2004/09/29 (Wed) ¥á¡¼¥ë¥µ¡¼¥Ð¡¼ ¤Ç¥¦¥£¥ë¥¹Âкö
ËèÆüËèÆüSpam¥á¡¼¥ë¤È¥¦¥£¥ë¥¹¥á¡¼¥ë¤Î¿ô¤¬¤¹¤´¤¤¡£¤Ê¤ó¤È¤«¤Ê¤é¤Ê¤¤¤â¤Î¤«¡£
¤È¹Í¤¨¤¿·ë²Ì¤¬¤³¤ì¡£
qmail + F-Prot + Spam Assassin + Qmail-Scanner
¤Ä¤Þ¤ê¡¢qmail¤Ç½èÍýÃæ¤Î¥¥å¡¼¤òqmail scanner¤Ç
¡¦LinuxÍѤÎFree¥¦¥£¥ë¥¹¥Á¥§¥Ã¥¯¥½¥Õ¥È¤Ç¥Á¥§¥Ã¥¯
¡¦SpamAssasign¤Ë¤ÆSPAM¥á¡¼¥ë¤Î½èÍý
¤ò¹Ô¤¦¡£
¤½¤Î°Ù¤Ë1Âæ¥á¡¼¥ë¥µ¡¼¥Ð¤ò¹½ÃÛ¤·¤¿¡£¤È¤¤¤Ã¤Æ¤âVMware¤ò»ÈÍѤ·¤Æ¤¤¤ë¤Î¤Ç¡¢Â¾¤Î¥µ¡¼¥Ð¤ò¥³¥Ô¤Ã¤Æ¤¤Æµ¯Æ°¤¹¤ë¤À¤±¡£³Ú¥Á¥ó¡£
¥¢¥ó¥Á¥¦¥£¥ë¥¹¥á¡¼¥ëGW¥µ¡¼¥Ð¤òºî¤ë¼ê½ç¤Î³µÍפϰʲ¼¤ÎÄ̤ꡣ
¡F-Prot¤òƳÆþ
¢SpamAssasin¤òƳÆþ
£qmail-scanner¤òƳÆþ
¤qmail¤ÎÀßÄêÊѹ¹
¥¥Á¥§¥Ã¥¯
¡F-Prot¤òƳÆþ
F-Prot¤ÎPRM¥Õ¥¡¥¤¥ë¥À¥¦¥ó¥í¡¼¥É¥µ¥¤¥È¤è¤êRPM¥Õ¥¡¥¤¥ë¤Î¥À¥¦¥ó¥í¡¼¥É¤·¤Æ¤¯¤ë¡£¡Ê¥Û¡¼¥à¥æ¡¼¥¶ÈǤϥե꡼)
¤½¤·¤Æ¥¤¥ó¥¹¥È¡¼¥ë
VIRUS SIGNATURE FILES
SIGN.DEF created 23 September 2004
SIGN2.DEF created 23 September 2004
MACRO.DEF created 20 September 2004
#
¤Þ¤º¤Ï¥Æ¥¹¥È¤ò¤·¤Æ¤ß¤ë¡£
virustest¥Ç¥£¥ì¥¯¥È¥ê¤òºîÀ®¤·¤Æ¡¢¤½¤³¤Ë¥Æ¥¹¥È¥¦¥£¥ë¥¹¤ò³ÊǼ¡£
¥Æ¥¹¥È¥¦¥£¥ë¥¹¤Ï°Ê²¼¤«¤é¥À¥¦¥ó¥í¡¼¥É¤¹¤ë¡£
http://www.eicar.org/download/eicar.com
http://www.eicar.org/download/eicar.com.txt
http://www.eicar.org/download/eicar_com.zip
http://www.eicar.org/download/eicarcom2.zip
# ./f-prot virustest/
Virus scanning report - 26 September 2004 @ 21:40
F-PROT ANTIVIRUS
Program version: 4.4.6
Engine version: 3.14.13
VIRUS SIGNATURE FILES
SIGN.DEF created 23 September 2004
SIGN2.DEF created 23 September 2004
MACRO.DEF created 20 September 2004
Search: virustest/
Action: Report only
Files: "Dumb" scan of all files
Switches: -ARCHIVE -PACKED -SERVER
/usr/local/f-prot/virustest/eicar.com Infection: EICAR_Test_File
/usr/local/f-prot/virustest/eicar.com.txt Infection: EICAR_Test_File
/usr/local/f-prot/virustest/eicar_com.zip->eicar.com Infection: EICAR_Test_File
/usr/local/f-prot/virustest/eicarcom2.zip->eicar_com.zip->eicar.com Infection: EICAR_Test_File
Results of virus scanning:
Files: 4
MBRs: 0
Boot sectors: 0
Objects scanned: 7
Infected: 4
Suspicious: 0
Disinfected: 0
Deleted: 0
Renamed: 0
Time: 0:00
#
¤Á¤ã¤ó¤È¸¡ÃΤǤ¤¿¤è¤¦¤À¡£
Äê´üŪ¤Ë¥Ñ¥¿¡¼¥ó¥Õ¥¡¥¤¥ë¤ò¥À¥¦¥ó¥í¡¼¥É¤¹¤ë¤è¤¦¤Ëcron¤ËÅÐÏ¿¤¹¤ë¡£
¢SpamAssasin¤òƳÆþ
ɬÍפʤâ¤Î
¡ (Perl)Net::DNS
¢ (Perl)Time::HiRes
£ razor-agents
¤ (Perl)Mail::SpamAssassin
¡¢¤¤È¤â¤ËCPAN¤Ë¤¢¤ë¤Î¤Ç¡¢°Ê²¼¤Ë¤Æ¥¤¥ó¥¹¥È¡¼¥ë¡£
# perl -MCPAN -e shell
cpan> o conf prerequisites_policy ask
cpan> install Mail::SpamAssassin
cpan> quit
¤¿¤À¤·¡¢Mail::SpamAssassin¥¤¥ó¥¹¥È¡¼¥ëÁ°¤Ë£razor-agents¤òƳÆþ¤·¤Æ¤ª¤¯¡£
razor-agetns¤Ïhttp://razor.sourceforge.net¤è¤êÆþ¼ê²Äǽ¡£(razor-agents-2.61.tar.gz¤ò¥À¥¦¥ó¥í¡¼¥É)
# perl Makefile.PL
# make
# make test
# make install
¤Ç¥¤¥ó¥¹¥È¡¼¥ë¤·¡¢¤½¤Î¸å¥»¥Ã¥È¥¢¥Ã¥×¤ò¹Ô¤¦¡£
# which razor-client
/usr/bin/razor-client
# razor-client
Creating symlink razor-client <== /usr/bin/razor-check
Creating symlink razor-client <== /usr/bin/razor-report
Creating symlink razor-client <== /usr/bin/razor-revoke
Creating symlink razor-client <== /usr/bin/razor-admin
#
# razor-admin -d -create -home=/etc/razor
¡Ä
# touch /etc/razor/razor-agent.log
# chmod 666 /etc/razor/razor-agent.log (ËÜÅö¤Ï666¤Ï¤è¤í¤·¤¯¤Ê¤¤¡Ä)
¼¡¤Ëspamd(SpamAssassin¥Ç¡¼¥â¥ó)Íѥ桼¥¶/¥°¥ë¡¼¥×¤ÎÅÐÏ¿
spamd¤ò¥¹¥¿¡¼¥È¥¢¥Ã¥×¤ËÅÐÏ¿
/etc/sysconfig/spamassassin¤òºîÀ®
/etc/mail/spamassasin/local.cf¤òÊÔ½¸¤·¥ë¡¼¥ë¤òÀßÄê
(»²¹Í¤Ë¤µ¤»¤Æ¤â¤é¤Ã¤¿¥µ¥¤¥È)
¡¦SecureMail - pukiwiki¼«Â𥵡¼¥Ð¡¼¹½ÃÛ¥á¥â
¡¦SpamAssassin Milter¤ÎƳÆþ [FreeBSD](fkimura.com)
# 2¥Ð¥¤¥È¥³¡¼¥É¤ÎȽÄê¤ò¤æ¤ë¤ä¤«¤Ë¤¹¤ë¤¿¤á¤Ë ¥Ý¥¤¥ó¥È¤ò0¤ËÊѹ¹
score HEADER_8BITS 0
score HTML_COMMENT_8BITS 0
score SUBJ_FULL_OF_8BITS 0
score UPPERCASE_25_50 0
score UPPERCASE_50_75 0
score UPPERCASE_75_100 0
# ´¶ÅÙ¤ÎÀßÄꡣɸ½à¤Ï£µ¡£
# ¥Æ¥¹¥È¤ò½Å¤Í¤¿·ë²Ì£¹¤¬¥Ù¥¹¥È¤À¤È»×¤¦¡£
required_hits 9
# SpamAssassin¤¬spam¥á¡¼¥ë¤Î¥¿¥¤¥È¥ë¤ò½ñ¤´¹¤¨¤é¤ì¤ë¤è¤¦¤Ë
# ¤¿¤À¤·report_safe ¤¬0¤Î¾ì¹ç¤Ë¤Î¤ß͸ú
rewrite_subject 1
#rewrite_header Subject *****SPAM*****
# spam¤ÈȽÄꤵ¤ì¤¿»þ¥¿¥¤¥È¥ë¤ËÉÕ¤±¤é¤ì¤ë¥¿¥°¤ÎÄêµÁ
subject_tag [SPAM]
# spamʬÀÏ·ë²Ì¤ò¥á¡¼¥ëËÜʸ¤Ç¤Ê¤¯¥Ø¥Ã¥À¤ËÉÕ¤±¤ë
report_safe 1
# SPAM¤Î»þ¤À¤±¥Ø¥Ã¥À¡¼¤ò½Ð¤¹¤è¤¦¤Ë¤¹¤ë¤Ë¤Ï 0¡£¾ï¤Ë½Ð¤¹¤Ê¤é 1¡£
always_add_headers 0
# SPAMȽÄꤵ¤ì¤¿¾ì¹ç¤Ë¤½¤ÎȽÄêÍýͳ¤ò½Ð¤¹¾ì¹ç¤Ë¤Ï 0¡£(¥Ç¥Õ¥©¥ë¥È)
# ½Ð¤·¤¿¤¯¤Ê¤¤¾ì¹ç¤Ë¤Ï 1¤Ë¤·¤Æ¤ª¤¯¡£
always_add_report 0
# Spamassassin¤ÏÁ´¤Æ¤Î¥á¡¼¥ë¤òÂоݤ˼¡¤Î¤è¤¦¤Ê¥æ¡¼¥Æ¥£¥ê¥Æ¥£¤ò»È¤¦¤Î¤¬¥Ç¥Õ¥©¥ë¥È¤Ë¤Ê¤Ã¤Æ¤ë¤¬¡¢
# ¡Ê¾Ü¤·¤¯¤Ï http://www.spamassassin.org/dist/INSTALL ¤Ç)
# CPUÉé²Ù¤Ë¤Ê¤ë¤â¤Î¤òÈò¤±¤ë¤¿¤á¤ËÅöʬ¥¤¥ó¥¹¥È¡¼¥ë¤»¤º¤Ë»ÈÍÑÉԲĤˤ·¤Æ¤ª¤¯¡£
use_dcc 0
use_pyzor 0
# razor2¥Á¥§¥Ã¥¯¤ò»ÈÍÑ
use_razor2 1
loadplugin Mail::SpamAssassin::Plugin::SPF
loadplugin Mail::SpamAssassin::Plugin::Razor2
razor_config /etc/razor/razor-agent.conf
# SpamAssassin¤ÎRBL¥Á¥§¥Ã¥¯ :
# ´û¤Ëqmail¤Îrblsmpd¤ÇRBL¥Õ¥£¥ë¥¿¤òÍѤ¤¤¿¤¬¡¢SpamAssassin¤ÎRBL¥Á¥§¥Ã¥¯¤ÇÊ̤ÎRBL¾ðÊó¤Î»ÈÍѤòÁ¦¤á¤ë¡£
# ¤â¤Ã¤ÈÀµ³Î¤ËSPAM¥¿¥°¤òźÉÕ¤¹¤ë¤¿¤á¤À¡£
skip_rbl_checks 0
# £³ÉÃ°ÊÆâ¤Ë¥ì¥¹¥Ý¥ó¥¹¤¬¤Ê¤¤¾ì¹ç¤Ï¥Á¥§¥Ã¥¯¤ò¥¹¥¥Ã¥×¤¹¤ë¡£
rbl_timeout 3
# ¤³¤³¤Ç¡¢¤¤¤¯¤Ä¤«¥Ç¥Õ¥©¥ë¥È¤ÎÅÀ¿ô¤òÊѹ¹¤·¤Æ¤ª¤³¤¦¡£
#
# ¥Ç¥Õ¥©¥ë¥È¤Ç»ÈÍÑÉԲĤˤʤäƤëbl.spamcop.net¤ÎRBL¤òÍѤ¤¤Æ¥Ò¥Ã¥È¤¹¤ì¤Ð3ÅÀ¤Ä¤±¤ë¤³¤È¤Ë¤¹¤ë¡£
# ¾Ü¤·¤¤¾ðÊó¤Ï http://spamcop.net/fom-serve/cache/290.html ¤Ç¡£
score RCVD_IN_BL_SPAMCOP_NET 3
# ÆÃÄê¤Î¥Í¥Ã¥È¥ï¡¼¥¯¥¢¥É¥ì¥¹¤ä¥á¡¼¥ë¥µ¡¼¥Ð¡¼¤Î¤¢¤ë¥Í¥Ã¥È¥ï¡¼¥¯¤òÀ©¸æ¤Ç¤¤ë¡£
# ¤Ä¤Þ¤ê¡¢¿®Íê¤Ç¤¤ë¥Í¥Ã¥È¤Î¥á¡¼¥ë¥µ¡¼¥Ð¡¼¤ËRBL¥Á¥§¥Ã¥¯¤ò¤«¤±¤ëɬÍפϤʤ¤¤«¤é¤À¡£
# ²¼¤ÎÎã¤Ïc¥¯¥é¥¹¤Î123.123.123.0/24¤òSpamassassin¤ÎRBL¥Á¥§¥Ã¥¯¤«¤é½ü³°¤·¤Æ¤¤¤ë¡£
trusted_networks 192.168.30. 192.168.10. 127.
use_bayes 1
bayes_auto_learn 1
bayes_path /home/spamd/.spamassassin/bayes
¤Þ¤¿¡¢spamd¤òµ¯Æ°¤·¡¢³Ø½¬¤ò¹Ô¤¦¡£
(»²¹Í¤Ë¤µ¤»¤Æ¤â¤é¤Ã¤¿¥µ¥¤¥È)
¡¦Easy setup & configuration of SpamAssassin with fetchmail -Tokyo Linux Entertainment Community-
# service spamd start
# cd /home/spamd
# mkdir spam
# cd spam
# wget http://www.flcl.org/~yoh/spam9xxxx.tar.gz
# tar zxf spam9xxxx.tar.gz
# sa-learn --spam *
£qmail-scanner¤òƳÆþ
qmail-queue¤ò¼Â¹Ô¤¹¤ëÁ°¤Ë¾¤Î¥×¥í¥°¥é¥à¤ËÅϤ¹¥Ñ¥Ã¥Á¤ò°Ê²¼¤«¤é¥À¥¦¥ó¥í¡¼¥É¤·¤Æ¥Ñ¥Ã¥Á¤òŬÍѤ¹¤ë¡£
http://www.qmail.org/qmailqueue-patch
qmail¤Î¹½ÃۤλÅÊý¤Ï¤³¤Á¤é¡£
http://prdownloads.sourceforge.net/qmail-scanner/¤è¤êqmail-scanner-1.23.gz¤ò¥À¥¦¥ó¥í¡¼¥É¤·¡¢¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¡£
¤Þ¤º¤ÏÀìÍѤΥ¢¥«¥¦¥ó¥È¤ò½àÈ÷¤¹¤ë¡£
maildrop¤ò¥À¥¦¥ó¥í¡¼¥É¤·¥¤¥ó¥¹¥È¡¼¥ë
http://www.flounder.net/~mrsam/maildrop/
¤½¤Î¸åconfigure¤ò¤«¤±¤Æ¥¤¥ó¥¹¥È¡¼¥ë¡£¤Á¤Ê¤ß¤Ëmaildrop¤Ïbzip¤È¤¤¤¦·Á¼°¤Ç°µ½Ì¤µ¤ì¤Æ¤¤¤ë¤¿¤á¡¢°Ê²¼¤Î¤è¤¦¤Ë¤·¤Æ²òÅह¤ë¡£
¤½¤Î¸åqmail-scanner¤Îconfigure¤ò¤«¤±¤Æ¥¤¥ó¥¹¥È¡¼¥ë
# LANG=ja_JP.EUC (ÆüËܸìÂбþ¤¹¤ë¤¿¤á)
# export LANG
# ./configure --install
¤³¤Î¤Þ¤Þ¤Ç¤Ï¤Þ¤Àư¤«¤Ê¤¤¡£(¾¯¤Ê¤¯¤È¤âRH9¤Ç¤Ï)
perl-suidperl¤ò¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¡£s¥Ó¥Ã¥È¤¬¤¿¤Ã¤Æ¤¤¤ëperl¥â¥¸¥å¡¼¥ë(/var/qmail/bin/qmail-scanner-queue.pl)¤ò¼Â¹Ô¤·¤è¤¦¤È¤¹¤ë¤Èqmail¤Ë¤Æ¡¢qq¥¨¥é¡¼¤¬È¯À¸¤·¤Æ¤·¤Þ¤¦¤¿¤ásuidperl¤¬É¬Íפˤʤ롣
suidperl¤Ë¤Ä¤¤¤Æ¤ÏRH¤«¤é¥À¥¦¥ó¥í¡¼¥É¤Ç¤¤ë¡£
¼¡¤Ë/var/qmail/bin/qmail-scanner-queue.pl¤òÊÔ½¸
# Address carbon-copied on any virus reports
my $QUARANTINE_CC='root@www.hne.jp'; ¢«·Ù¹ð¥á¡¼¥ë¤ÎCC
#Array of local domains that are checked against for
#deciding whether or not to send recipient alerts to
my @local_domains_array=('kamata-net.com', , 'cannon-ball.net', 'avons.jp', 'hne.jp'); ¢«¥¦¥£¥ë¥¹¥Á¥§¥Ã¥¯¤ò¤¹¤ë¥É¥á¥¤¥ó¤òµ½Ò
¤Þ¤¿¥Õ¥¡¥¤¥ë¥Ñ¡¼¥ß¥Ã¥·¥ç¥ó¤Ï°Ê²¼¤Î¤è¤¦¤Ë¤Ê¤Ã¤Æ¤¤¤ëɬÍפ¬¤¢¤ë¡£
¥¦¥£¥ë¥¹¸¡ºº¤¹¤ë¥¿¥¤¥×¤Î»ØÄê¥Õ¥¡¥¤¥ë(/var/spool/qmailscan/quarantine-attachments.txt)¤òÊÔ½¸¤¹¤ë¡£
(»²¹Í¤Ë¤µ¤»¤Æ¤â¤é¤Ã¤¿¥µ¥¤¥È)
¡¦qmail-scanner
¡¦9.3 ¥¦¥£¥ë¥¹¥¹¥¥ã¥ó¤ÎÀßÄê
ÀßÄê¤ò͸ú¤Ë¤¹¤ë
¥¦¥£¥ë¥¹¤Ï/var/spool/qmailscan/quarantine/new/ÇÛ²¼¤Ë³ÊǼ¤µ¤ì¤ë°Ù°Ê²¼¤Î¥³¥Þ¥ó¥É¤òcron¤Ë»Å¹þ¤ßÄê´üŪ¤Ëºï½ü¤·¤Ê¤±¤ì¤Ð¤Ê¤é¤Ê¤¤¡£
¤qmail¤ÎÀßÄêÊѹ¹
tcpserver¤Ë´Ä¶ÊÑ¿ô¤òÄɲ乤롣
smtpÍÑtcpserverÀßÄê¥Õ¥¡¥¤¥ë¤Ï°Ê²¼¤ÎÄ̤ê
¥í¡¼¥«¥ë¥Í¥Ã¥È¥ï¡¼¥¯¤È¥ë¡¼¥×¥Ð¥Ã¥¯¥¢¥É¥ì¥¹¤«¤é¤ÎSMTP¥¢¥¯¥»¥¹¤Ç¤Ï¥¦¥£¥ë¥¹¥Á¥§¥Ã¥¯¤ò¤·¤Ê¤¤¤è¤¦¤Ë¤·¤Æ¤¤¤ë¡£
tcpserver¤ÎDB¹¹¿·¤â˺¤ì¤º¤Ë
(»²¹Í¤Ë¤µ¤»¤Æ¤â¤é¤Ã¤¿¥µ¥¤¥È)
¡¦Qmail-Scanner Frequently Asked Questions
¤Þ¤¿¡¢¤¦¤Á¤Î´Ä¶¤Ç¤Ï¥¦¥£¥ë¥¹¥Á¥§¥Ã¥¯¸åwww¥µ¡¼¥Ð¤ËžÁ÷¤¹¤ë¤¿¤á¡¢/var/qmail/alias/.qmail-default¥Õ¥¡¥¤¥ë¤Ë°Ê²¼¤Î¤è¤¦¤Ëµ½Ò¤¹¤ë¡£
¤Þ¤¿¡¢/var/qmail/control/smtproutes¥Õ¥¡¥¤¥ë¤Ë¤Ï¼õ¿®¤¹¤ëÁ´¤Æ¤Î¥É¥á¥¤¥ó¤Ë¤Ä¤¤¤ÆÀßÄꤷ¤Ê¤¤¤È¡¢¥ë¡¼¥×¤òµ¯¤³¤·¤Æ¤·¤Þ¤¦¡£(¤Ê¤¼.qmail-default¤ò¸«¤Æwww.hne.jp¤ËžÁ÷¤·¤Ê¤¤¤Î¤À¤í¤¦¡Ä)
hne.jp:[192.168.aa.bb]
.hne.jp:[192.168.aa.bb]
.kamata-net.com:[192.168.aa.bb]
kamata-net.com:[192.168.aa.bb]
¡Ä
¥¥Á¥§¥Ã¥¯
qmail¤Èspamd¤ÎºÆµ¯Æ°¤ò¹Ô¤Ã¤¿¸å¡¢°Ê²¼¤Î¥³¥Þ¥ó¥É¤Ë¤Æ¥¦¥£¥ë¥¹¤ò¸¡ÃΤǤ¤ë¤«³Îǧ¤¹¤ë¡£
# cd /usr/local/src/qmail-scanner-1.23/contrib(¥½¡¼¥¹¥Õ¥¡¥¤¥ëÃÖ¤¾ì)
# ./test_installation.sh -doit
¤Þ¤¿¡¢SPAM¥á¡¼¥ë¤Ë¤Ï°Ê²¼¤Î¥Ø¥Ã¥À¤¬¤Ä¤¤¤Æ¤¤¤ë¤³¤È¤ò³Îǧ
Received: from 61.159.253.113
by mail (envelope-from
with qmail-scanner-1.23 (f-prot: 4.4.6/3.14.13. spamassassin: 3.0.0. Clear:RC:0(61.159.253.113):SA:1(19.4/9.0):. Processed in 2.305798 secs);
28 Sep 2004 16:22:09 -0000
X-Spam-Status: Yes, hits=19.4 required=9.0
X-Spam-Level: +++++++++++++++++++
¤³¤ì¤Ë¤è¤êBecky!¤Ç¤ÏX-Spam-Status: Yes¤ò¥´¥ßÈ¢¤Ë¥Õ¥£¥ë¥¿¤¹¤ë¤³¤È¤¬Íưפˤʤ롣
¤¤¤Ä¤â»×¤Ã¤Æ¤ë¤ó¤Ç¤¹¤¬¡¢¼«Âð¤Ç¤µ¤ÐΩ¤Æ¤Æ¤ë¤Ç¤¹¤«¡©
Posted by: ¤É¤¶ : September 29, 2004 04:45 PM
¤â¤¦£µÇ¯°Ê¾å¼«Â𻪤Ǥ¹¤è¡Á¡£¤¨¤¨¡¢Î©Çɤʥª¥¿¥¯¤Ç¤¹¡ª£÷
¤ª¡¼¡¼¡¼¡¼¡¼¡¼¡¢¤ª¤¿¤¯¤À¡Ê¾Ð¡Ë
Posted by: ¤É¤¶ : September 29, 2004 07:08 PM