Third Party Relay¶õ °£´ÜÇÏ°Ô ¸»Çؼ SMTP¼¹öÀÇ »ç¿ëÀÚ°¡ ¾Æ´Ñ »ç¶÷(º¸Åë ½ºÆÔÀ» »Ñ¸®±â À§ÇÑ ¾ÇÀÇ·Î)ÀÌ SMTP¼¹ö¸¦ ÀÌ¿ëÇÏ´Â °ÍÀÔ´Ï´Ù. µû¶ó¼ A ÄÄÇ»ÅÍÀÇ SMTP¼¹ö¸¦ C ÄÄÇ»ÅÍ¿¡ ÀÖ´Â »ç¿ëÀÚ°¡ B ÄÄÇ»ÅÍ·Î ¸ÞÀÏÀ» º¸³»±â À§ÇØ ÀÌ¿ëÇϴ°æ¿ì¸¦ ¸»ÇÕ´Ï´Ù. Á»´õ ÀÚ¼¼ÇÑ ¼³¸íÀº What is Third-Party Mail Relay?¸¦ Âü°íÇϽñ⠹ٶø´Ï´Ù.
¾ÆÁ÷±îÁö ¸¹Àº ¼¹öµéÀÌ Third Party Relay¸¦ Çã¿ëÇÏ°í ÀÖÀ¸¸ç, À̶§¹®¿¡ ÀÚ½ÅÀÌ °ü¸®Çϴ ȣ½ºÆ®°¡ ½ºÆÔ »çÀÌÆ®·Î ÀνĵǴ°͵µ ¸ð¸£°í ÀÖ´Â °æ¿ì°¡ Çã´ÙÇÕ´Ï´Ù. ¿ì¼± ÀÚ½ÅÀÌ °ü¸®Çϴ ȣ½ºÆ®ÀÇ SMTP¼¹ö°¡ Third Party Relay¸¦ Çã¿ëÇÏ´ÂÁö¸¦ üũÇÏ·Á¸é Is My Mailer Vulnerable?¿¡¼ ÇÏ½Ç ¼ö ÀÖ½À´Ï´Ù. ²À Çغ¸½Ã±â ¹Ù¶ø´Ï´Ù.
Third Party Relay¸¦ ¸·À¸·Á¸é Àû¾îµµ sendmail 8.8.x °¡ µÇ¾î¾ß ÇÕ´Ï´Ù. µû¶ó¼ ÃÖ½ÅÀÇ sendmail·Î ¾÷±×·¹À̵带 ÇϽñ⠹ٶø´Ï´Ù.
sendmail.cf¿¡ ¾Æ·¡¿Í °°Àº Rule setÀ» ³Ö°í sendmail.cRÆÄÀÏ¿¡ relay¸¦ Çã¿ëÇϴ ȣ½ºÆ®ÀÇ FQDNÀ̳ª IP address¸¦ ÀÔ·ÂÇÏ¸é µË´Ï´Ù. ( http://www.sendmail.org/antispam.html¿¡¼´Â IP address¸¦ ±ÇÇÏ°í ÀÖ½À´Ï´Ù.)
FR-o /etc/sendmail.cR Scheck_rcpt # anything terminating locally is ok R< $+ @ $=w > $@ OK R< $+ @ $=R > $@ OK # anything originating locally is ok R$* $: $(dequote "" $&{client_name} $) R$=w $@ OK R$=R $@ OK R$@ $@ OK # anything else is bogus R$* $#error $: "550 Relaying Denied"
±×¸®°í /etc/sendmail.cRÀÇ ¼³Á¤Àº ¾Æ·¡¿Í À¯»çÇÏ°Ô ÇÏ½Ã¸é µË´Ï´Ù.
/ $ cat /etc/sendmail.cR 155.230.28.117 155.230.28.118
sendmail 8.9.x¿¡¼´Â ±âº»ÀûÀ¸·Î third party relay¸¦ ±ÝÁöÇÏ°í ÀÖ½À´Ï´Ù. ¸¸ÀÏ third party relay¸¦ Çã¿ëÇÏ·Á¸é promiscuous_relay FEATURE¸¦ mcÆÄÀÏ¿¡ Ãß°¡ÇÏ°í sendmail.cf¸¦ »ý¼ºÇÏ¸é µË´Ï´Ù. (ÇÏÁö¸¸ ÀÌ·¸°Ô ÇÒ »ç¶÷ÀÌ ÀÖ³ª¿ä? ^^)
µû¶ó¼ sendmail 8.9.x¿¡¼´Â sendmail.cf¿¡ Ưº°ÇÑ ¼öÁ¤¾øÀÌ relay¿¡ °üÇÑ ÆÄÀϸ¸ ¼öÁ¤ÇÏ¸é µË´Ï´Ù. ¾Æ·¡¿¡¼´Â »ç¿ëÇÏ°í ÀÖ´Â µµ¸ÞÀÎ À̸§ÀÌ company.co.kr ÀÌ°í, È£½ºÆ® À̸§ÀÌ myhost, ip address°¡ 203.123.45.67 ÀÎ °æ¿ì¶ó°í °¡Á¤ÇÕ´Ï´Ù.
/etc/mail/access : ´©°¡ ÀÌ ¸ÞÀÏ ¼¹ö¸¦ ¸±·¹ÀÌ ¼¹ö·Î ÁöÁ¤Çؼ »ç¿ëÇÒ ¼ö Àִ°¡, ¾î¶² ÁÖ¼Ò¿¡¼ ¿À´Â ¸ÞÀÏÀº °ÅÀýÇÒ °ÍÀΰ¡¸¦ ¼³Á¤ÇÏ´Â ÆÄÀÏÀÔ´Ï´Ù.
mail $ cat access 203.123.45 RELAY 209.1.2.3 RELAY cyberpromo.com REJECT
ÀÌ·¸°Ô ¼³Á¤ÇÑ °æ¿ì myhost¿Í °°Àº ¼ºê³Ý¿¡ ÀÖ´Â ÄÄÇ»Å͵é¿Í 209.1.2.3À» »ç¿ëÇÏ´Â ÄÄÇ»ÅÍ¿¡¼¸¸ myhost.company.co.krÀ» SMTP ¼¹ö·Î ÁöÁ¤Çؼ ¸ÞÀÏÀ» º¸³¾ ¼ö ÀÖ½À´Ï´Ù. ±×¸®°í cyberpromo.com°ú cyperpromo.com µµ¸ÞÀο¡ ¼ÓÇÏ´Â ¸ðµç È£½ºÆ®¿¡¼ ¿À´Â ¸ÞÀÏÀº °ÅÀýÇÕ´Ï´Ù. ÀÏ´Ü ÀÌ ÈÀÏÀ» ¸¸µå¼Ì´Ù¸é ÀÌÁ¦´Â DB ÈÀÏÀ» ¸¸µå¼Å¾ß ÇÕ´Ï´Ù.
/ $ cd /etc/mail mail $ makemap hash access < access
±×¸®°í /etc/mail/access ÈÀÏÀ» ¼öÁ¤À» ÇÒ ¶§¸¶´Ù ¹Ýµå½Ã ÀÌ ÀÛ¾÷À» ÇØ ÁÖ¼Å¾ß ÇÕ´Ï´Ù. ÇÏÁö¸¸ ÀÌ ÀÛ¾÷À» ÈÄ¿¡ sendmailÀ» Á×ÀÌ°í ´Ù½Ã ¶ç¿ï ÇÊ¿ä´Â ¾ø½À´Ï´Ù.
±×¸®°í accessÆÄÀÏÀ» »ç¿ëÇÒ °æ¿ì¿¡´Â sendmail.cf¸¦ »ý¼ºÇÒ ¶§ mcÆÄÀÏ¿¡ FEATURE(access_db)¸¦ Ãß°¡ÇØ¾ß ÇÕ´Ï´Ù.
¶ÇÇÑ makemapÀÇ ¹öÀüÀÌ ³·Àº°æ¿ì ÀÛµ¿À» ÇÏÁö ¾Ê´Â °æ¿ì°¡ ÀÖ½À´Ï´Ù. À̶§´Â sendmail ÆÐÅ°Áö¿Í ÇÔ²² µþ·Á³ª¿À´Â makemapÀ» ÄÄÆÄÀÏ ÇÑ ÈÄ ½ÃµµÇØ º¸½Ã±â ¹Ù¶ø´Ï´Ù. makemapµµ sendmail°ú ¸¶Âù°¡Áö·Î -DNEWDB¸¦ ¼±ÅÃÇØ ÁÖ¼Å¾ß ÇÕ´Ï´Ù.
/etc/mail/relay-domains : À§ÀÇ /etc/mail/access¿¡¼ ÁöÁ¤ÇÑ °÷ ¿Ü¿¡¼ ¸ÞÀÏ ¼¹ö·Î ÁöÁ¤ÇÏ´Â °æ¿ì¿¡µµ, relay-domains ¿¡ µî·ÏÇÑ µµ¸ÞÀÎÀÇ È£½ºÆ®¿¡ ´ëÇؼ´Â Çã¿ëÇÕ´Ï´Ù. relay-domains¿Í accessÆÄÀÏÀÇ Å« Â÷ÀÌÁ¡ÀÇ Çϳª´Â accessÆÄÀÏÀÇ °æ¿ì ¼öÁ¤ÈÄ sendmailÀ» ´Ù½Ã ½ÇÇàÇÒ ÇÊ¿ä°¡ ¾øÁö¸¸ relay-domainsÆÄÀÏÀº ¼öÁ¤ÈÄ sendmailÀ» ´Ù½Ã ½ÇÇàÇØ¾ß ¹Ù²ï ³»¿ëÀ» ÀνÄÇÕ´Ï´Ù. ÆíÇÑ ÆÄÀÏÀ» Çϳª Á¤Çؼ »ç¿ëÇÏ½Ã¸é µË´Ï´Ù. ÀúÀÇ °æ¿ì accessÆÄÀÏÀº RELAY-FROM¿¡ ÇØ´çÇϴ ȣ½ºÆ®¿¡ relay-domains´Â RELAY-TO¿¡ ÇØ´çÇϴ ȣ½ºÆ®¸¦ ¼³Á¤ÇÕ´Ï´Ù.
mail $ cat relay-domains company.co.kr
ÀÌ °æ¿ì company.co.kr µµ¸ÞÀο¡¼ ¿À´Â ¸ÞÀÏÀº ¸ðµÎ Á߰踦 Çã¿ëÇÕ´Ï´Ù. ¸¸ÀÏ ÀÌ ¸ÞÀÏ ¼¹ö·Î¸¸ ¿À´Â ¸ÞÀÏÀ» ¹Þ°í ½Í´Ù¸é(´ëºÎºÐÀÇ °æ¿ì°¡ ¿©±â¿¡ ¼ÓÇÕ´Ï´Ù) access ÈÀÏ°ú relay-domains ÈÀÏÀ» 0¹ÙÀÌƮ¥¸® ÈÀÏ·Î ¸¸µé¸é µË´Ï´Ù.
ÀÌ·¸°Ô ¼³Á¤ÇÑ ÈÄ SMTP¼¹ö°¡ third party relay¸¦ Çã¿ëÇÏ´ÂÁö Å×½ºÆ®ÇØ º¸½Ã±â ¹Ù¶ø´Ï´Ù.