´ÙÀ½ ÀÌÀü Â÷·Ê

6. Third Party Relay

6.1 Third Party Relay¶õ?

Third Party Relay¶õ °£´ÜÇÏ°Ô ¸»Çؼ­ SMTP¼­¹öÀÇ »ç¿ëÀÚ°¡ ¾Æ´Ñ »ç¶÷(º¸Åë ½ºÆÔÀ» »Ñ¸®±â À§ÇÑ ¾ÇÀÇ·Î)ÀÌ SMTP¼­¹ö¸¦ ÀÌ¿ëÇÏ´Â °ÍÀÔ´Ï´Ù. µû¶ó¼­ A ÄÄÇ»ÅÍÀÇ SMTP¼­¹ö¸¦ C ÄÄÇ»ÅÍ¿¡ ÀÖ´Â »ç¿ëÀÚ°¡ B ÄÄÇ»ÅÍ·Î ¸ÞÀÏÀ» º¸³»±â À§ÇØ ÀÌ¿ëÇϴ°æ¿ì¸¦ ¸»ÇÕ´Ï´Ù. Á»´õ ÀÚ¼¼ÇÑ ¼³¸íÀº What is Third-Party Mail Relay?¸¦ Âü°íÇϽñ⠹ٶø´Ï´Ù.

¾ÆÁ÷±îÁö ¸¹Àº ¼­¹öµéÀÌ Third Party Relay¸¦ Çã¿ëÇÏ°í ÀÖÀ¸¸ç, À̶§¹®¿¡ ÀÚ½ÅÀÌ °ü¸®Çϴ ȣ½ºÆ®°¡ ½ºÆÔ »çÀÌÆ®·Î ÀνĵǴ°͵µ ¸ð¸£°í ÀÖ´Â °æ¿ì°¡ Çã´ÙÇÕ´Ï´Ù. ¿ì¼± ÀÚ½ÅÀÌ °ü¸®Çϴ ȣ½ºÆ®ÀÇ SMTP¼­¹ö°¡ Third Party Relay¸¦ Çã¿ëÇÏ´ÂÁö¸¦ üũÇÏ·Á¸é Is My Mailer Vulnerable?¿¡¼­ ÇÏ½Ç ¼ö ÀÖ½À´Ï´Ù. ²À Çغ¸½Ã±â ¹Ù¶ø´Ï´Ù.

6.2 ¼³Á¤¹æ¹ý

sendmail 8.7.x ÀÌÇÏ

Third Party Relay¸¦ ¸·À¸·Á¸é Àû¾îµµ sendmail 8.8.x °¡ µÇ¾î¾ß ÇÕ´Ï´Ù. µû¶ó¼­ ÃÖ½ÅÀÇ sendmail·Î ¾÷±×·¹À̵带 ÇϽñ⠹ٶø´Ï´Ù.

sendmail 8.8.x

sendmail.cf¿¡ ¾Æ·¡¿Í °°Àº Rule setÀ» ³Ö°í sendmail.cRÆÄÀÏ¿¡ relay¸¦ Çã¿ëÇϴ ȣ½ºÆ®ÀÇ FQDNÀ̳ª IP address¸¦ ÀÔ·ÂÇÏ¸é µË´Ï´Ù. ( http://www.sendmail.org/antispam.html¿¡¼­´Â IP address¸¦ ±ÇÇÏ°í ÀÖ½À´Ï´Ù.)

FR-o /etc/sendmail.cR

Scheck_rcpt
# anything terminating locally is ok
R< $+ @ $=w >           $@ OK
R< $+ @ $=R >           $@ OK

# anything originating locally is ok
R$*                     $: $(dequote "" $&{client_name} $)
R$=w                    $@ OK
R$=R                    $@ OK
R$@                     $@ OK

# anything else is bogus
R$*                     $#error $: "550 Relaying Denied"

±×¸®°í /etc/sendmail.cRÀÇ ¼³Á¤Àº ¾Æ·¡¿Í À¯»çÇÏ°Ô ÇÏ½Ã¸é µË´Ï´Ù.

/ $ cat /etc/sendmail.cR
155.230.28.117
155.230.28.118

sendmail 8.9.x

sendmail 8.9.x¿¡¼­´Â ±âº»ÀûÀ¸·Î third party relay¸¦ ±ÝÁöÇÏ°í ÀÖ½À´Ï´Ù. ¸¸ÀÏ third party relay¸¦ Çã¿ëÇÏ·Á¸é promiscuous_relay FEATURE¸¦ mcÆÄÀÏ¿¡ Ãß°¡ÇÏ°í sendmail.cf¸¦ »ý¼ºÇÏ¸é µË´Ï´Ù. (ÇÏÁö¸¸ ÀÌ·¸°Ô ÇÒ »ç¶÷ÀÌ ÀÖ³ª¿ä? ^^)

µû¶ó¼­ sendmail 8.9.x¿¡¼­´Â sendmail.cf¿¡ Ưº°ÇÑ ¼öÁ¤¾øÀÌ relay¿¡ °üÇÑ ÆÄÀϸ¸ ¼öÁ¤ÇÏ¸é µË´Ï´Ù. ¾Æ·¡¿¡¼­´Â »ç¿ëÇÏ°í ÀÖ´Â µµ¸ÞÀÎ À̸§ÀÌ company.co.kr ÀÌ°í, È£½ºÆ® À̸§ÀÌ myhost, ip address°¡ 203.123.45.67 ÀÎ °æ¿ì¶ó°í °¡Á¤ÇÕ´Ï´Ù.

/etc/mail/access : ´©°¡ ÀÌ ¸ÞÀÏ ¼­¹ö¸¦ ¸±·¹ÀÌ ¼­¹ö·Î ÁöÁ¤Çؼ­ »ç¿ëÇÒ ¼ö Àִ°¡, ¾î¶² ÁÖ¼Ò¿¡¼­ ¿À´Â ¸ÞÀÏÀº °ÅÀýÇÒ °ÍÀΰ¡¸¦ ¼³Á¤ÇÏ´Â ÆÄÀÏÀÔ´Ï´Ù.

mail $ cat access
203.123.45      RELAY
209.1.2.3       RELAY
cyberpromo.com  REJECT

ÀÌ·¸°Ô ¼³Á¤ÇÑ °æ¿ì myhost¿Í °°Àº ¼­ºê³Ý¿¡ ÀÖ´Â ÄÄÇ»Å͵é¿Í 209.1.2.3À» »ç¿ëÇÏ´Â ÄÄÇ»ÅÍ¿¡¼­¸¸ myhost.company.co.krÀ» SMTP ¼­¹ö·Î ÁöÁ¤Çؼ­ ¸ÞÀÏÀ» º¸³¾ ¼ö ÀÖ½À´Ï´Ù. ±×¸®°í cyberpromo.com°ú cyperpromo.com µµ¸ÞÀο¡ ¼ÓÇÏ´Â ¸ðµç È£½ºÆ®¿¡¼­ ¿À´Â ¸ÞÀÏÀº °ÅÀýÇÕ´Ï´Ù. ÀÏ´Ü ÀÌ È­ÀÏÀ» ¸¸µå¼Ì´Ù¸é ÀÌÁ¦´Â DB È­ÀÏÀ» ¸¸µå¼Å¾ß ÇÕ´Ï´Ù.

/ $ cd /etc/mail
mail $ makemap hash access < access

±×¸®°í /etc/mail/access È­ÀÏÀ» ¼öÁ¤À» ÇÒ ¶§¸¶´Ù ¹Ýµå½Ã ÀÌ ÀÛ¾÷À» ÇØ ÁÖ¼Å¾ß ÇÕ´Ï´Ù. ÇÏÁö¸¸ ÀÌ ÀÛ¾÷À» ÈÄ¿¡ sendmailÀ» Á×ÀÌ°í ´Ù½Ã ¶ç¿ï ÇÊ¿ä´Â ¾ø½À´Ï´Ù.

±×¸®°í accessÆÄÀÏÀ» »ç¿ëÇÒ °æ¿ì¿¡´Â sendmail.cf¸¦ »ý¼ºÇÒ ¶§ mcÆÄÀÏ¿¡ FEATURE(access_db)¸¦ Ãß°¡ÇØ¾ß ÇÕ´Ï´Ù.

¶ÇÇÑ makemapÀÇ ¹öÀüÀÌ ³·Àº°æ¿ì ÀÛµ¿À» ÇÏÁö ¾Ê´Â °æ¿ì°¡ ÀÖ½À´Ï´Ù. À̶§´Â sendmail ÆÐÅ°Áö¿Í ÇÔ²² µþ·Á³ª¿À´Â makemapÀ» ÄÄÆÄÀÏ ÇÑ ÈÄ ½ÃµµÇØ º¸½Ã±â ¹Ù¶ø´Ï´Ù. makemapµµ sendmail°ú ¸¶Âù°¡Áö·Î -DNEWDB¸¦ ¼±ÅÃÇØ ÁÖ¼Å¾ß ÇÕ´Ï´Ù.

/etc/mail/relay-domains : À§ÀÇ /etc/mail/access¿¡¼­ ÁöÁ¤ÇÑ °÷ ¿Ü¿¡¼­ ¸ÞÀÏ ¼­¹ö·Î ÁöÁ¤ÇÏ´Â °æ¿ì¿¡µµ, relay-domains ¿¡ µî·ÏÇÑ µµ¸ÞÀÎÀÇ È£½ºÆ®¿¡ ´ëÇؼ­´Â Çã¿ëÇÕ´Ï´Ù. relay-domains¿Í accessÆÄÀÏÀÇ Å« Â÷ÀÌÁ¡ÀÇ Çϳª´Â accessÆÄÀÏÀÇ °æ¿ì ¼öÁ¤ÈÄ sendmailÀ» ´Ù½Ã ½ÇÇàÇÒ ÇÊ¿ä°¡ ¾øÁö¸¸ relay-domainsÆÄÀÏÀº ¼öÁ¤ÈÄ sendmailÀ» ´Ù½Ã ½ÇÇàÇØ¾ß ¹Ù²ï ³»¿ëÀ» ÀνÄÇÕ´Ï´Ù. ÆíÇÑ ÆÄÀÏÀ» Çϳª Á¤Çؼ­ »ç¿ëÇÏ½Ã¸é µË´Ï´Ù. ÀúÀÇ °æ¿ì accessÆÄÀÏÀº RELAY-FROM¿¡ ÇØ´çÇϴ ȣ½ºÆ®¿¡ relay-domains´Â RELAY-TO¿¡ ÇØ´çÇϴ ȣ½ºÆ®¸¦ ¼³Á¤ÇÕ´Ï´Ù.

mail $ cat relay-domains
company.co.kr

ÀÌ °æ¿ì company.co.kr µµ¸ÞÀο¡¼­ ¿À´Â ¸ÞÀÏÀº ¸ðµÎ Á߰踦 Çã¿ëÇÕ´Ï´Ù. ¸¸ÀÏ ÀÌ ¸ÞÀÏ ¼­¹ö·Î¸¸ ¿À´Â ¸ÞÀÏÀ» ¹Þ°í ½Í´Ù¸é(´ëºÎºÐÀÇ °æ¿ì°¡ ¿©±â¿¡ ¼ÓÇÕ´Ï´Ù) access È­ÀÏ°ú relay-domains È­ÀÏÀ» 0¹ÙÀÌƮ¥¸® È­ÀÏ·Î ¸¸µé¸é µË´Ï´Ù.

ÀÌ·¸°Ô ¼³Á¤ÇÑ ÈÄ SMTP¼­¹ö°¡ third party relay¸¦ Çã¿ëÇÏ´ÂÁö Å×½ºÆ®ÇØ º¸½Ã±â ¹Ù¶ø´Ï´Ù.


´ÙÀ½ ÀÌÀü Â÷·Ê