<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>クラック | ～下町物語～</title>
	<atom:link href="https://blog.rurineko.com/archives/tag/%E3%82%AF%E3%83%A9%E3%83%83%E3%82%AF/feed" rel="self" type="application/rss+xml" />
	<link>https://blog.rurineko.com</link>
	<description>入り組んだ現代社会に鋭いメスを入れ、おもしろおかしく書綴るブログである</description>
	<lastBuildDate>Thu, 05 Apr 2018 16:06:11 +0000</lastBuildDate>
	<language>ja</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://blog.rurineko.com/wp-content/uploads/2017/04/cropped-image2_9-32x32.jpg</url>
	<title>クラック | ～下町物語～</title>
	<link>https://blog.rurineko.com</link>
	<width>32</width>
	<height>32</height>
</image> 
<atom:link rel="hub" href="https://pubsubhubbub.appspot.com"/>
<atom:link rel="hub" href="https://pubsubhubbub.superfeedr.com"/>
<atom:link rel="hub" href="https://websubhub.com/hub"/>
<atom:link rel="self" href="https://blog.rurineko.com/archives/tag/%E3%82%AF%E3%83%A9%E3%83%83%E3%82%AF/feed"/>
	<item>
		<title>中国からのアタック！監視されているのも知らずに！</title>
		<link>https://blog.rurineko.com/archives/10849</link>
		
		<dc:creator><![CDATA[rurineko]]></dc:creator>
		<pubDate>Thu, 05 Apr 2018 23:18:15 +0000</pubDate>
				<category><![CDATA[1.趣味関連]]></category>
		<category><![CDATA[2.IT関連]]></category>
		<category><![CDATA[3.ホットな話題]]></category>
		<category><![CDATA[Linux(ミドル）]]></category>
		<category><![CDATA[Linux（OS）]]></category>
		<category><![CDATA[Router]]></category>
		<category><![CDATA[クラウド]]></category>
		<category><![CDATA[ネットワーク]]></category>
		<category><![CDATA[ネットワーク関連]]></category>
		<category><![CDATA[ファイヤウォール]]></category>
		<category><![CDATA[アタック]]></category>
		<category><![CDATA[クラック]]></category>
		<category><![CDATA[不正アクセス]]></category>
		<category><![CDATA[不正アクセス禁止法]]></category>
		<category><![CDATA[中国]]></category>
		<category><![CDATA[辞書攻撃]]></category>
		<guid isPermaLink="false">https://blog.rurineko.com/?p=10849</guid>

					<description><![CDATA[<p><span class="span-reading-time rt-reading-time" style="display: block;"><span class="rt-label rt-prefix">この記事を読む およそ時間</span> <span class="rt-time"> 3</span> <span class="rt-label rt-postfix">分</span></span>監視されているのも知らずに！ かれこれもう数ヶ月になろうか？私が管理しているとあるserverに、ポートスキャンをして、応答があるサービスに向かってアタックを開始した。それは、server乗っ取り系のアタックであるが、古 [&#8230;]</p>
<p>The post <a href="https://blog.rurineko.com/archives/10849">中国からのアタック！監視されているのも知らずに！</a> first appeared on <a href="https://blog.rurineko.com">～下町物語～</a>.</p>]]></description>
										<content:encoded><![CDATA[<span class="span-reading-time rt-reading-time" style="display: block;"><span class="rt-label rt-prefix">この記事を読む およそ時間</span> <span class="rt-time"> 3</span> <span class="rt-label rt-postfix">分</span></span><h2 id="midashi2">監視されているのも知らずに！</h2>
<p>かれこれもう数ヶ月になろうか？私が管理しているとあるserverに、ポートスキャンをして、応答があるサービスに向かってアタックを開始した。それは、server乗っ取り系のアタックであるが、古典的な手法でのアタックである。こちらも知ってはいながら、どんなことをしてくるか？詳細にログを取りながら手口を伺っていたのですが、そろそろ手を打とうかという事で対応を行った。</p>
<h3 id="midashi3">どんなアタックを仕掛けてきたか？</h3>
<p>まずは、私が契約しているグローバルIPに対してポートスキャンを確認した。次に、あるサイトの開発serverで、複数人で使用しているので、お分かりであろうかと思うのだが、SSHをあけているのだが、もちろん標準ポートではないですよ。先ほどのポートスキャンでＳＳＨサービスが応答してしまったので、それに向かってアタックを仕掛けてきた。</p>
<p>下記がそのアタックの一部抜粋したログである。スクリプトによる辞書アタックな典型的なアタック手法ですね。いろんな文言・言葉・名前などを送ってＩＤがあるかないか？を調べて居る模様が手に取るように分かりますね。このserverですよ、パスワード認証許可しておらず、公開鍵だけの認証にしているので、鍵を持ってこないとまず入れる事はないのです。また、前段にIPSがいてパケット単位で監視しているサーバになります。</p>
<p>Apr 1 03:48:01 stg sshd[32096]: input_userauth_request: invalid user beppie<br />
Apr 1 03:54:12 stg sshd[32196]: input_userauth_request: invalid user berangere<br />
Apr 1 04:00:22 stg sshd[32292]: input_userauth_request: invalid user berd<br />
Apr 1 04:06:32 stg sshd[32395]: input_userauth_request: invalid user berenice<br />
Apr 1 04:12:39 stg sshd[32487]: input_userauth_request: invalid user berenice<br />
Apr 1 04:18:48 stg sshd[32582]: input_userauth_request: invalid user berenice<br />
Apr 1 04:24:54 stg sshd[32677]: input_userauth_request: invalid user beret<br />
Apr 1 04:31:01 stg sshd[302]: input_userauth_request: invalid user berg<br />
Apr 1 04:37:07 stg sshd[400]: input_userauth_request: invalid user berger<br />
Apr 1 04:43:14 stg sshd[499]: input_userauth_request: invalid user berget<br />
Apr 1 04:49:18 stg sshd[595]: input_userauth_request: invalid user berk<br />
Apr 1 04:55:22 stg sshd[688]: input_userauth_request: invalid user berna<br />
Apr 1 05:01:25 stg sshd[791]: input_userauth_request: invalid user bernabe<br />
Apr 1 05:07:29 stg sshd[889]: input_userauth_request: invalid user bernabeu<br />
Apr 1 05:13:31 stg sshd[983]: input_userauth_request: invalid user bernadene<br />
Apr 1 05:19:32 stg sshd[1078]: input_userauth_request: invalid user bernadette<br />
Apr 1 05:25:34 stg sshd[1170]: input_userauth_request: invalid user bernadette<br />
Apr 1 05:31:36 stg sshd[1262]: input_userauth_request: invalid user bernadette<br />
Apr 1 05:37:37 stg sshd[1361]: input_userauth_request: invalid user bernadina<br />
Apr 1 05:43:37 stg sshd[1453]: input_userauth_request: invalid user bernadine<br />
Apr 1 05:49:37 stg sshd[1548]: input_userauth_request: invalid user bernadine<br />
Apr 1 05:55:37 stg sshd[1640]: input_userauth_request: invalid user bernadine<br />
Apr 1 06:01:38 stg sshd[1765]: input_userauth_request: invalid user bernard<br />
Apr 1 06:07:39 stg sshd[1861]: input_userauth_request: invalid user bernard<br />
Apr 1 06:13:39 stg sshd[1971]: input_userauth_request: invalid user bernarda<br />
Apr 1 06:19:38 stg sshd[2066]: input_userauth_request: invalid user bernardina<br />
Apr 1 06:25:39 stg sshd[2158]: input_userauth_request: invalid user bernardo<br />
Apr 1 06:31:40 stg sshd[2250]: input_userauth_request: invalid user bernd<br />
Apr 1 06:37:39 stg sshd[2342]: input_userauth_request: invalid user bernhard<br />
Apr 1 06:43:40 stg sshd[2434]: input_userauth_request: invalid user berni<br />
Apr 1 06:49:41 stg sshd[2526]: input_userauth_request: invalid user bernice<br />
Apr 1 06:55:42 stg sshd[2618]: input_userauth_request: invalid user bernice<br />
Apr 1 07:01:43 stg sshd[2721]: input_userauth_request: invalid user bernice<br />
Apr 1 07:07:44 stg sshd[2813]: input_userauth_request: invalid user berri<br />
Apr 1 07:13:45 stg sshd[2905]: input_userauth_request: invalid user berrie<br />
Apr 1 07:19:48 stg sshd[3000]: input_userauth_request: invalid user bert<br />
Apr 1 07:25:49 stg sshd[3092]: input_userauth_request: invalid user bertha<br />
Apr 1 07:31:54 stg sshd[3187]: input_userauth_request: invalid user bertha<br />
Apr 1 07:37:56 stg sshd[3279]: input_userauth_request: invalid user bertha<br />
Apr 1 07:43:58 stg sshd[3371]: input_userauth_request: invalid user bertille<br />
Apr 1 07:50:01 stg sshd[3463]: input_userauth_request: invalid user bertille<br />
Apr 1 07:56:04 stg sshd[3556]: input_userauth_request: invalid user bertille<br />
Apr 1 08:02:06 stg sshd[3661]: input_userauth_request: invalid user bertram<br />
Apr 1 08:08:09 stg sshd[3756]: input_userauth_request: invalid user bertrand<br />
Apr 1 08:14:12 stg sshd[3852]: input_userauth_request: invalid user bery<br />
Apr 1 08:20:18 stg sshd[3949]: input_userauth_request: invalid user beryl<br />
Apr 1 08:26:23 stg sshd[4042]: input_userauth_request: invalid user beryl<br />
Apr 1 08:32:27 stg sshd[4134]: input_userauth_request: invalid user beryl<br />
Apr 1 08:38:33 stg sshd[4226]: input_userauth_request: invalid user beryle<br />
Apr 1 08:44:41 stg sshd[4318]: input_userauth_request: invalid user beshi<br />
Apr 1 08:50:47 stg sshd[4410]: input_userauth_request: invalid user bess<br />
Apr 1 08:56:54 stg sshd[4505]: input_userauth_request: invalid user bess<br />
Apr 1 09:03:02 stg sshd[4608]: input_userauth_request: invalid user bess<br />
Apr 1 09:09:12 stg sshd[4708]: input_userauth_request: invalid user bessie<br />
Apr 1 09:15:25 stg sshd[4804]: input_userauth_request: invalid user bessie<br />
Apr 1 09:21:38 stg sshd[4899]: input_userauth_request: invalid user bessie<br />
Apr 1 09:27:50 stg sshd[4991]: input_userauth_request: invalid user bessy<br />
Apr 1 09:34:04 stg sshd[5088]: input_userauth_request: invalid user best<br />
Apr 1 09:40:18 stg sshd[5191]: input_userauth_request: invalid user bestman</p>
<h3 id="midashi3">どこからよ！？</h3>
<p>って実IPいりですよｗ今回だけ特別ですからね。中国から発信されているっぽですね。以前は<span style="color: #ff0000;"><strong>166.111.5.141</strong><span style="color: #000000;">だけだったのですが最近３カ所からアタックし始めたのでウザイので泳がせずブロックする事にしました。見て分かる通り、気づかれないように時間も数分に１度程度のアタックを継続して送ってくる奴っぽいですね。とはいえですね、茶番に付き合う気はないのでとっととブロックです。</span></span></p>
<p><img fetchpriority="high" decoding="async" class="alignnone size-full wp-image-10858" src="https://blog.rurineko.com/wp-content/uploads/2018/04/SnapCrab_NoName_2018-4-5_23-19-39_No-00.png" alt="" width="386" height="426" /></p>
<p>泳がすこと数ヶ月、下記のアタック回数となってます。ひどいですよねぇ。</p>
<p>[root@stg ~]# cat /var/log/secure* | grep 166.111.5.141 | wc -l<br />
334</p>
<p>[root@stg ~]# cat /var/log/secure* | grep 103.235.247.242 | wc -l</p>
<p>15281</p>
<p>IPひろばで調べて見ると！中華人民共和国ってでてますね。</p>
<p><img decoding="async" class="alignnone size-full wp-image-10851" src="https://blog.rurineko.com/wp-content/uploads/2018/04/SnapCrab_NoName_2018-4-5_23-25-30_No-00.png" alt="" width="379" height="594" /></p>
<p>ここら辺りからアクセスされているっぽです。まあ、プロバイダーの所在地でしょうけど。</p>
<p><img decoding="async" class="alignnone wp-image-10852" src="https://blog.rurineko.com/wp-content/uploads/2018/04/SnapCrab_NoName_2018-4-5_23-26-59_No-00-400x192.png" alt="" width="902" height="433" srcset="https://blog.rurineko.com/wp-content/uploads/2018/04/SnapCrab_NoName_2018-4-5_23-26-59_No-00-400x192.png 400w, https://blog.rurineko.com/wp-content/uploads/2018/04/SnapCrab_NoName_2018-4-5_23-26-59_No-00-620x298.png 620w, https://blog.rurineko.com/wp-content/uploads/2018/04/SnapCrab_NoName_2018-4-5_23-26-59_No-00-768x369.png 768w, https://blog.rurineko.com/wp-content/uploads/2018/04/SnapCrab_NoName_2018-4-5_23-26-59_No-00-940x451.png 940w, https://blog.rurineko.com/wp-content/uploads/2018/04/SnapCrab_NoName_2018-4-5_23-26-59_No-00.png 1216w" sizes="(max-width: 902px) 100vw, 902px" /></p>
<p>ブログ的には、記事になる案件なのでいいのですが、個人的には人のサーバにログインしてやろうなんてけしからん訳です。皆様も個人的な趣味・趣向でクラックなんかしてると、国内には不正アクセス禁止法なるものが存在していますので、痛い目を見るかも知れませんよ。くれぐれもやめておいた方がいいですよ。</p>
<h3 id="midashi3">ブロックしたIPは？</h3>
<p>ポリシーは詳しくは言えませんが、ブロックしたのはこのIPの32ビットマスクでブロックしてだけではありません。むしろ/32なんかでブロックする訳がありません。もう分かりましたよね？はい。まあそういう事ですね。</p>
<h3 id="midashi3">結論</h3>
<p><img loading="lazy" decoding="async" class="alignnone wp-image-10855" src="https://blog.rurineko.com/wp-content/uploads/2018/04/SnapCrab_NoName_2018-4-6_1-3-35_No-00-400x34.png" alt="" width="600" height="51" srcset="https://blog.rurineko.com/wp-content/uploads/2018/04/SnapCrab_NoName_2018-4-6_1-3-35_No-00-400x34.png 400w, https://blog.rurineko.com/wp-content/uploads/2018/04/SnapCrab_NoName_2018-4-6_1-3-35_No-00.png 471w" sizes="auto, (max-width: 600px) 100vw, 600px" /></p>
<p>ブロックして、１時間程度で３つIPからのアタックは停止したようです。向こうからしてみれば、IPが変わったんだろう程度だろうですが、アタックしている事もログを取って監視されているという事をお忘れ無く！</p><p>The post <a href="https://blog.rurineko.com/archives/10849">中国からのアタック！監視されているのも知らずに！</a> first appeared on <a href="https://blog.rurineko.com">～下町物語～</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>【手口】実際に辞書アタックってこういう感じ！</title>
		<link>https://blog.rurineko.com/archives/5205</link>
		
		<dc:creator><![CDATA[rurineko]]></dc:creator>
		<pubDate>Fri, 23 Oct 2015 14:41:23 +0000</pubDate>
				<category><![CDATA[3.ホットな話題]]></category>
		<category><![CDATA[Linux(ミドル）]]></category>
		<category><![CDATA[アタック]]></category>
		<category><![CDATA[クラック]]></category>
		<category><![CDATA[シェル]]></category>
		<category><![CDATA[ロシアから愛をこめて]]></category>
		<guid isPermaLink="false">http://blog.rurineko.com/?p=5205</guid>

					<description><![CDATA[<p><span class="span-reading-time rt-reading-time" style="display: block;"><span class="rt-label rt-prefix">この記事を読む およそ時間</span> <span class="rt-time"> 9</span> <span class="rt-label rt-postfix">分</span></span>&#160; 185.17.1.248のIPからのアタックをgrepかけた結果である。 ○ちなみにアタックしてきているIPはロシアのモスクワからはるばる海を越えてやってきてます。 whoisをひくと、いかのプロバイダから [&#8230;]</p>
<p>The post <a href="https://blog.rurineko.com/archives/5205">【手口】実際に辞書アタックってこういう感じ！</a> first appeared on <a href="https://blog.rurineko.com">～下町物語～</a>.</p>]]></description>
										<content:encoded><![CDATA[<span class="span-reading-time rt-reading-time" style="display: block;"><span class="rt-label rt-prefix">この記事を読む およそ時間</span> <span class="rt-time"> 9</span> <span class="rt-label rt-postfix">分</span></span><p>&nbsp;</p>
<p>185.17.1.248のIPからのアタックをgrepかけた結果である。</p>
<p>○ちなみにアタックしてきているIPはロシアのモスクワからはるばる海を越えてやってきてます。</p>
<p>whoisをひくと、いかのプロバイダからやってきている事が確認できます。</p>
<p>うぜーな！</p>
<pre>  % This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
%       To receive output for a database update, use the "-B" flag.

% Information related to '185.17.1.0 - 185.17.1.255'

% Abuse contact for '185.17.1.0 - 185.17.1.255' is 'info@le.lc'

inetnum:        185.17.1.0 - 185.17.1.255
org:            ORG-LEL4-RIPE
netname:        LE
descr:          LE
country:        RU
admin-c:        NA4577-RIPE
tech-c:         NA4577-RIPE
status:         ASSIGNED PA
mnt-by:         MNT-NTX
created:        2015-08-11T14:07:37Z
last-modified:  2015-08-11T14:07:37Z
source:         RIPE

organisation:   ORG-LEL4-RIPE
org-name:       Longbow Electric LLC
org-type:       Other
address:        Ekvatornaya str., bld 14, app 31
address:        630060
address:        Novosibirsk
address:        RUSSIAN FEDERATION
phone:          +79859746811
fax-no:         +79859746811
abuse-c:        AR16767-RIPE
mnt-ref:        VG82356-MNT
mnt-ref:        MNT-NTX
mnt-ref:        MNT-NTX
mnt-by:         MNT-NTX
abuse-mailbox:  abuse@le.lc
created:        2013-01-21T14:04:53Z
last-modified:  2015-09-30T09:57:53Z
source:         RIPE # Filtered

role:           NTX-NOC
address:        Russia, Moscow, Nizhgorodskaya 32
nic-hdl:        NA4577-RIPE
mnt-by:         MNT-NTX
remarks:        ***
remarks:        ***
remarks:        ***
created:        2014-11-05T18:02:34Z
last-modified:  2014-11-05T18:03:36Z
source:         RIPE # Filtered

% Information related to '185.17.1.0/24AS199388'

route:          185.17.1.0/24
descr:          LE-1
origin:         AS199388
mnt-by:         MNT-NTX
created:        2015-08-24T16:18:58Z
last-modified:  2015-08-24T16:18:58Z
source:         RIPE

% This query was served by the RIPE Database Query Service version 1.80.1 (DB-2)</pre>
<p>&nbsp;</p>
<p>○送信テストをしてもて、オープンリレーになっていないかをチェックしていますね。</p>
<p>NOQUEUE: reject: RCPT from unknown[185.17.1.248]: 554 5.7.1 &lt;unknown[185.17.1.248]&gt;: Client host rejected: Access denied;</p>
<p>○辞書アタックってどういうログをはくのか！？不明な方もいらっしゃると思うので一例を下記の通り実際のログを掲載してみました。</p>
<p>ざーっと、思いつく文言でユーザがいるかいないかをチェックしていますね。</p>
<p>ユーザがいると、パスワードを求められるので、次のステップとしては</p>
<p>そのユーザへの辞書クラックを始める訳です。</p>
<p>Oct 18 05:28:59 [809] : auth failure: [user=service] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 05:33:46 [812] : auth failure: [user=agent] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 05:43:35 [809] : auth failure: [user=contact] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 05:47:38 [809] : auth failure: [user=service] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 05:51:59 [812] : auth failure: [user=agent] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 06:04:06 [812] : auth failure: [user=spam] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 06:08:03 [812] : auth failure: [user=video] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 06:22:43 [812] : auth failure: [user=spam] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 06:26:07 [812] : auth failure: [user=video] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 06:30:00 [812] : auth failure: [user=contact] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 06:42:14 [812] : auth failure: [user=sekretariat] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 06:57:37 [812] : auth failure: [user=contakt] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 07:00:23 [812] : auth failure: [user=sekretariat] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 07:16:15 [812] : auth failure: [user=contact] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 07:16:26 [812] : auth failure: [user=secretaria] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 07:32:37 [812] : auth failure: [user=sales] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 07:34:39 [812] : auth failure: [user=secretaria] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 07:48:56 [812] : auth failure: [user=exit] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 07:50:42 [812] : auth failure: [user=webmaster] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 07:58:54 [812] : auth failure: [user=admin] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 08:02:18 [812] : auth failure: [user=contact] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 08:08:55 [812] : auth failure: [user=webmaster] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 08:23:46 [812] : auth failure: [user=education] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 08:24:56 [812] : auth failure: [user=baseball] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 08:43:04 [812] : auth failure: [user=baseball] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 08:58:30 [812] : auth failure: [user=fax] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 08:59:07 [812] : auth failure: [user=backup] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 09:16:53 [812] : auth failure: [user=fax] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 09:17:17 [812] : auth failure: [user=backup] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 09:33:29 [812] : auth failure: [user=backuppc] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 09:51:39 [812] : auth failure: [user=formation] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 09:51:47 [812] : auth failure: [user=backuppc] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 10:07:50 [812] : auth failure: [user=badmin] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 10:07:57 [809] : auth failure: [user=general] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 10:26:02 [809] : auth failure: [user=badmin] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 10:42:09 [809] : auth failure: [user=bank] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 10:42:38 [812] : auth failure: [user=guest] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 10:55:00 [812] : auth failure: [user=admin] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 11:00:27 [812] : auth failure: [user=bank] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 11:01:04 [809] : auth failure: [user=guest] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 11:16:42 [809] : auth failure: [user=billing] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 11:35:03 [809] : auth failure: [user=billing] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 11:35:43 [809] : auth failure: [user=sample] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 11:51:08 [809] : auth failure: [user=biblioteca] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 11:52:11 [812] : auth failure: [user=sales01] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 12:09:27 [812] : auth failure: [user=biblioteca] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 12:10:29 [812] : auth failure: [user=sales01] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 12:25:33 [812] : auth failure: [user=blink] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 12:43:53 [812] : auth failure: [user=blink] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 12:45:15 [812] : auth failure: [user=sales1] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 12:59:50 [812] : auth failure: [user=blog] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 13:18:09 [812] : auth failure: [user=blog] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 13:20:01 [812] : auth failure: [user=score] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 13:27:03 [812] : auth failure: [user=admin] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 13:34:21 [812] : auth failure: [user=bo] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 13:36:15 [812] : auth failure: [user=scores] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 13:52:48 [812] : auth failure: [user=bo] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 13:54:41 [812] : auth failure: [user=scores] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 14:09:04 [812] : auth failure: [user=boffice] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 14:11:01 [812] : auth failure: [user=scan] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 14:27:24 [812] : auth failure: [user=boffice] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 14:43:37 [812] : auth failure: [user=book] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 15:02:01 [812] : auth failure: [user=book] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 15:04:18 [812] : auth failure: [user=scanner] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 15:18:15 [812] : auth failure: [user=box] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 15:36:41 [812] : auth failure: [user=box] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 15:53:02 [812] : auth failure: [user=business] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 15:55:25 [809] : auth failure: [user=send] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 16:11:34 [809] : auth failure: [user=business] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 16:13:59 [809] : auth failure: [user=send] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 16:24:09 [809] : auth failure: [user=admin] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 16:27:47 [809] : auth failure: [user=buster] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 16:30:12 [809] : auth failure: [user=setting] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 16:46:06 [809] : auth failure: [user=buster] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 17:02:23 [809] : auth failure: [user=cache] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 17:20:43 [809] : auth failure: [user=cache] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 17:36:55 [812] : auth failure: [user=captured] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 17:55:19 [812] : auth failure: [user=captured] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 17:58:27 [812] : auth failure: [user=root] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 18:11:22 [812] : auth failure: [user=captures] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 18:14:49 [812] : auth failure: [user=hr] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 18:29:44 [812] : auth failure: [user=captures] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 18:33:16 [812] : auth failure: [user=hr] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 18:46:00 [812] : auth failure: [user=ceo] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 18:56:20 [812] : auth failure: [user=admin] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 19:04:24 [812] : auth failure: [user=ceo] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 19:08:10 [812] : auth failure: [user=info] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 19:20:35 [812] : auth failure: [user=checkin] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 19:24:21 [812] : auth failure: [user=intern] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 19:38:56 [812] : auth failure: [user=checkin] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 19:42:47 [812] : auth failure: [user=intern] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 19:55:17 [812] : auth failure: [user=checkout] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 20:13:46 [809] : auth failure: [user=checkout] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 20:30:02 [809] : auth failure: [user=chief] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 20:48:29 [809] : auth failure: [user=chief] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 20:52:16 [809] : auth failure: [user=library] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 21:04:43 [809] : auth failure: [user=clamav] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 21:08:34 [812] : auth failure: [user=monitor] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 21:22:53 [812] : auth failure: [user=clamav] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 21:26:47 [809] : auth failure: [user=monitor] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 21:38:44 [809] : auth failure: [user=clerk] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 21:42:47 [812] : auth failure: [user=newsletter] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 21:53:10 [812] : auth failure: [user=admin] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 21:56:38 [812] : auth failure: [user=clerk] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 22:00:56 [812] : auth failure: [user=newsletter] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 22:12:06 [812] : auth failure: [user=client] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 22:16:57 [809] : auth failure: [user=office] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 22:30:02 [809] : auth failure: [user=client] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 22:35:13 [809] : auth failure: [user=office] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 22:45:51 [809] : auth failure: [user=communication] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 22:51:11 [809] : auth failure: [user=reception] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 22:59:17 [812] : auth failure: [user=rurineko] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 23:03:45 [812] : auth failure: [user=communication] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 23:09:33 [812] : auth failure: [user=reception] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 23:19:31 [812] : auth failure: [user=com] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 23:37:31 [812] : auth failure: [user=com] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 23:43:39 [812] : auth failure: [user=user01] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 23:53:20 [809] : auth failure: [user=couple] [service=smtp] [realm=mx.a.com] [mech=shadow] [reason=Unknown]<br />
Oct 18 23:59:56 [809] : auth failure: [user=user1] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 19 05:14:44 [809] : auth failure: [user=abuse] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 19 08:51:19 [812] : auth failure: [user=abuse] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 19 12:30:09 [809] : auth failure: [user=abuse] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 19 15:24:00 [812] : auth failure: [user=gomi] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 19 16:11:32 [809] : auth failure: [user=abuse] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 19 19:54:52 [809] : auth failure: [user=abuse] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 19 23:34:31 [812] : auth failure: [user=test] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 20 02:09:38 [780] : auth failure: [user=test] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 20 10:33:26 [782] : auth failure: [user=asdgas] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 20 10:33:53 [780] : auth failure: [user=asdgas] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:11:48 [782] : auth failure: [user=noauth] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:11:51 [780] : auth failure: [user=spam] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:11:53 [782] : auth failure: [user=test] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:11:54 [782] : auth failure: [user=noauth] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:11:56 [782] : auth failure: [user=info] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:11:57 [782] : auth failure: [user=spam] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:11:58 [782] : auth failure: [user=admin] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:00 [782] : auth failure: [user=test] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:01 [782] : auth failure: [user=administrator] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:03 [782] : auth failure: [user=info] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:03 [782] : auth failure: [user=mail] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:05 [780] : auth failure: [user=admin] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:06 [780] : auth failure: [user=postmaster] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:08 [780] : auth failure: [user=administrator] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:09 [780] : auth failure: [user=sales] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:10 [780] : auth failure: [user=mail] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:11 [782] : auth failure: [user=support] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:13 [782] : auth failure: [user=postmaster] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:14 [782] : auth failure: [user=webmaster] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:16 [782] : auth failure: [user=sales] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:16 [782] : auth failure: [user=help] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:18 [782] : auth failure: [user=support] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:19 [782] : auth failure: [user=contact] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:21 [782] : auth failure: [user=webmaster] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:21 [782] : auth failure: [user=office] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:23 [782] : auth failure: [user=help] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:24 [782] : auth failure: [user=staff] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:26 [782] : auth failure: [user=contact] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:26 [782] : auth failure: [user=news] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:29 [782] : auth failure: [user=office] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:29 [782] : auth failure: [user=careers] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:31 [782] : auth failure: [user=staff] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:32 [782] : auth failure: [user=fax] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:34 [782] : auth failure: [user=news] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:34 [782] : auth failure: [user=abuse] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:37 [782] : auth failure: [user=careers] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:37 [782] : auth failure: [user=hostmaster] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:39 [782] : auth failure: [user=fax] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:39 [782] : auth failure: [user=noreply] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:42 [782] : auth failure: [user=abuse] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:42 [782] : auth failure: [user=pop3] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:44 [782] : auth failure: [user=hostmaster] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:45 [782] : auth failure: [user=sysadmin] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:47 [782] : auth failure: [user=noreply] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:47 [782] : auth failure: [user=web] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:50 [782] : auth failure: [user=pop3] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:50 [782] : auth failure: [user=www] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:52 [782] : auth failure: [user=sysadmin] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:55 [782] : auth failure: [user=web] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 00:12:57 [782] : auth failure: [user=www] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 22 22:12:13 [782] : auth failure: [user=muietrista] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 22 22:13:03 [780] : auth failure: [user=muietrista] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 23 02:08:21 [782] : auth failure: [user=admin] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 23 02:09:19 [780] : auth failure: [user=administrator] [service=smtp] [realm=] [mech=shadow] [reason=Unknown]<br />
Oct 23 03:59:31 [780] : auth failure: [user=test] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]<br />
Oct 23 13:07:12 [780] : auth failure: [user=gomi] [service=smtp] [realm=a.com] [mech=shadow] [reason=Unknown]</p><p>The post <a href="https://blog.rurineko.com/archives/5205">【手口】実際に辞書アタックってこういう感じ！</a> first appeared on <a href="https://blog.rurineko.com">～下町物語～</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>まじか！まさか１ID　辞書マッチングでクラックｗ</title>
		<link>https://blog.rurineko.com/archives/5106</link>
		
		<dc:creator><![CDATA[rurineko]]></dc:creator>
		<pubDate>Sun, 18 Oct 2015 11:17:21 +0000</pubDate>
				<category><![CDATA[Linux(ミドル）]]></category>
		<category><![CDATA[ネットワーク]]></category>
		<category><![CDATA[クラック]]></category>
		<guid isPermaLink="false">http://blog.rurineko.com/?p=5106</guid>

					<description><![CDATA[<p><span class="span-reading-time rt-reading-time" style="display: block;"><span class="rt-label rt-prefix">この記事を読む およそ時間</span> <span class="rt-time"> 1未満</span> <span class="rt-label rt-postfix">分</span></span>まじか！！！！ パターンマッチングでクラックされ、そこからメールがまかれていた用だ。 件数としては、それほど無いけどクレームが来て浮き彫りになって さっき詳細な通報時のヘッダーをもらってメッセージIDより調査した結果そう [&#8230;]</p>
<p>The post <a href="https://blog.rurineko.com/archives/5106">まじか！まさか１ID　辞書マッチングでクラックｗ</a> first appeared on <a href="https://blog.rurineko.com">～下町物語～</a>.</p>]]></description>
										<content:encoded><![CDATA[<span class="span-reading-time rt-reading-time" style="display: block;"><span class="rt-label rt-prefix">この記事を読む およそ時間</span> <span class="rt-time"> 1未満</span> <span class="rt-label rt-postfix">分</span></span><p>まじか！！！！</p>
<p>パターンマッチングでクラックされ、そこからメールがまかれていた用だ。</p>
<p>件数としては、それほど無いけどクレームが来て浮き彫りになって</p>
<p>さっき詳細な通報時のヘッダーをもらってメッセージIDより調査した結果そうだった！</p>
<p>接続もとは「188.53.220.208」サウジアラビアだった！下記が生LOGである。</p>
<p>ろくな事してくれねーなｗ　オープンリレーは一切ないし</p>
<p>ブラックリストチェックもバッチで監視しているから、大丈夫だと思ってたんだけどな。</p>
<p>サーバ運用者様お気をつけて運用されてください。</p>
<p>&nbsp;</p>
<p>＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾＾</p>
<p>Oct 5 00:00:04 mx postfix/smtpd[29710]: 79D2F61A0DF: client=unknown[188.53.220.208], sasl_method=PLAIN, sasl_username=gomi1234@aaaaaa.com<br />
Oct 5 00:00:05 mx /usr/local/sbin/geoip-policyd[29716]: address:188.53.220.208 country:SA result:DUNNO<br />
Oct 5 00:00:17 mx last message repeated 18 times<br />
Oct 5 00:00:18 mx postfix/cleanup[29717]: 79D2F61A0DF: message-id=&lt;34235a9c7ebe$b96b9e62$83b274f8$@aaaaaa.com&gt;<br />
Oct 5 00:00:18 mx postfix/qmgr[18126]: 79D2F61A0DF: from=&lt;marievercelletto@aaaaaa.com&gt;, size=2000, nrcpt=20 (queue active)<br />
Oct 5 00:00:18 mx postfix/smtpd[29722]: connect from localhost.localdomain[127.0.0.1]<br />
Oct 5 00:00:18 mx postfix/smtpd[29722]: 9D1A361A181: client=localhost.localdomain[127.0.0.1]<br />
Oct 5 00:00:18 mx postfix/cleanup[29717]: 9D1A361A181: message-id=&lt;34235a9c7ebe$b96b9e62$83b274f8$@aaaaaa.com&gt;<br />
Oct 5 00:00:18 mx postfix/qmgr[18126]: 9D1A361A181: from=&lt;marievercelletto@aaaaaa.com&gt;, size=2294, nrcpt=20 (queue active)<br />
Oct 5 00:00:18 mx postfix/smtpd[29722]: disconnect from localhost.localdomain[127.0.0.1]<br />
Oct 5 00:00:18 mx amavis[28622]: (28622-11) Passed CLEAN {RelayedOpenRelay}, [188.53.220.208] &lt;marievercelletto@aaaaaa.com&gt; -&gt; &lt;Gary.Machado@artemiscourtage.com&gt;,&lt;g.vercelletto@free.fr&gt;,&lt;georges.markovic@free.fr&gt;,&lt;gilles.lebatard@free.fr&gt;,&lt;fredericlucfrancois@gmail.com&gt;,&lt;gael.nini@gmail.com&gt;,&lt;georges.markovic@gmail.com&gt;,&lt;gitelacroisette@gmail.com&gt;,&lt;gladys.lapalus@gmail.com&gt;,&lt;malakoff@guyhoquet.com&gt;,&lt;vanves@guyhoquet.com&gt;,&lt;frguise@hotmail.com&gt;,&lt;gaellecauvin@hotmail.com&gt;,&lt;gaelle-masson@orange.fr&gt;,&lt;gladys.lapalus@orange.fr&gt;,&lt;gabrielle.oiry.75112@paris.notaires.fr&gt;,&lt;martine.graziadey@total.com&gt;,&lt;geraldine.lombardo@yahoo.fr&gt;,&lt;grey_paris@yahoo.fr&gt;,&lt;guilletgilbert@yahoo.fr&gt;, Message-ID: &lt;34235a9c7ebe$b96b9e62$83b274f8$@aaaaaa.com&gt;, mail_id: GPnE7ipa7x5p, Hits: -, size: 2212, queued_as: 9D1A361A181, dkim_sd=key1:aaaaaa.com, 208 ms<br />
Oct 5 00:00:18 mx postfix/smtp[29719]: 79D2F61A0DF: to=&lt;Gary.Machado@artemiscourtage.com&gt;, relay=127.0.0.1[127.0.0.1]:10024, delay=15, delays=15/0.01/0/0.21, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as 9D1A361A181)<br />
Oct 5 00:00:18 mx postfix/smtp[29719]: 79D2F61A0DF: to=&lt;g.vercelletto@free.fr&gt;, relay=127.0.0.1[127.0.0.1]:10024, delay=15, delays=15/0.01/0/0.21, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as 9D1A361A181)<br />
Oct 5 00:00:18 mx postfix/smtp[29719]: 79D2F61A0DF: to=&lt;georges.markovic@free.fr&gt;, relay=127.0.0.1[127.0.0.1]:10024, delay=15, delays=15/0.01/0/0.21, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as 9D1A361A181)<br />
Oct 5 00:00:18 mx postfix/smtp[29719]: 79D2F61A0DF: to=&lt;gilles.lebatard@free.fr&gt;, relay=127.0.0.1[127.0.0.1]:10024, delay=15, delays=15/0.01/0/0.21, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as 9D1A361A181)<br />
Oct 5 00:00:18 mx postfix/smtp[29719]: 79D2F61A0DF: to=&lt;fredericlucfrancois@gmail.com&gt;, relay=127.0.0.1[127.0.0.1]:10024, delay=15, delays=15/0.01/0/0.21, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as 9D1A361A181)<br />
Oct 5 00:00:18 mx postfix/smtp[29719]: 79D2F61A0DF: to=&lt;gael.nini@gmail.com&gt;, relay=127.0.0.1[127.0.0.1]:10024, delay=15, delays=15/0.01/0/0.21, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as 9D1A361A181)<br />
Oct 5 00:00:18 mx postfix/smtp[29719]: 79D2F61A0DF: to=&lt;georges.markovic@gmail.com&gt;, relay=127.0.0.1[127.0.0.1]:10024, delay=15, delays=15/0.01/0/0.21, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as 9D1A361A181)</p>
<p>&nbsp;</p><p>The post <a href="https://blog.rurineko.com/archives/5106">まじか！まさか１ID　辞書マッチングでクラックｗ</a> first appeared on <a href="https://blog.rurineko.com">～下町物語～</a>.</p>]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
