{"id":3697,"date":"2015-06-02T19:29:21","date_gmt":"2015-06-02T19:29:21","guid":{"rendered":"http:\/\/www.deuzebranaweb.com.br\/?p=3697"},"modified":"2015-06-02T19:29:21","modified_gmt":"2015-06-02T19:29:21","slug":"dica-para-identificar-spam","status":"publish","type":"post","link":"https:\/\/blog.deuzebranaweb.com.br\/dica-para-identificar-spam\/","title":{"rendered":"Dica para Identificar Spam"},"content":{"rendered":"<p>Quando o load tiver alto e voc\u00ea dar o comando &#8220;top&#8221; e ver muitos processos do exim, \u00e9 bem prov\u00e1vel que seja spam. Digite o comando:<\/p>\n<p>tail -f \/var\/log\/exim_mainlog<\/p>\n<p>este comando ir\u00e1 lhe mostrar os logs do servidor de e-mail que est\u00e3o sendo gerado naquele momento. Voc\u00ea provavelmente ver\u00e1 algo assim crescendo rapidamente:<\/p>\n<div class=\"codetop\">CODE<\/div>\n<div class=\"codemain\">2005-12-01 12:43:29 1Ehpej-0007MK-Kl &lt;= &lt;&gt; R=1Ehpeg-0007JV-FE U=mailnull P=local S=4897<br \/>\n2005-12-01 12:43:30 1Ehpej-0007MK-Kl User 0 set for local_delivery transport is on the never_users list<br \/>\n2005-12-01 12:43:30 1Ehpej-0007MK-Kl == root@hostname.seuservidor.com &lt;nobody@hostname.seuservidor.com&gt; R=localuser T=local_delivery defer (-29): User 0 set for local_delivery transport is on the never_users list<br \/>\n2005-12-01 12:43:30 1Ehpej-0007MK-Kl ** root@hostname.seuservidor.com &lt;nobody@hostname.seuservidor.com&gt;: retry timeout exceeded<br \/>\n2005-12-01 12:43:30 1Ehpej-0007MK-Kl root@hostname.seuservidor.com &lt;nobody@hostname.seuservidor.com&gt;: error ignored<br \/>\n2005-12-01 12:43:30 1Ehpej-0007MK-Kl Completed<\/div>\n<p>At\u00e9 a\u00ed, com a configura\u00e7\u00e3o padr\u00e3o do exim, fica dificil identificar o spammer.<br \/>\nVoc\u00ea deve alterar o modo que o exim grava estas informa\u00e7\u00f5es no log, para isto, acesse o arquivo \/etc\/exim.conf e adicione a seguinte linha:<\/p>\n<p><b>log_selector = +address_rewrite +all_parents +arguments +connection_reject +delay_delivery +delivery_size +dnslist_defer +incoming_interface +incoming_port +lost_incoming_connection +queue_run +received_sender +received_recipients +retry_defer +sender_on_delivery +size_reject +skip_delivery +smtp_confirmation +smtp_connection +smtp_protocol_error +smtp_syntax_error +subject +tls_cipher +tls_peerdn<\/b><\/p>\n<p>salve o arquivo, reinicie o exim e v\u00e1 novamente em:<br \/>\ntail -f \/var\/log\/exim_mainlog<\/p>\n<p>O que voc\u00ea ver\u00e1 provavelmente \u00e9 algo parecido ao log abaixo:<\/p>\n<div class=\"codetop\">CODE<\/div>\n<div class=\"codemain\">2005-12-01 12:43:30 1Ehpek-0007Ml-57 User 0 set for local_delivery transport is on the never_users list<br \/>\n2005-12-01 12:43:30 1Ehpek-0007Ml-57 == root@hostname.seuservidor.com &lt;nobody@hostname.seuservidor.com&gt; R=localuser T=local_delivery defer$<br \/>\n2005-12-01 12:43:30 1Ehpek-0007Ml-57 ** root@hostname.seuservidor.com &lt;nobody@hostname.seuservidor.com&gt;: retry timeout exceeded<br \/>\n2005-12-01 12:43:30 cwd=\/home\/usuario\/public_html\/scriptmailicioso 3 args: \/usr\/sbin\/sendmail -t -i<br \/>\n2005-12-01 12:43:30 1Ehpek-0007Ml-57 root@hostname.seuservidor.com &lt;nobody@hostname.seuservidor.com&gt;: error ignored<\/div>\n<p>Note que em &#8220;cwd=\/home\/usuario\/public_html\/scriptmailicioso&#8221; est\u00e1 dizendo qual script est\u00e1 gerando o e-mail. Da\u00ed \u00e9 apagar o script malicioso, suspender o usu\u00e1rio e o problema est\u00e1 resolvido.<\/p>\n<p>\u00c9 bem poss\u00edvel que a sua fila de e-mails esteja lotada de spam que est\u00e3o congelados por l\u00e1, \u00e9 interessante apagar para que as mensagens que j\u00e1 est\u00e3o l\u00e1 n\u00e3o sejam enviadas. \u00c9 claro que deverm ter outros meios, principalmente executando comandos do exim que n\u00e3o tenho na cabe\u00e7a no momento, mas se a fila for muito grande, apague na unha &#8220;rm -rf \/var\/spool\/exim\/input&#8221;<\/p>\n<p>&nbsp;<\/p>\n<p>http:\/\/www.forumcpanel.com.br\/topic\/434-dica-para-identificar-spam\/<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Quando o load tiver alto e voc\u00ea dar o comando &#8220;top&#8221; e ver muitos processos do exim, \u00e9 bem prov\u00e1vel que seja spam. Digite o comando: tail -f \/var\/log\/exim_mainlog este comando ir\u00e1 lhe mostrar os logs do servidor de e-mail que est\u00e3o sendo gerado naquele&#8230;<\/p>\n","protected":false},"author":2,"featured_media":3737,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_angie_page":false,"page_builder":"","footnotes":""},"categories":[19],"tags":[],"class_list":["post-3697","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-whmcapenel"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.deuzebranaweb.com.br\/wp-json\/wp\/v2\/posts\/3697","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.deuzebranaweb.com.br\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.deuzebranaweb.com.br\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.deuzebranaweb.com.br\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.deuzebranaweb.com.br\/wp-json\/wp\/v2\/comments?post=3697"}],"version-history":[{"count":0,"href":"https:\/\/blog.deuzebranaweb.com.br\/wp-json\/wp\/v2\/posts\/3697\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.deuzebranaweb.com.br\/wp-json\/wp\/v2\/media\/3737"}],"wp:attachment":[{"href":"https:\/\/blog.deuzebranaweb.com.br\/wp-json\/wp\/v2\/media?parent=3697"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.deuzebranaweb.com.br\/wp-json\/wp\/v2\/categories?post=3697"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.deuzebranaweb.com.br\/wp-json\/wp\/v2\/tags?post=3697"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}