
<
±×¸² 1 >
1. ¸ÕÀú Ŭ¶óÀÌ¾ðÆ®´Â POP3
Á¢¼Ó(¹è´Þ ¹öưÀ» ´©¸§)À» ¼º°øÀûÀ¸·Î ÇØ¾ßÇÑ´Ù.
2. ¼º°øÇÏ¸é ¼¹ö¿¡ ·Î±×°¡
³²°Ô µÇ°í, Ŭ¶óÀÌ¾ðÆ®´Â ¸ÞÀÏÀ» º¸³¾ ¼ö ÀÖ°Ô µÈ´Ù.
3. SMTP Á¢¼ÓÀÌ µé¾î¿À¸é
¼¹ö´Â ¸ÕÀú [localnets] ¼½¼ÇÀ» È®ÀÎÇØ ¸±·¹ÀÌ Çã¿ë ¿©ºÎ¸¦ ÆÇ´ÜÇÑ´Ù.
4. ´ÙÀ½ "popauth"
Ç׸ñÀÌ "yes"·Î ¼³Á¤µÇ¾ú´Ù¸é Á¢¼ÓÇÑ Å¬¶óÀ̾ðÆ®ÀÇ IP¿¡ ´ëÇÑ POP3 ¼º°ø
·Î±×°¡ ÀÖ´ÂÁö È®ÀÎÇÑ´Ù.
-
POP3 ·Î±× ³»¿ë : user1 from 192.168.1.170 PASS **** OK [18/Sep/2001:09:18:04]
5. ¼º°ø ·Î±×ÀÇ ¸¶Áö¸· ½Ã°£°ú
ÇöÀç Á¢¼Ó½Ã°£ÀÇ Â÷À̰¡ "pop3time" Ç׸ñ¿¡ ¼³Á¤µÈ ½Ã°£º¸´Ù ÀûÀ¸¸é ¸ÞÀÏÀ»
º¸³»°Ô µÈ´Ù.
6. ·Î±×°¡ ¾ø°Å³ª ½Ã°£ÀÌ °æ°úµÈ
°æ¿ì´Â "deletetrash" Ç׸ñÀÇ ¼³Á¤¿¡ µû¶ó »èÁ¦ ¶Ç´Â trash Æú´õ·Î
¹ö·ÁÁø´Ù.
7. ¼º°ø ¶Ç´Â ½ÇÆÐ½Ã [localnets]
¼½¼ÇÀÇ "addheader" Ç׸ñÀÌ "yes"·Î ¼³Á¤µÇ¾î
ÀÖÀ¸¸é ¾Æ·¡¿Í °°Àº Çì´õ¸¦ º»¹®¿¡ Ãß°¡ÇÑ´Ù.
-
¼º°ø : X-Antirelay: Good relay from user1 from 192.168.1.170
PASS **** OK [18/Sep/2001:09:20:10]
- ½ÇÆÐ : X-Antirelay: Bad Relay
DNS
Blacklists ±â´ÉÀ» ÀÌ¿ëÇÑ ¸ÞÀÏ °ÅºÎ
ÀÌ ±â´ÉÀº MAPS(www.mail-abuse.org)¿Í
°°Àº ½ºÆÔ ¼¹ö µî·Ï±â°ü¿¡¼ Á¦°øÇÏ´Â Á¤º¸¸¦ ÀÌ¿ëÇØ ¸ÞÀÏ ¼ö½ÅÀ» Á¦ÇÑÇÏ´Â ±â´ÉÀÌ´Ù. ÀÌ ±â´ÉÀ»
ÅëÇØ ½ºÆÔ ¸ÞÀÏ ¼¹ö ¶Ç´Â Blacklist·Î µî·ÏµÈ °÷À¸·ÎºÎÅÍ ¸ÞÀÏÀ» ¹Þ°Ô µÇ¸é ¸ÞÀÏ ¼ö½ÅÀ»
°ÅºÎÇÒ ¼ö ÀÖ´Ù.
>> µ¿ÀÛ °úÁ¤
1. ¸ÞÀÏÀ» ¹Þ°Ô µÇ¸é Antirelay´Â
¸ÞÀÏ º»¹®ÀÇ Ã¹¹øÂ° "Received:" ºÎºÐ¿¡ ¸í½ÃµÈ IP ÁÖ¼Ò¸¦ È®ÀÎÇÑ´Ù.
-
º»¹® ³»¿ë : Received: from svr1 (unverified [192.168.1.170])
by 192.168.1.1
(EMWAC SMTPRS 0.83) with SMTP id <B0000000042@192.168.1.1>;
...
2. ´ÙÀ½ IP ÁÖ¼Ò¸¦ ¿ªÀ¸·Î
ÇÑ ´ÙÀ½ DNS À̸§¿¡ Ãß°¡ÇÑ´Ù.
-
¿¹: IP ÁÖ¼Ò°¡ 192.168.1.170À̰í DNS À̸§ÀÌ relays.mail-abuse.orgÀÏ
°æ¿ì 170.1.168.192.relay.mail-abuse.org°¡ µÈ´Ù.
3. DNS ¼¹ö¸¦ ÀÌ¿ëÇØ ÀÌ
À̸§¿¡ ÇØ´çÇÏ´Â A ·¹ÄÚµåÀÇ À¯¹«¸¦ È®ÀÎÇÑ´Ù.
-
nslookup ÅøÀ» ÀÌ¿ëÇÑ A ·¹ÄÚµå È®ÀÎ ¿¹ ( IP ÁÖ¼ÒÀÇ Áß°£À» XXX·Î Ç¥Çö )
D:\>nslookup
Default Server: svr1...
Address: 192.168.1.1
> 121.XXX.XXX.203.relays.mail-abuse.org.
¡ç MAPS RSS ¸®½ºÆ®¿¡ µî·ÏµÈ IP
Server: svr1...
Address: 192.168.1.1
Non-authoritative
answer:
Name: 121.XXX.XXX.203.relays.mail-abuse.org
Address: 127.0.0.2 ¡ç A ·¹ÄÚµå °á°ú°ª ¹Ýȯ
> 133.XXX.XXX.203.relays.mail-abuse.org.
¡ç MAPS RSS ¸®½ºÆ®¿¡ µî·Ï ¾ÈµÈ IP
Server: svr1...
Address: 192.168.1.1
*** svr1... can't
find 133.XXX.XXX.203.relays.mail-abuse.org.: Non-existent
domain
> ¡ç A ·¹ÄÚµå °á°ú°ª Á¸ÀçÇÏÁö ¾ÊÀ½
4. A ·¹Äڵ尡 Á¸ÀçÇϸé "deletetrash"
Ç׸ñÀÇ ¼³Á¤¿¡ µû¶ó »èÁ¦ ¶Ç´Â trash Æú´õ·Î ¹ö·ÁÁø´Ù.
5. trash Æú´õ·Î À̵¿½Ã
"addheader" Ç׸ñÀÌ "yes"·Î ¼³Á¤µÈ °æ¿ì ´ÙÀ½°ú
°°Àº Çì´õ¸¦ Ãß°¡ÇÑ´Ù.
X-Antirelay:
Source IP 203.XXX.XXX.121 listed in relays.mail-abuse.org
X-Antirelay-Warning: Please see <http://work-rss.mail-abuse.org/cgi-bin/nph-rss?query=203.XXX.XXX.121>
¢Ø____________ "headertext"
Ç׸ñ¿¡ ÀÔ·ÂÇÑ ³»¿ë
¸¸ÀÏ DNS Blacklists
±â´ÉÀ¸·Î ÀÎÇØ ƯÁ¤ ¼¹ö·ÎºÎÅÍ ¸ÞÀÏ ¼ö½ÅÀÌ ¾ÈµÉ °æ¿ì ÇØ´ç ¼¹ö ´ã´çÀÚ°¡ ¸®½ºÆ®¿¡¼ »èÁ¦Çϱâ
Àü¿¡´Â ¸ÞÀÏÀ» ¹ÞÀ» ¼ö ¾ø°ÔµÈ´Ù. ÀÌ °æ¿ì, Àӽ÷Π¸ÞÀÏÀ» ¹Þ°ÔÇϱâ À§Çؼ´Â ¸ÕÀú "allowlocal"
Ç׸ñÀ» "yes"·Î ¼³Á¤ÇÑ´Ù. ´ÙÀ½, [localnets] ¼½¼Ç¿¡ ÇØ´ç ¼¹öÀÇ
IP ÁÖ¼Ò¸¦ Æ÷ÇÔ½ÃŰ¸é µÈ´Ù.
MAPS(www.mal-abuse.org)³ª
±âŸ DNS ¸®½ºÆ®¿¡ ´ëÇÑ Á¤º¸´Â ÇØ´ç »çÀÌÆ®¸¦ Âü°íÇÑ´Ù.