首页 -> 安全研究
安全研究
绿盟月刊
绿盟安全月刊->第9期->安全文摘
整理:deepin < deepin@nsfocus.com >
出处:http://www.whitehats.com
主页:http://www.nsfocus.com
日期:2000-05-05
下面的测试过程显示了mail-abuse.org的mailrelay的详细测试过程。我的示范邮件服
务器是example.whitehats.org,默认安装了sendmail8.9.3这个测试用来测试一个给定
的MTA(邮件传输代理)是否会被第三方转发所影响。如果某项测试被通过,证明这个MTA
允许外部的第三方利用这个邮件服务器散发垃圾邮件或者潜在的违背安全规则。当然你
的主机情况和我是不同的
如果你的主机存在这样的问题,请参考另一篇文章的详细内容来修补它。
[example ~]% telnet mail-abuse.org
Trying 204.152.184.74...
Connected to mail-abuse.org.
Escape character is '^]'.
Connecting to 23.23.23.23 for anonymous test ...
<<< 220 example.whitehats.com ESMTP Sendmail 8.9.3/8.9.3; Mon, 22 Nov 1999
14:50:32 -0800
>>> HELO mail-abuse.org
<<< 250 example Hello maps1.pa.vix.com [204.152.184.35], pleased to meet you
Relay test 1
>>> RSET
<<< 250 Reset state
>>> MAIL FROM:
<<< 250
>>> RCPT TO:
<<< 550
Relay test 2
>>> RSET
<<< 250 Reset state
>>> MAIL FROM:
<<< 553
Relay test 3
>>> RSET
<<< 250 Reset state
>>> MAIL FROM:<>
<<< 250 <>... Sender ok
>>> RCPT TO:
<<< 550
Relay test 4
>>> RSET
<<< 250 Reset state
>>> MAIL FROM:
<<< 250
>>> RCPT TO:
<<< 550
Relay test 5
>>> RSET
<<< 250 Reset state
>>> MAIL FROM:
<<< 250
>>> RCPT TO:
<<< 550
Relay test 6
>>> RSET
<<< 250 Reset state
>>> MAIL FROM:
<<< 250
>>> RCPT TO:
<<< 550
Relay test 7
>>> RSET
<<< 250 Reset state
>>> MAIL FROM:
<<< 250
>>> RCPT TO:
<<< 550
Relay test 8
>>> RSET
<<< 250 Reset state
>>> MAIL FROM:
<<< 250
>>> RCPT TO:<"relaytest@mail-abuse.org">
<<< 550 <"relaytest@mail-abuse.org">... Relaying denied
Relay test 9
>>> RSET
<<< 250 Reset state
>>> MAIL FROM:
<<< 250
>>> RCPT TO:<"relaytest%mail-abuse.org">
<<< 550 <"relaytest%mail-abuse.org">... Relaying denied
Relay test 10
>>> RSET
<<< 250 Reset state
>>> MAIL FROM:
<<< 250
>>> RCPT TO:
<<< 550
Relay test 11
>>> RSET
<<< 250 Reset state
>>> MAIL FROM:
<<< 250
>>> RCPT TO:<"relaytest@mail-abuse.org"@example.whitehats.com>
<<< 550 <"relaytest@mail-abuse.org"@example.whitehats.com>... Relaying
denied
Relay test 12
>>> RSET
<<< 250 Reset state
>>> MAIL FROM:
<<< 250
>>> RCPT TO:
<<< 550
Relay test 13
>>> RSET
<<< 250 Reset state
>>> MAIL FROM:
<<< 250
>>> RCPT TO:<@example.whitehats.com:relaytest@mail-abuse.org>
<<< 550 <@example.whitehats.com:relaytest@mail-abuse.org>... Relaying denied
Relay test 14
>>> RSET
<<< 250 Reset state
>>> MAIL FROM:
<<< 250
>>> RCPT TO:<@example.whitehats.com:relaytest@mail-abuse.org>
<<< 550 <@example.whitehats.com:relaytest@mail-abuse.org>... Relaying denied
Relay test 15
>>> RSET
<<< 250 Reset state
>>> MAIL FROM:
<<< 553
Relay test 16
>>> RSET
<<< 250 Reset state
>>> MAIL FROM:
<<< 250
>>> RCPT TO:
<<< 550
Relay test 17
>>> RSET
<<< 250 Reset state
>>> MAIL FROM:
<<< 250
>>> RCPT TO:
<<< 550
Relay test 18
>>> RSET
<<< 250 Reset state
>>> MAIL FROM:
<<< 250
>>> RCPT TO:
<<< 550
如果所有的测试通过,那么一切正常
Connection closed by foreign host.
[example ~]%
版权所有,未经许可,不得转载