这是pw@example.com转发给我的邮件,源文件如下:
Return-Path: <pw@example.com>
Delivered-To: dannil@example.com
Received: from localhost (mail.example.com [127.0.0.1])
by mail.example.com (iRedMail) with ESMTP id C52301900620
for <dannil@example.com>; Fri, 22 Apr 2011 11:17:51 +0800 (CST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=example.com; h=
user-agent:message-id:reply-to:organization:subject:subject:to
:from:from:date:date:content-transfer-encoding:content-type
:content-type:mime-version; s=dkim; t=1303442270; x=1304306270;
bh=YG5w/mlztxnWf4+Ba4Wmu2feBcpPCVSMVb8S9RTxoGk=; b=Rl5dIcNwIPVI
NvuH3OhKlRI5pq2l5VJsgcuOe8M6qbzfwQ50STYwHe7Pdj9e8wxk/CU90H05qGbg
XNeZgVU29aVOOiC7cxrMJ0zSjjintCzFDBvr9TsCfPw7RrGr8nlKd6xT49m4Xoo1
o6WLE+MSFUOhIN1Vb4x8TN8TLnvRWqI=
X-Virus-Scanned: Debian amavisd-new at mail.example.com
Received: from mail.example.com ([127.0.0.1])
by localhost (mail.example.com [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id Q9QT-doKjcxw for <dannil@example.com>;
Fri, 22 Apr 2011 11:17:50 +0800 (CST)
Received: from mail.example.com (mail.example.com [127.0.0.1])
by mail.example.com (iRedMail) with ESMTP id 7283E19002A4
for <dannil@example.com>; Fri, 22 Apr 2011 11:17:50 +0800 (CST)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8;
format=flowed
Content-Transfer-Encoding: 8bit
Date: Fri, 22 Apr 2011 11:17:50 +0800
From: =?UTF-8?Q?=E7=8E=8B=E5=9B=BD=E7=BB=B4?= <pw@example.com>
To: =?UTF-8?Q?=E7=8E=8B=E7=AB=8B=E6=9D=B0?= <dannil@example.com>
Subject: Fwd: most#article#lives
Organization: =?UTF-8?Q?=E6=97=A0=E9=94=A1=E7=99=BE=E6=AD=A5=E7=A7=91?=
=?UTF-8?Q?=E6=8A=80=E6=9C=89=E9=99=90=E5=85=AC=E5=8F=B8?=
Reply-To: <pw@example.com>
Mail-Reply-To: <pw@example.com>
Message-ID: <2d1b65a61cf904d03b6a811414d01422@example.com>
X-Sender: pw@example.com
User-Agent: =?UTF-8?Q?=E6=97=A0=E9=94=A1=E7=99=BE=E6=AD=A5=E7=A7=91?=
=?UTF-8?Q?=E6=8A=80=E6=9C=89=E9=99=90=E5=85=AC=E5=8F=B8=E7=94=B5=E5=AD=90?=
=?UTF-8?Q?=E9=82=AE=E4=BB=B6=E7=B3=BB=E7=BB=9F/0=2E5=2E1?=
-------- Original Message --------
Subject: most#article#lives
Date: Thu, 21 Apr 2011 07:08:04 +0800 (CST)
From: qualityglobe@mail.example.com
To: pw@example.com
When you feel depressed and lonely, it's better to have a cup of tea &
visit your closest friends.
http://bit.ly/g6bOnZ
一般服务器被黑该如何排查呢?第一次被黑,不知道该从何下手,抓狂....
我用nmap扫描了一下。发现多开了下面的端口
PORT STATE SERVICE
53/tcp filtered domain
222/tcp filtered rsh-spx
4444/tcp filtered krb524
4445/tcp filtered unknown
8081/tcp filtered blackice-icecap
8099/tcp filtered unknown