|
Ëæ×ÅÀ¬»øÓʼþµÄ²»¶Ï·ºÀÄ£¬À¬»øÓʼþ¶ÔÈ«ÇòµÄÉÌÒµ£¬ÆóÒµµÄÀûÒæÒѾÔì³ÉÑÏÖØµÄÓ°Ï죬ΪÁ˼õÉÙÀ¬»øÓʼþ¶ÔÈ«ÇòµÄÓ°Ï죻ȫÇò¸÷¸ö¹ú¼Ò£¬°üÀ¨Öйú¡¢ÃÀ¹ú¡¢Å·ÃË¡¢°ÄÖÞ¡¢ÈÕ±¾¼°Æą̈ÍåµØÇø¶ÔÀ¬»øÓʼþ¶¼×ö³öÁËÏàÓ¦µÄÁ¢·¨£¬¶ÔÀ¬»øÓʼþ·¢ËÍÕß½«½øÐÐÑÏÀ÷µÄ´¦·£¡£
Protocol Scan™¼¼ÊõËùÈ¡µÃµÄ³É¼¨Óë¿Ï¶¨ ÔÚÔçÆÚÀ¬»øÓʼþ¹ýÂËÖ÷Ҫͨ¹ýÄÚÈÝ¡¢¹Ø¼ü×Ö¡¢ipµÈ·½Ê½´¦ÀíÀ¬»øÓʼþ£¬ÓÉÓÚ´óÁ¿Í¼ÏñʽÀ¬»øÓʼþµÄ·ºÀÄ£¬´ËµÈ¼¼ÊõÒÔÎÞ·¨ÓÐЧµÄ½øÐÐÅжϣ¬ËùÒÔÖ»ÓÐͨ¹ýP Scan™µÄɨÃè¼¼ÊõÕë¶ÔÀ¬»øÓʼþ·¢ËÍÕßµÄÐÐΪ½øÐÐÅжϣ¬²ÅÄÜÓÐЧµÄ·ÀÖ¹À¬»øÓʼþ¡£ ¹ú¼Ò¶ÔÀ¬»øÓʼþµÄ·ºÀÄ£¬Ò²²ÉÈ¡ÁËÐí¶àµÄÊֶκͷ½Ê½½øÐпØÖÆÀ¬»øÓʼþ¡£ÐÅÏ¢²úÒµ²¿ÔÚ2006Äê3ÔÂ30ÈÕ£¬Õë¶Ô¡¶µç×ÓÓʼþ·þÎñ¹ÜÀí°ì·¨¡·µÚÈýÌõÃ÷È·¹æ¶¨¹«ÃñʹÓû¥ÁªÍøµç×ÓÓʼþ·þÎñµÄͨÐÅÃØÃÜÊÜ·¨Âɱ£»¤¡£³ýÒò¹ú¼Ò°²È«»òÕß×·²éÐÌÊ·¸×ïµÄÐèÒª£¬Óɹ«°²»ú¹Ø»òÕß¼ì²ì»ú¹ØÒÀÕÕ·¨Âɹ涨µÄ³ÌÐò¶ÔͨÐÅÄÚÈݽøÐмì²éÍ⣬ÈκÎ×éÖ¯»òÕ߸öÈ˲»µÃÒÔÈκÎÀíÓÉÇÖ·¸¹«ÃñµÄͨÐÅÃØÃÜ¡£ÒòΪÏÖÔڴ󲿷ֵÄÍø¹Ø²úÆ·Ö÷Ҫͨ¹ýÄÚÈݹýÂ˵ļ¼Êõ½øÐйýÂËÀ¬»øÓʼþ£¬ËùÓеĹؼü×ÖºÍÄÚÈÝ£¬Íø¹Ø¶¼¶¼¿ÉÒÔ¿´µ½£¬¶øÈíÌåÓÖÊÇÈ˱àд³öÀ´£¬É豸¿ÉÒÔ¿´µ½ËùÓеÄÄÚÈÝ£¬È˾ͿÉÒÔÖªµÀ£¬ËùÒÔÕâÖÖ²úÆ·Ó¦¸ÃÓ¦Óõ½±£ÃܲúÆ··½Ã棬ÒòΪͨ¹ýP Scan™µÄ¼¼Êõ¶ÔÐÐΪ½øÐÐÅжϣ¬ËùÒÔµÄÓʼþÔÚûÓе½´ïÍø¹ØÖ®Ç°¾Í¿ÉÒÔÅжϳöÓʼþÊÇ·ñΪÀ¬»øÓʼþ£¬½øÐд¦Àí£¬ÊÇÍêÈ«·ûºÏ¡¶µç×ÓÓʼþ·þÎñ¹ÜÀí°ì·¨¡·ÖеĹ涨¡£ ÔÚ2006ÄêÐÅÏ¢²úÒµ²¿¶Ô¼¸Ê®¼ÒµÄÓʼþÍø¹Ø²úÆ·²âÊÔµ±ÖУ¬P Scan™¼¼ÊõÔڴ˴βâÆÀÖÐÀ¬»øÓʼþ×èµ²ÂÊ´ïµ½ÁË99.2£¥¡¢ÎóÅÐÂÊСÓÚ1£¥£¬½á¹û·Ç³£µÄ¾ªÈË£¬´Ë´Î²âÆÀÒ²ÕæÕýÌåÏÖ³öP Scan™¼¼ÊõÔÚÓʼþ°²È«ÖеÄÖØÒªÐÔ£¬Ò²ÊÇδÀ´Óʼþ°²È«²úÆ·ÖбØÐëʹÓõÄÒ»Ïî¼¼Êõ¡£ 2007ÄêÄê³õ£¬ÐÅÏ¢²úÒµ²¿Õë¶Ô·´À¬»øÓʼþµÄ¼¼ÊõÒªÇóµÄ¹æ·¶µÄÖÆ¶¨£¬²¢ÑûÇë˶çù¿Æ¼¼ÒÔר¼ÒµÄÉí·Ý¶Ô´Ë´Î¼¼ÊõµÄÒªÇ󹿷¶½øÐвÎÓëºÍÐÞ¶©£¬Ò²³ä·ÖÌåÏÖÁËÐÅÏ¢²úÒµ²¿¶ÔP Scan™¼¼ÊõÔÚÓʼþ°²È«Íø¹ØÖÐÓ¦ÓÃÈ¡µÃµÄ³ÉЧµÄ¿Ï¶¨¡£ ÒÔÉÏÖ÷Òª½éÉÜÁËP Scan™¼¼ÊõÔÚÓʼþ°²È«ÁìÓòÖÐÓ¦ÓõÄÖØÒªÐÔ¼°ÆäÔÚÓʼþ°²È«ÁìÓòÖÐÈ¡µÃµÄ³É¼¨ºÍ¹ú¼Ò¶Ô´Ë¼¼ÊõµÄ¿Ï¶¨¡£ÒÔϽ«¾Ù³öProtocol Scan™¼¼Êõ¶ÔÌØÊâ±àÂëÓʼþµÄ¹ýÂËʵÀýÀ´ËµÃ÷¡£ Protocol Scan™¼¼Êõ¶ÔÌØÊâ±àÂëÓʼþµÄ¹ýÂË ¸÷¸ö¹ú¼ÒÕë¶Ô×Ô¼ºµÄÓïÑÔ¶¼×Ô¶¨Á˸÷×ԵıàÂë±ê×¼£¬ÀýÈçBig5£¨·±ÌåÖÐÎÄ£©£¬GB2312£¨¼òÌåÖÐÎÄ£©£¬Unicode£¨UTF-8£©£¬Shift-JIS(ÈÕÎÄ)£¬EUC-KR£¨º«ÎÄ£©µÈµÈ·Ç³£¶àµÄÓïϵ¶¼ÓÐ×Ô¼ºµÄ±àÂë¡£¹úÄÚMailϵͳµ÷Ñз¢ÏÖ£ººÜ¶àʹÓùúÍâÆ·ÅÆµÄServerÒ»°ãÖ§³ÖUTF-8±àÂ룬¹úÄÚÆ·ÅƵÄServerÒ»°ãÖ§³ÖGB2312±àÂ룬ºÜÉÙÓÐÖ§³ÖÆäËüÓïÑÔ±àÂëµÄ¹ýÂË£¬Õë¶ÔÕâЩ·Ç±ê׼ʹÓõıàÂë¼°ÓïÑÔ£¬ÉèÖùؼü×Ö¹ýÂ˱¾Éí¶ÔÆóÒµMISÌá³öÁ˺ܸ߷Ǽ¼ÊõÉÏÒªÇó¡£ Ë¶çù¿Æ¼¼Ò»Ö±×¨×¢ÓÚÓʼþ°²È«²úÆ·µÄÑз¢£¬P Scan™ (ͨѶÐÒéɨÃè)¼¼Êõ¾ÍÊÇ˶çù¿Æ¼¼ÔÚÓʼþ°²È«·½ÃæÖØÒª³É¾ÍÖ®Ò»£¬ÊÇ·ÀÀ¬»øÓʼþ¼¼ÊõÁìÓòµÄÒ»ÖÖÐÂÐͼ¼Êõ£¬Ö÷ÒªÕë¶ÔÀ¬»øÓʼþµÄ·¢ÐÅÐÐΪ£¬½øÐжԷ¢¼þÈËµÄ¼à¿Ø£¬×èµ²£¬ÒÔ´ïµ½¼õÉÙÀ¬»øÓʼþ¡£P Scan™¼¼ÊõÕë¶ÔSMTPÐÒé½øÐÐɨÃ裬°²È«ÎÞÐèÒÀÀµ¹Ø¼ü×Ö£¬ÎÞÂÛÊÇÀ¬»øÓʼþ£¬Í¼ÏñÓʼþ£¬³¬Á¬½ÓÀàÐ͵ÄÀ¬»øÓʼþ¶¼ÄÜÓÐЧµÄ×è¸ô¡£ ÏÂÃæ¾ÍÒÔÒ»·âÓʼþÀ´ËµÃ÷P Scan¼¼Êõ¶ÔUTF8£¨Ó¢Ó»òGB2312£¨¼òÌåÖÐÎÄ£©µÈ£¬ÒԷdz£ÓñàÂëµÄÀ¬»øÓʼþ¹ýÂË×è¸ôЧ¹û¡£ ¸ÃÓʼþ±»´úºÅΪ¡°bkdoco3525¡±ÕâÌõ¹æÔò×è¸ô • ´Ë·âµç×ÓÓʼþµÄ SpamTrap ´úºÅÊÇ£ºbkdoco • ´úºÅÊÍÒåΪ£º·¢¼þÈËÀ´Ô´ÍøÂç IP ÓëÖ÷»úÍøÂç IP µÄ¹úÂë²»·ûºÏ BOXÎÀÊ¿ÓʲúÆ·µ×²ã¼Ç¼µÄlog£º • root@st:~# grep l4V9File003332 /var/log/mail.log • May 31 17:15:46 st sendmail[3332]: l4V9File003332: original.SourceRoute=[82.77.201.70], SenderHost=.localhost.localdomain #Ðû¸æÀ´Ô´ipΪ[82.77.201.70]£¬À´×Ôlocalhost£¬Æäʵ¾ÍÊÇÒ»·¢ÐÅ»ú££ • May 31 17:15:46 st sendmail[3332]: l4V9File003332: EnvelopeFrom:vinit480temp@phayze.com ££ Ðû¸æ·¢¼þÈËΪvinit480temp@phayze.com ££ • May 31 17:15:47 st sendmail[3332]: l4V9File003332: Message-ID:<95b901c7a363$047304ce$bc3754c2@phayze.com>, queueID:l4V9File003332 • May 31 17:15:47 st sendmail[3332]: l4V9File003332: From:=?windows-1251?B?weDOjt?=vinit480temp@phayze.com ££?windows-1251?B?·Ç±ê×¼±àÂ룣 • May 31 17:15 w7:47 st sendmail[3332]: l4V9File003332: To:ssz@haining.info • May 31 17:15:47 st sendmail[3332]: l4V9File003332: Sub:=?windows-1251?B?Rnc6IMIg7eD45ekg6u7s7+Dt6Ogg4vsg8ezu5uXy5SDt4Ony6CDg4fHu6/7y7e4g?= =?windows-1251?B?4vHlIOTr/yDh6+Dj7vPx8vDu6fHy4uAg4uD45ePuIO706PHg?= ££ Ðû¸æ±àÂëΪ?windows-1251?B?£¬Îª·¢¼þÕß×Ô¶¨Ò壬·Ç±ê×¼±àÂë # • May 31 17:15:47 st sendmail[3332]: l4V9File003332: SourceRoute=[82.77.201.70], SenderHost=.localhost.localdomain, DNSLookUp=.FAIL • May 31 17:15:47 st sendmail[3332]: l4V9File003332: STResult=quarantine, CodeID=bkdoco3525 • May 31 17:15:49 st sendmail[3332]: l4V9File003332: from=<vinit480temp@phayze.com>, size=51865, class=0, nrcpts=1, msgid=<95b901c7a363$047304ce$bc3754c2@phayze.com>, proto=SMTP, daemon=MTA, relay=[82.77.201.70] • May 31 17:15:49 st helpspam[3333]: l4V9File003332: to=ssz@haining.info, ruleset=check_eom, reject=4.7.0, stat=SpamTrap=quarantine mode, dsn=4.7.0, Message blocked by BOX Solutions (www.box-sol.com) SpamTrap Technology: (bkdoco3525) ££ ¾ö¶¨ÐÔ×è¸ôÔÒò (bkdoco3525) ££ • May 31 17:15:49 st helpspam[3333]: l4V9File003332: Remove the file /tmp/l4V9File003332.tmp • May 31 17:15:49 st sendmail[3332]: l4V9File003332: Milter: data, discard • May 31 17:15:49 st sendmail[3332]: l4V9File003332: discarded ÒÔÏ´úÂëÊÇÕâ·âÓʼþµÄMail Header:£¨¿ÉÔÚÓʼþ£>ÊôÐÔ£>ÏêϸÐÅÏ¢£>ÓʼþÀ´Ô´²é¿´£© • Message-ID:a89c01c7a363$67180868$bf44e9d4@barefootbubbas.com • From:=?windows-1251?B?3i4g0eDr/O3o6u7i?=tatsuo6@barefootbubbas.com ££ ·¢¼þÕßÏÔʾΪtatsuo6@barefootbubbas.com,,ÒѾ¸Ä±ä££ • To:shb@haining.info •Subject:?windows-1251?B?8ODp8ero6SDz4+7r7uog6CDv8OXi7vH17uTt++kg7uH65eryIOTr/yDo7eLl8fLo?= =?windows-1251?B?9ujp?= ££²»Ã÷windows-1251?B?±àÂ룬Ϊ·¢¼þÕß×Ô¶¨Ò壣 • Date:Thu,31May200712:13:48 • +0300MIME-Version: 1.0 •Content-Type:multipart/related;type="multipart/alternative";boundary="----=_NextPart_000_0000_7B7414CD.524ADB3D" • X-Priority:3X-MSMail-Priority: • NormalX-Mailer: Microsoft Outlook Express V6.00.2900.2180 • X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180This is a multi-part message in MIME format. ʵ¼ÊÉÏ´Ë·âÐŵÄÄÚÈÝÈ´ÊÇÒ»·â¶íÎÄ£¬´øÓÐͼÏñ¸½¼þµÄÀ¬»øÓʼþ£¬ÈçÏÂͼ£º

Protocol Scan™¼¼ÊõµÄÓÅÔ½ÐÔ ¹Ø¼ü×Ö¹ýÂËÎÞ·¨Ê¶±ðһЩ·Ç±ê×¼±àÂëµÄÖ÷Ì⣬¶ÔһЩ·ÇÓ¢Óï¼°ÖÐÎĵĹؼü×ÖÉèÖ㬱¾Éí¶ÔÆóÒµµÄMIS¾ÍÌá³öÁ˷dz£¸ßµÄ·Ç¼¼ÊõÐÔÒªÇó£¬Ôö¼ÓÁËÉèÖõÄÄѶȡ£ P Scan™¼¼ÊõÄܶԴËÀà·Ç±ê×¼±àÂ룬À´×ÔÆäËü¹ú¼ÒµÄÓïÑÔ£¨·ÇÓ¢Óï¼°ÖÐÎÄ£©µÄÓʼþ£¬²»ÐèÒª±È¶Ô¹Ø¼ü×Ö£¬²»ÐèҪά»¤¹Ø¼ü×ֿ⣬¼õÉÙMISµÄ¹¤×÷Á¿£¬²¢´Ó¸ù±¾É϶ԴËÀàÓʼþ×öµ½×è¸ô¡£ ÒÔ±´Ò¶ÆÚË㷨Ϊ´ú±íµÄÄÚÈݹؽ¡×Ö¹ýÂ˼¼ÊõÔø¾ÔÚÓʼþ°²È«·½Ãæ·¢»ÓÁËÖØÒªµÄ×÷Ó㬵«ÊÇËæ×Å·¢À¬»øÓʼþ¼¼ÊõµÄÌá¸ß£¬´ËÏî¼¼ÊõÒѾ²»ÄÜÂú×㵱ǰµÄÐèÇó£¬ÌرðÊǶÔͼÏñÀàÐ͵ÄÀ¬»øÓʼþÒÔ¼°Ò»Ð©À´×Ô¹úÍâµÄÀ¬»øÓʼþ£¬ÄÚÈݹýÂ˼¼ÊõÎÞ·¨×èµ²´ËÀàÓʼþ£¬µ«P Scan™¼¼ÊõÍêÈ«ÄÜ×èµ²´ËÀàÓʼþ¡£ ÔÚÒÔºóµÄÎÄÕÂÖлá×ÅÖØ½éÉÜP Scan™¼¼ÊõÔÚÓʼþ°²È«ÁìÓò²úÆ·ÆäËüÀàÐÍÀ¬»øÓʼþ·ÀÓùÓ¦ÓÃÖеĶ๦ÄÜÐÔ¡£
|