Enviado em 14/08/2013 - 08:10h
Fala Gente bom dia a todos!!!!
Seguinte to com um problema em meu servidor de email(Ubuntu rodando Dovecote,postfix,amavis-new,spamassasin) abaixo postei o log do que está ocorrendo, está sempre acontecendo isso usuarios SPAM se conectam em meu servidor e enviam emails de um funcionario para ele mesmo com algo em anexo, ou seja, a propria pessoa mandando email para ela mesma, sendo que foi esse Spam, no exemplo abaixo ta um tal de brunosanches.com.br fazendo isso que eu falei, alguem sabe alguma saida? nao sei mais o q fazer isso acontece mto.
Substituir o nome do email para usuariodaempresa@meudominio.com.br
Aug 14 05:40:48 mail postfix/smtpd[1468]: connect from 186-84-162-69.brunosanches.com.br[69.162.84.186]
Aug 14 05:40:48 mail postfix/smtpd[1468]: setting up TLS connection from 186-84-162-69.brunosanches.com.br[69.162.84.186]
Aug 14 05:40:48 mail postfix/smtpd[1468]: 186-84-162-69.brunosanches.com.br[69.162.84.186]: TLS cipher list "ALL:+RC4:@STRENGTH"
Aug 14 05:40:48 mail postfix/smtpd[1468]: SSL_accept:before/accept initialization
Aug 14 05:40:49 mail postfix/smtpd[1468]: SSL_accept:SSLv3 read client hello B
Aug 14 05:40:49 mail postfix/smtpd[1468]: SSL_accept:SSLv3 write server hello A
Aug 14 05:40:49 mail postfix/smtpd[1468]: SSL_accept:SSLv3 write certificate A
Aug 14 05:40:49 mail postfix/smtpd[1468]: SSL_accept:SSLv3 write key exchange A
Aug 14 05:40:49 mail postfix/smtpd[1468]: SSL_accept:SSLv3 write server done A
Aug 14 05:40:49 mail postfix/smtpd[1468]: SSL_accept:SSLv3 flush data
Aug 14 05:40:49 mail postfix/smtpd[1468]: SSL_accept:SSLv3 read client key exchange A
Aug 14 05:40:49 mail postfix/smtpd[1468]: SSL_accept:SSLv3 read finished A
Aug 14 05:40:49 mail postfix/smtpd[1468]: SSL_accept:SSLv3 write change cipher spec A
Aug 14 05:40:49 mail postfix/smtpd[1468]: SSL_accept:SSLv3 write finished A
Aug 14 05:40:49 mail postfix/smtpd[1468]: SSL_accept:SSLv3 flush data
Aug 14 05:40:49 mail postfix/smtpd[1468]: 186-84-162-69.brunosanches.com.br[69.162.84.186]: save session 0748B03939E4210C273EC11547EE5310857597A038AB7B68F543A5DC42B8A0FC&s=smtp to smtpd cache
Aug 14 05:40:49 mail postfix/tlsmgr[19950]: put smtpd session id=0748B03939E4210C273EC11547EE5310857597A038AB7B68F543A5DC42B8A0FC&s=smtp [data 127 bytes]
Aug 14 05:40:49 mail postfix/tlsmgr[19950]: write smtpd TLS cache entry 0748B03939E4210C273EC11547EE5310857597A038AB7B68F543A5DC42B8A0FC&s=smtp: time=1376469649 [data 127 bytes]
Aug 14 05:40:49 mail postfix/smtpd[1468]: Anonymous TLS connection established from 186-84-162-69.brunosanches.com.br[69.162.84.186]: TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)
Aug 14 05:40:50 mail postfix/smtpd[1468]: A9AFC78007D: client=186-84-162-69.brunosanches.com.br[69.162.84.186]
Aug 14 05:40:50 mail postfix/cleanup[1791]: A9AFC78007D: message-id=<201308140537507F2559E2EA$A6CF2653F2@FEEBB>
Aug 14 05:40:50 mail postfix/qmgr[19929]: A9AFC78007D: from=<usuariodaempresa@meudominio.com.br>, size=2988, nrcpt=1 (queue active)
Aug 14 05:40:50 mail postfix/smtpd[1794]: initializing the server-side TLS engine
Aug 14 05:40:50 mail postfix/smtpd[1794]: connect from localhost[127.0.0.1]
Aug 14 05:40:50 mail postfix/smtpd[1794]: F331578007E: client=localhost[127.0.0.1]
Aug 14 05:40:50 mail postfix/cleanup[1791]: F331578007E: message-id=<201308140537507F2559E2EA$A6CF2653F2@FEEBB>
Aug 14 05:40:51 mail postfix/smtpd[1794]: disconnect from localhost[127.0.0.1]
Aug 14 05:40:51 mail postfix/qmgr[19929]: F331578007E: from=<usuariodaempresa@meudominio.com.br>, size=3389, nrcpt=1 (queue active)
Aug 14 05:40:51 mail amavis[1514]: (01514-09) Passed CLEAN, [69.162.84.186] [173.255.189.59] <usuariodaempresa@meudominio.com.br> -> <usuariodaempresa@meudominio.com.br>, Message-ID: <201308140537507F2559E2EA$A6CF2653F2@FEEBB>, mail_id: 7e2R3SjxVpVh, Hits: -, size: 2988, queued_as: F331578007E, 117 ms
Aug 14 05:40:51 mail postfix/smtp[1792]: A9AFC78007D: to=<usuariodaempresa@meudominio.com.br>, relay=127.0.0.1[127.0.0.1]:10024, delay=1.4, delays=1.3/0.01/0/0.12, dsn=2.0.0, status=sent (250 2.0.0 Ok, id=01514-09, from MTA([127.0.0.1]:10025): 250 2.0.0 Ok: queued as F331578007E)
Aug 14 05:40:51 mail postfix/qmgr[19929]: A9AFC78007D: removed
Aug 14 05:40:51 mail postfix/smtpd[1468]: disconnect from 186-84-162-69.brunosanches.com.br[69.162.84.186]
Aug 14 05:40:51 mail postfix/local[1795]: F331578007E: to=<usuariodaempresa@meudominio.com.br>, orig_to=<usuariodaempresa@meudominio.com.br>, relay=local, delay=0.26, delays=0.04/0/0/0.21, dsn=2.0.0, status=sent (delivered to command: procmail -a "$EXTENSION")
Seguinte to com um problema em meu servidor de email(Ubuntu rodando Dovecote,postfix,amavis-new,spamassasin) abaixo postei o log do que está ocorrendo, está sempre acontecendo isso usuarios SPAM se conectam em meu servidor e enviam emails de um funcionario para ele mesmo com algo em anexo, ou seja, a propria pessoa mandando email para ela mesma, sendo que foi esse Spam, no exemplo abaixo ta um tal de brunosanches.com.br fazendo isso que eu falei, alguem sabe alguma saida? nao sei mais o q fazer isso acontece mto.
Substituir o nome do email para usuariodaempresa@meudominio.com.br
Aug 14 05:40:48 mail postfix/smtpd[1468]: connect from 186-84-162-69.brunosanches.com.br[69.162.84.186]
Aug 14 05:40:48 mail postfix/smtpd[1468]: setting up TLS connection from 186-84-162-69.brunosanches.com.br[69.162.84.186]
Aug 14 05:40:48 mail postfix/smtpd[1468]: 186-84-162-69.brunosanches.com.br[69.162.84.186]: TLS cipher list "ALL:+RC4:@STRENGTH"
Aug 14 05:40:48 mail postfix/smtpd[1468]: SSL_accept:before/accept initialization
Aug 14 05:40:49 mail postfix/smtpd[1468]: SSL_accept:SSLv3 read client hello B
Aug 14 05:40:49 mail postfix/smtpd[1468]: SSL_accept:SSLv3 write server hello A
Aug 14 05:40:49 mail postfix/smtpd[1468]: SSL_accept:SSLv3 write certificate A
Aug 14 05:40:49 mail postfix/smtpd[1468]: SSL_accept:SSLv3 write key exchange A
Aug 14 05:40:49 mail postfix/smtpd[1468]: SSL_accept:SSLv3 write server done A
Aug 14 05:40:49 mail postfix/smtpd[1468]: SSL_accept:SSLv3 flush data
Aug 14 05:40:49 mail postfix/smtpd[1468]: SSL_accept:SSLv3 read client key exchange A
Aug 14 05:40:49 mail postfix/smtpd[1468]: SSL_accept:SSLv3 read finished A
Aug 14 05:40:49 mail postfix/smtpd[1468]: SSL_accept:SSLv3 write change cipher spec A
Aug 14 05:40:49 mail postfix/smtpd[1468]: SSL_accept:SSLv3 write finished A
Aug 14 05:40:49 mail postfix/smtpd[1468]: SSL_accept:SSLv3 flush data
Aug 14 05:40:49 mail postfix/smtpd[1468]: 186-84-162-69.brunosanches.com.br[69.162.84.186]: save session 0748B03939E4210C273EC11547EE5310857597A038AB7B68F543A5DC42B8A0FC&s=smtp to smtpd cache
Aug 14 05:40:49 mail postfix/tlsmgr[19950]: put smtpd session id=0748B03939E4210C273EC11547EE5310857597A038AB7B68F543A5DC42B8A0FC&s=smtp [data 127 bytes]
Aug 14 05:40:49 mail postfix/tlsmgr[19950]: write smtpd TLS cache entry 0748B03939E4210C273EC11547EE5310857597A038AB7B68F543A5DC42B8A0FC&s=smtp: time=1376469649 [data 127 bytes]
Aug 14 05:40:49 mail postfix/smtpd[1468]: Anonymous TLS connection established from 186-84-162-69.brunosanches.com.br[69.162.84.186]: TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)
Aug 14 05:40:50 mail postfix/smtpd[1468]: A9AFC78007D: client=186-84-162-69.brunosanches.com.br[69.162.84.186]
Aug 14 05:40:50 mail postfix/cleanup[1791]: A9AFC78007D: message-id=<201308140537507F2559E2EA$A6CF2653F2@FEEBB>
Aug 14 05:40:50 mail postfix/qmgr[19929]: A9AFC78007D: from=<usuariodaempresa@meudominio.com.br>, size=2988, nrcpt=1 (queue active)
Aug 14 05:40:50 mail postfix/smtpd[1794]: initializing the server-side TLS engine
Aug 14 05:40:50 mail postfix/smtpd[1794]: connect from localhost[127.0.0.1]
Aug 14 05:40:50 mail postfix/smtpd[1794]: F331578007E: client=localhost[127.0.0.1]
Aug 14 05:40:50 mail postfix/cleanup[1791]: F331578007E: message-id=<201308140537507F2559E2EA$A6CF2653F2@FEEBB>
Aug 14 05:40:51 mail postfix/smtpd[1794]: disconnect from localhost[127.0.0.1]
Aug 14 05:40:51 mail postfix/qmgr[19929]: F331578007E: from=<usuariodaempresa@meudominio.com.br>, size=3389, nrcpt=1 (queue active)
Aug 14 05:40:51 mail amavis[1514]: (01514-09) Passed CLEAN, [69.162.84.186] [173.255.189.59] <usuariodaempresa@meudominio.com.br> -> <usuariodaempresa@meudominio.com.br>, Message-ID: <201308140537507F2559E2EA$A6CF2653F2@FEEBB>, mail_id: 7e2R3SjxVpVh, Hits: -, size: 2988, queued_as: F331578007E, 117 ms
Aug 14 05:40:51 mail postfix/smtp[1792]: A9AFC78007D: to=<usuariodaempresa@meudominio.com.br>, relay=127.0.0.1[127.0.0.1]:10024, delay=1.4, delays=1.3/0.01/0/0.12, dsn=2.0.0, status=sent (250 2.0.0 Ok, id=01514-09, from MTA([127.0.0.1]:10025): 250 2.0.0 Ok: queued as F331578007E)
Aug 14 05:40:51 mail postfix/qmgr[19929]: A9AFC78007D: removed
Aug 14 05:40:51 mail postfix/smtpd[1468]: disconnect from 186-84-162-69.brunosanches.com.br[69.162.84.186]
Aug 14 05:40:51 mail postfix/local[1795]: F331578007E: to=<usuariodaempresa@meudominio.com.br>, orig_to=<usuariodaempresa@meudominio.com.br>, relay=local, delay=0.26, delays=0.04/0/0/0.21, dsn=2.0.0, status=sent (delivered to command: procmail -a "$EXTENSION")