:25,956 - [     74059] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:26,370 - [     74060] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:26,370 - [     74060] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:27,120 - [     74063] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:27,120 - [     74063] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:27,785 - [     74062] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:27,785 - [     74062] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:28,194 - [     74064] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:28,194 - [     74064] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:30,129 - [     74061] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:30,129 - [     74061] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:30,973 - [     74059] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:30,973 - [     74059] C --> DATA
2014-03-20 14:59:30,973 - [     74059] S <-- 503 Send RCPT TO before DATA command
2014-03-20 14:59:31,356 - [     74060] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:31,356 - [     74060] C --> DATA
2014-03-20 14:59:31,356 - [     74060] S <-- 503 Send RCPT TO before DATA command
2014-03-20 14:59:32,135 - [     74063] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:32,135 - [     74063] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:32,803 - [     74062] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:32,803 - [     74062] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:33,186 - [     74064] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:33,186 - [     74064] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:35,151 - [     74061] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:35,151 - [     74061] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:37,139 - [     74063] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:37,139 - [     74063] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:37,823 - [     74062] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:37,823 - [     74062] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:38,198 - [     74064] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:38,198 - [     74064] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:40,167 - [     74061] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:40,167 - [     74061] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:42,156 - [     74063] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:42,156 - [     74063] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:42,828 - [     74062] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:42,828 - [     74062] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:43,221 - [     74064] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:43,221 - [     74064] C --> RCPT TO:<[email protected]>
2014-03-20 14:59:44,007 - [     74059] ~~~~~~~~~~~~ Connection Terminated (124147:999999)
2014-03-20 14:59:44,610 - [     74060] ~~~~~~~~~~~~ Connection Terminated (124300:999999)
2014-03-20 14:59:45,171 - [     74061] S <-- 550 5.7.1 Unable to relay
2014-03-20 14:59:45,171 - [     74061] C --> RCPT TO:<[email protected]>

答案1

SMTP 不保证交付,也不保证及时交付。您唯一能做的就是排除系统是延迟的原因。我建议这样做:找到从您的客户端发送的示例电子邮件,并将其到达防火墙的时间与到达代理的时间进行比较,然后将其与到达 Exchange 服务器的时间进行比较。如果延迟时间很长,那么您可以更深入地了解发生这种情况的原因。如果没有延迟,那么问题可能不在您这边,您对此无能为力。

相关内容