junsheng_lin 發表於 2006-12-12 09:16:15

一堆莫名其妙廣告信 固定從一個郵件帳戶寄出去 ....

您好 <BR>有個問題 想請教各位 ...<BR>因為最近公司郵件主機 都會有一推莫名其妙廣告信<BR>固定從一個郵件帳戶寄出去 ....<BR>而幾乎都被退信 ... (如以下訊息)<BR><BR>Returned mail: see transcript for details<BR>Permanent Delivery Failure<BR>failure delivery<BR><BR>主旨都是<BR>Subject: 渡橾 褐樓 霜濰檣/蘋萄 渠轎萄董棲棻717146<BR>寄給對方的網域都是以下的網域<BR>@dreamwiz.com<BR>@empal.com<BR>@yahoo.co.kr<BR><BR>似乎來自韓國地區<BR><BR>這樣問題是否已經被當成跳板 都固定用 [email protected] 帳戶在傳送信件<BR>不知有什麼辦法可以透過 Log 查出問題點及阻止這樣廣告信 !! 謝謝<BR><BR>1. 作業系統:Windows 2000 server<BR>2. 是否安防毒軟體,名稱 : 安裝 Norton antivirus<BR>3. 是否安裝防火牆,名稱 : 無<BR>4. 是否自行架設 DNS,或代管 : 有<BR>5. ADSL 是否使用真正固接制或計時制(但有配發臨用型固定 IP): 固接制 固定 IP<BR>6. 是否使用 IP 分享器 : 無<BR>7. MDaemon、AntiVirus 版本 : V7.11<BR>8. MDaemon 其他相關的設定<BR>9 SMTP (in) 及 (Out) 的記錄內容參考這裏<BR><BR>-----Original Message-----<BR>From: [email protected] <BR>Sent: Thursday, December 07, 2006 7:29 PM<BR>To: [email protected]<BR>Subject: Transient Delivery Failure<BR><BR>The attached message had transient non-fatal delivery errors<BR><BR>THIS IS A WARNING MESSAGE ONLY - YOU DO NOT NEED TO RESEND YOUR MESSAGE!<BR><BR>This server is configured to automatically retry delivery at configured<BR>intervals. Subsequent attempts to deliver this message are pending.<BR><BR>--- Session Transcript ---<BR>Thu 2006-12-07 19:28:25: Parsing Message &lt;xxxxxxxxxxxxxxxxxx\pd50000009808.<BR>msg&gt;<BR>Thu 2006-12-07 19:28:25: From: [email protected]<BR>Thu 2006-12-07 19:28:25: To: [email protected]<BR>Thu 2006-12-07 19:28:25: Subject: Aw@e@N4kCb/D+5e4k1] 4kCb<BR>=E&lt;S9^@8&lt;&lt;?d30348<BR>Thu 2006-12-07 19:28:25: Message-ID:<BR>Thu 2006-12-07 19:28:25: Route slip host: yahoo.co.kr<BR>Thu 2006-12-07 19:28:25: Route slip port: 25<BR>Thu 2006-12-07 19:28:25: MX-record resolution of in progress<BR>(DNS Server: 168.95.1.1)...<BR>Thu 2006-12-07 19:28:25: P=020 D=yahoo.co.kr TTL=(42)<BR>MX= {202.165.108.248}<BR>Thu 2006-12-07 19:28:25: P=020 D=yahoo.co.kr TTL=(42)<BR>MX=<BR>Thu 2006-12-07 19:28:25: Attempting MX: P=020 D=yahoo.co.kr TTL=(42)<BR>MX=<BR>Thu 2006-12-07 19:28:25: Attempting SMTP connection to <BR>Thu 2006-12-07 19:28:25: A-record resolution of in<BR>progress (DNS Server: 168.95.1.1)...<BR>Thu 2006-12-07 19:28:25: D=mx3a.mail.yahoo.co.kr TTL=(89)<BR>A=<BR>Thu 2006-12-07 19:28:25: Attempting SMTP connection to <BR>Thu 2006-12-07 19:28:25: Waiting for socket connection...<BR>Thu 2006-12-07 19:28:26: Socket connection established (192.168.2.250 :<BR>2968 -&gt; 202.165.108.248 : 25)<BR>Thu 2006-12-07 19:28:26: Waiting for protocol initiation...<BR>Thu 2006-12-07 19:28:26: &lt;-- 453 Mail from 211.23.115.99 not allowed - <BR>Thu 2006-12-07 19:28:26: --&gt; QUIT<BR>Thu 2006-12-07 19:28:26: Attempting MX: P=020 D=yahoo.co.kr TTL=(42)<BR>MX= {202.165.108.248}<BR>Thu 2006-12-07 19:28:26: Attempting SMTP connection to <BR>Thu 2006-12-07 19:28:26: Waiting for socket connection...<BR>Thu 2006-12-07 19:28:26: Socket connection established (192.168.2.250 :<BR>2970 -&gt; 202.165.108.248 : 25)<BR>Thu 2006-12-07 19:28:26: Waiting for protocol initiation...<BR>Thu 2006-12-07 19:28:29: &lt;-- 453 Mail from 211.23.115.99 not allowed - <BR>Thu 2006-12-07 19:28:29: --&gt; QUIT<BR>Thu 2006-12-07 19:28:29: This message is 60 minutes old; it has 0 minutes<BR>left in this queue<BR>Thu 2006-12-07 19:28:29: Primary queue lifetime exceeded; message placed in<BR>retry queue<BR>--- End Transcript ---<BR>: Message contains file attachments<BR><BR>

tungwj 發表於 2006-12-12 09:42:02

<a href='http://www.suma.tw/modules/ipboard/index.php?showtopic=887' target='_blank'>http://www.suma.tw/modules/ipboard/in...p?showtopic=887</a><br><a href='http://www.suma.tw/modules/ipboard/index.php?showtopic=2126' target='_blank'>http://www.suma.tw/modules/ipboard/in...?showtopic=2126</a><br><br>由於 MDaemon 架設的環境會影響諸多功能及設定,請於發問前提供詳細的架設環境,包括:<br><br>1. 作業系統:2000/XP/2003/Server 等等<br>2. 是否安防毒軟體,名稱<br>3. 是否安裝防火牆,名稱<br>4. 是否自行架設 DNS,或代管<br>5. ADSL 是否使用真正固接制或計時制(但有配發臨用型固定 IP)<br>6. 是否使用 IP 分享器<br>7. MDaemon、AntiVirus 版本<br>8. MDaemon 其他相關的設定<br>9 SMTP (in) 及 (Out) 的記錄內容參考這裏<br><br>以上資料越多越詳細越好,未提供上述資料者一律不回答。

MarchFun 發表於 2006-12-21 13:59:37

參考這篇看看:<br><a href='http://www.suma.tw/modules/ipboard/index.php?showtopic=756' target='_blank'>http://www.suma.tw/modules/ipboard/in...p?showtopic=756</a>

wheifund 發表於 2007-1-17 12:33:40

今天我們公司的伺服器也發生跟上面大大同樣的問題~~<br>冒用我們公司的mail地址寄信到韓國~幫別人在發信~<br>主要來至58.151.235.135、58.151.235.68、58.151.235.137,都發信到yahoo.co.kr<br>冒用的帳號為 postmaster@公司的mail地址,大量的的寄信到 yahoo.co.kr<br><br>我一早上來看到時,已經積了一百多封在retry queue,且還在不斷發信中..<br>我趕快刪信件、重開機,封IP,封58.151.235.*,但其是會寄出去,所以我就再打一個IP一個IP的打~<br>在Address Suppression封了這個mail: postmaster@公司的mail地址,<br>在最終~更新最近的病毒碼~接著全系統掃毒~掃到2個病毒~移除。<br><br>做了這些事後,mail server目前已停止在幫人發信了~<br>但該 58.151.235.* 類似IP目前還是一直在screen 著我們公司的mail server<br><br>PS. Open Relay 很早以前就已關閉了~<br><br>把log給大家看一下~~目前已停止這場驚魂....但我想知道,真正的原因是因為中毒了嗎 <!--emo&:頭破血流:--><img src='http://www.suma.tw/uploads/smiles-063.gif' border='0' style='vertical-align:middle' alt='smiles-063.gif' /><!--endemo--> ?<br><br>smtp(in):<br>Wed 2007-01-17 09:57:28: ----------<br>Wed 2007-01-17 09:58:08: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:08: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:08: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:08: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:08: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:58:09: Message received from urtqflrtgx.com &lt;[email protected]&gt; with SMTP for &lt;[email protected]&gt; {c:\mdaemon\remoteq\md50000003247.msg}<br>Wed 2007-01-17 09:53:04: Accepting SMTP connection from <br>Wed 2007-01-17 09:53:04: Looking up PTR record for 58.151.235.135 (135.235.151.58.IN-ADDR.ARPA)<br>Wed 2007-01-17 09:53:05: Name server reports domain name unknown.<br>Wed 2007-01-17 09:53:05: --&#62; 220 ooooooooo.com.tw ESMTP MDaemon 6.8.5; Wed, 17 Jan 2007 09:53:05 +0800<br>Wed 2007-01-17 09:53:05: &lt;-- HELO urtqflrtgx.com<br>Wed 2007-01-17 09:53:05: --&#62; 250 ooooooooo.com.tw Hello urtqflrtgx.com, pleased to meet you<br>Wed 2007-01-17 09:53:05: &lt;-- MAIL FROM:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:53:05: Spam Blocker is checking 58.151.235.135 (connecting IP)<br>Wed 2007-01-17 09:53:05: * rbl.softworking.com - passed<br>Wed 2007-01-17 09:53:05: * bl.spamcom.net - passed<br>Wed 2007-01-17 09:53:05: Spam Blocker is finished<br>Wed 2007-01-17 09:53:05: --&#62; 250 &lt;[email protected]&gt;, Sender ok<br>Wed 2007-01-17 09:53:06: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:53:06: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:53:06: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:53:06: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:53:06: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:53:06: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:53:06: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:53:06: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:53:06: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:53:06: More than 5 RCPT commands encountered; this session tarpitted with a 10 second delay<br>Wed 2007-01-17 09:53:06: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:53:16: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:53:16: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:53:26: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:53:26: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:53:36: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:53:36: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:53:46: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:53:46: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:53:56: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:53:56: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:54:06: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:54:06: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:54:25: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:54:25: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:54:35: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:54:35: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:54:45: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:54:45: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:54:55: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:54:55: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:55:06: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:55:06: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:55:15: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:55:15: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:55:25: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:55:25: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:55:35: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:55:35: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:55:54: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:55:54: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:56:05: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:56:05: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:56:16: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:56:16: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:56:31: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:56:31: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:56:40: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:56:40: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:56:50: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:56:50: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:57:00: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:57:00: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:57:10: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:57:10: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:57:28: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:57:28: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:57:38: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:57:38: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:57:48: &lt;-- RCPT TO:&lt;[email protected]&gt;<br>Wed 2007-01-17 09:57:48: --&#62; 250 &lt;[email protected]&gt;, Recipient ok<br>Wed 2007-01-17 09:57:58: &lt;-- DATA<br>Wed 2007-01-17 09:57:58: --&#62; 354 Enter mail, end with &lt;CRLF&gt;.&lt;CRLF&gt;<br>Wed 2007-01-17 09:57:59: --&#62; 250 Ok, message saved &lt;Message-ID: none present in original message&gt;<br>Wed 2007-01-17 09:58:08: &lt;-- QUIT<br>Wed 2007-01-17 09:58:08: --&#62; 221 See ya in cyberspace<br>Wed 2007-01-17 09:58:08: SMTP session successful, 788 bytes transferred.<br>Wed 2007-01-17 09:58:08: Shuffling message(s) into proper queue(s)<br>Wed 2007-01-17 09:58:09: ----------<br><br>smtp(out):<br>Wed 2007-01-17 10:34:32: ----------<br>Wed 2007-01-17 10:34:05: [-1:86:3] Parsing Message &lt;C:\MDAEMON\Remoteq\pd50000003248.msg&gt;<br>Wed 2007-01-17 10:34:05: [-1:86:3] From: [email protected]<br>Wed 2007-01-17 10:34:05: [-1:86:3] To: [email protected]<br>Wed 2007-01-17 10:34:05: [-1:86:3] Subject: 蘋萄 渠旎 渠陶 渡橾 萄董棲棻890700<br>Wed 2007-01-17 10:34:05: [-1:86:3] Message-ID: <br>Wed 2007-01-17 10:34:05: [-1:86:3] Route slip host: yahoo.co.kr<br>Wed 2007-01-17 10:34:05: [-1:86:3] Route slip port: 25<br>Wed 2007-01-17 10:34:05: [-1:86:3] MX-record resolution of in progress (DNS Server: 168.95.1.1)...<br>Wed 2007-01-17 10:34:06: [-1:86:3] P=020 D=yahoo.co.kr TTL=(53) MX= {202.165.108.248}<br>Wed 2007-01-17 10:34:06: [-1:86:3] P=020 D=yahoo.co.kr TTL=(53) MX= {202.165.108.248}<br>Wed 2007-01-17 10:34:06: [-1:86:3] Attempting MX: P=020 D=yahoo.co.kr TTL=(53) MX= {202.165.108.248}<br>Wed 2007-01-17 10:34:06: [-1:86:3] Attempting SMTP connection to <br>Wed 2007-01-17 10:34:06: Waiting for socket connection...<br>Wed 2007-01-17 10:34:06: Socket connection established (127.0.0.1 : 1337 -&gt; 202.165.108.248 : 25)<br>Wed 2007-01-17 10:34:06: Waiting for protocol initiation...<br>Wed 2007-01-17 10:34:24: &lt;-- 220 mta117.mail.krs.yahoo.com ESMTP YSmtp service ready<br>Wed 2007-01-17 10:34:24: --&#62; EHLO interking.com.tw<br>Wed 2007-01-17 10:34:24: &lt;-- 250-mta117.mail.krs.yahoo.com<br>Wed 2007-01-17 10:34:24: &lt;-- 250-8BITMIME<br>Wed 2007-01-17 10:34:24: &lt;-- 250-SIZE 31981568<br>Wed 2007-01-17 10:34:24: &lt;-- 250 PIPELINING<br>Wed 2007-01-17 10:34:24: --&#62; MAIL From:&lt;[email protected]&gt; SIZE=1172<br>Wed 2007-01-17 10:34:24: &lt;-- 250 sender &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:24: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:25: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:25: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:25: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:25: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:25: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:25: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:25: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:25: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:26: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:26: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:26: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:26: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:26: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:26: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:26: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:26: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:26: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:26: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:27: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:27: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:27: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:27: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:27: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:27: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:27: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:27: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:27: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:27: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:28: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:28: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:28: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:28: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:28: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:28: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:28: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:28: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:29: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:29: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:29: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:29: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:29: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:29: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:29: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:29: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:30: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:30: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:30: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:30: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:30: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:30: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:30: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:30: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:31: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:31: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:31: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:31: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:31: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:31: --&#62; RCPT To:&lt;[email protected]&gt;<br>Wed 2007-01-17 10:34:32: &lt;-- 250 recipient &lt;[email protected]&gt; ok<br>Wed 2007-01-17 10:34:32: --&#62; DATA<br>Wed 2007-01-17 10:34:32: &lt;-- 354 Please start mail input.<br>Wed 2007-01-17 10:34:32: Sending &lt;C:\MDAEMON\Remoteq\pd50000003248.msg&gt; to <br>Wed 2007-01-17 10:34:32: Transfer Complete.<br>Wed 2007-01-17 10:34:32: &lt;-- 250 Mail queued for delivery.<br>Wed 2007-01-17 10:34:32: --&#62; QUIT<br>Wed 2007-01-17 10:34:32: &lt;-- 221 Closing connection. Good bye.<br>Wed 2007-01-17 10:34:32: SMTP session successful, 1243 bytes transferred.<br>Wed 2007-01-17 10:34:32: ----------

MarchFun 發表於 2007-1-17 16:50:56

關閉 Open Relay 只能對付不是使用你們公司 mail 的位址。如果他冒用你們的 mail 位址還是防不了。所以除了關閉 Open Relay 之外,最好還能加上 POP Before SMTP。<br><br>至於是否因為中毒造成,我覺得應該不是。

iscandy 發表於 2007-12-13 16:01:33

下次有機會來試試看,

謝謝囉~
頁: [1]
檢視完整版本: 一堆莫名其妙廣告信 固定從一個郵件帳戶寄出去 ....