{"id":4105,"date":"2015-07-13T02:48:53","date_gmt":"2015-07-13T05:48:53","guid":{"rendered":"https:\/\/www.viazap.com.br\/?p=4105"},"modified":"2015-07-13T02:49:23","modified_gmt":"2015-07-13T05:49:23","slug":"como-localizar-scripts-realizando-spam-em-servidores-com-whmcpanel","status":"publish","type":"post","link":"https:\/\/blog.clusterweb.com.br\/?p=4105","title":{"rendered":"Como localizar scripts realizando spam em servidores com WHM\/cPanel"},"content":{"rendered":"<p><span lang=\"pt\"><span lang=\"pt\"><span class=\"hps\">Neste guia<\/span> <span class=\"hps\">vamos<\/span><span class=\"hps\"> ensinar<\/span> <span class=\"hps\">como usar os<\/span> <span class=\"hps\">logs<\/span> <span class=\"hps\">do<\/span> <span class=\"hps\">Exim<\/span> <span class=\"hps\">em seu<\/span> <span class=\"hps\">VPS\/Cloud<\/span> <span class=\"hps\">ou<\/span> <span class=\"hps\">servidor dedicado<\/span> <span class=\"hps\">para encontrar<\/span> <span class=\"hps\">poss\u00edveis tentativas<\/span> <span class=\"hps\">de<\/span> <span class=\"hps\">spammers<\/span><span class=\"hps\">\u00a0usando<\/span><span class=\"hps\">\u00a0scripts para envio de e-mails n\u00e3o solicitados<\/span>, a fim de <span class=\"hps\">retransmitir<\/span> <span class=\"hps\">o spam de<\/span> <span class=\"hps\">seu servidor<\/span>.<\/span><\/span><\/p>\n<p><strong><span id=\"result_box\" class=\"short_text\" lang=\"pt\"><span class=\"hps\">Como \u00e9 que<\/span> <span class=\"hps\">o spam<\/span> <span class=\"hps\">s\u00e3o enviados<\/span> <span class=\"hps\">do meu servidor<\/span>?<\/span><\/strong><\/p>\n<p><span id=\"result_box\" class=\"short_text\" lang=\"pt\"><span id=\"result_box\" lang=\"pt\"><span class=\"hps\">Voc\u00ea pode ter<\/span> <span class=\"hps atn\">um recurso de &#8220;<\/span>informar a um amigo&#8221;, um <span class=\"hps\">sistema de alerta ou campo para recebimento de newsletter<\/span> <span class=\"hps\">em seu site.<\/span> <span class=\"hps\">Se<\/span> <span class=\"hps\">voc\u00ea n\u00e3o tiver cuidado<\/span>, por vezes, <span class=\"hps\">estes<\/span> <span class=\"hps\">podem ser explorados por<\/span> <span class=\"hps\">bots<\/span> <span class=\"hps\">para fins<\/span> <span class=\"hps\">de spam.<\/span> <span class=\"hps\">Isso pode<\/span> <span class=\"hps\">prejudicar a reputa\u00e7\u00e3o<\/span> <span class=\"hps\">de envio<\/span> <span class=\"hps\">de<\/span> <span class=\"hps\">seu endere\u00e7o de<\/span> <span class=\"hps\">IP<\/span>, <span class=\"hps\">e<\/span> <span class=\"hps\">levar a problemas<\/span>, como fazer <span class=\"hps\">voc\u00ea acabar<\/span> <span class=\"hps\">em uma blacklist<\/span>.<\/span><\/span><\/p>\n<p><strong><span id=\"result_box\" class=\"short_text\" lang=\"pt\"><span class=\"hps\">Como fa\u00e7o para<\/span> <span class=\"hps\">parar o spam<\/span> <span class=\"hps\">vindo do meu<\/span><\/span><span id=\"result_box\" class=\"short_text\" lang=\"pt\"> <\/span><\/strong><span id=\"result_box\" class=\"short_text\" lang=\"pt\"><span class=\"hps\"><strong>servidor?<\/strong><\/span><\/span><\/p>\n<p><span id=\"result_box\" lang=\"pt\"><span class=\"hps\">Exim,<\/span> <span class=\"hps\">ou<\/span> <span class=\"hps\">o<\/span> <span class=\"hps\">MTA<\/span> <span class=\"hps\">(Mail<\/span> <span class=\"hps\">Transfer Agent<\/span>) <span class=\"hps\">em seu<\/span> <span class=\"hps\">servidor lida com<\/span> <span class=\"hps\">as entregas<\/span> <span class=\"hps\">de e-mail<\/span>. <span class=\"hps\">Toda a atividade<\/span> <span class=\"hps\">de e-mail<\/span> <span class=\"hps\">\u00e9 registrada<\/span> <span class=\"hps\">incluindo e-mails<\/span><span class=\"hps\">enviados a partir de<\/span> <span class=\"hps\">scripts.<\/span> <span class=\"hps\">Ele faz isso registrando a pasta <\/span><span class=\"hps\">a partir de onde<\/span> <span class=\"hps\">o script<\/span> <span class=\"hps\">foi executado.<\/span><br \/>\n<!--more--><br \/>\n<span class=\"hps\">Usando<\/span> <span class=\"hps\">esse conhecimento, voc\u00ea<\/span> <span class=\"hps\">pode facilmente<\/span> <span class=\"hps\">rastrear<\/span> <span class=\"hps\">um script<\/span> <span class=\"hps\">que<\/span> <span class=\"hps\">est\u00e1 sendo explorada<\/span> <span class=\"hps\">para enviar spam<\/span>, <span class=\"hps\">ou localizar<\/span> <span class=\"hps\">os scripts<\/span><span class=\"hps\">possivelmente<\/span> <span class=\"hps\">maliciosos que<\/span> <span class=\"hps\">um<\/span> <span class=\"hps\">spammer<\/span> <span class=\"hps\">tenha colocado<\/span> <span class=\"hps\">no seu servidor.<\/span><\/span><\/p>\n<p><strong><span id=\"result_box\" class=\"short_text\" lang=\"pt\"><span class=\"hps\">Localize os<\/span> <span class=\"hps\">Scripts com<\/span> <span class=\"hps\">envio<\/span> <span class=\"hps\">de e-mail no<\/span> <span class=\"hps\">Exim<\/span><\/span><\/strong><\/p>\n<p><span id=\"result_box\" class=\"short_text\" lang=\"pt\"><span class=\"hps\"><span id=\"result_box\" lang=\"pt\"><span class=\"hps\">Nos passos<\/span> <span class=\"hps\">abaixo<\/span> vamos<span class=\"hps\"> mostrar<\/span> <span class=\"hps\">como localizar<\/span> <span class=\"hps\">os<\/span> <span class=\"hps\">scripts em seu<\/span> <span class=\"hps\">servidor de envio<\/span> <span class=\"hps\">de e-mail.<\/span> <span class=\"hps\">Se<\/span> desconfiar de <span class=\"hps\">qualquer script<\/span>, voc\u00ea pode verificar <span class=\"hps\">os logs de acesso<\/span> <span class=\"hps\">do Apache<\/span> <span class=\"hps\">para encontrar<\/span> <span class=\"hps\">como<\/span> <span class=\"hps\">um<\/span> <span class=\"hps\">spammer<\/span> <span class=\"hps\">pode estar usando<\/span> <span class=\"hps\">seus scripts para<\/span> <span class=\"hps\">enviar<\/span> <span class=\"hps\">spam.<\/span><\/span><\/span><\/span><\/p>\n<p><span lang=\"pt\"><span class=\"hps\">Para<\/span> <span class=\"hps\">seguir os passos<\/span> <span class=\"hps\">abaixo voc\u00ea<\/span> <span class=\"hps\">precisa<\/span> <span class=\"hps\">de acesso root<\/span> <span class=\"hps\">ao servidor,<\/span> <span class=\"hps\">para que voc\u00ea tenha<\/span> <span class=\"hps\">acesso ao log<\/span> <span class=\"hps\">mail do<\/span> <span class=\"hps\">Exim<\/span>.<\/span><\/p>\n<p><strong>Passo 1<\/strong> &#8211; <span lang=\"pt\"><span class=\"hps\">Acesse<\/span> <span class=\"hps\">o servidor<\/span> <span class=\"hps\">via SSH<\/span> <span class=\"hps\">como usu\u00e1rio root<\/span>.<\/span><\/p>\n<p><strong>Passo 2<\/strong> &#8211; <span lang=\"pt\"><span class=\"hps\">Execute o seguinte comando<\/span> <span class=\"hps\">para verificar os scripts mais utilizados para envio de e-mails nos logs do Exim<\/span>:<\/span><\/p>\n<p>&nbsp;<\/p>\n<table border=\"1\">\n<tbody>\n<tr>\n<td><span id=\"result_box\" lang=\"pt\">grep cwd \/var\/log\/exim_mainlog | grep -v \/var\/spool | awk -F&#8221;cwd=&#8221; &#8216;{print $2}&#8217; | awk &#8216;{print $1}&#8217; | sort | uniq -c | sort -n<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span lang=\"pt\"><span lang=\"pt\"><span id=\"result_box\" lang=\"pt\"><span id=\"result_box\" lang=\"pt\"><span id=\"result_box\" lang=\"pt\"><br \/>\n<\/span><\/span><\/span><span id=\"result_box\" class=\"short_text\" lang=\"pt\"><span class=\"hps\">Voc\u00ea deve<\/span> <span class=\"hps\">receber de volta<\/span> <span class=\"hps\">algo como isto:<\/span><\/span><\/span><\/span><\/p>\n<p>&nbsp;<\/p>\n<table border=\"1\">\n<tbody>\n<tr>\n<td>15 \/home\/userna5\/public_html\/about-us<br \/>\n25 \/home\/userna5\/public_html<br \/>\n7866 \/home\/userna5\/public_html\/data<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span lang=\"pt\"><span lang=\"pt\"><br \/>\n<span id=\"result_box\" lang=\"pt\"><span class=\"hps\">Podemos ver<\/span> que\u00a0<strong>\/home\/userna5\/public_html\/data<\/strong> <span class=\"hps\">de longe<\/span> <span class=\"hps\">tem<\/span> <span class=\"hps\">mais envios<\/span><span class=\"hps\"> do que<\/span> <span class=\"hps\">quaisquer outros.<\/span><\/span><\/span><\/span><\/p>\n<p><strong>Passo 3<\/strong> &#8211; <span lang=\"pt\"><span class=\"hps\">Agora podemos<\/span> <span class=\"hps\">executar o seguinte comando<\/span> <span class=\"hps\">para ver os<\/span><span class=\"hps\"> scripts<\/span> que <span class=\"hps\">est\u00e3o localizados<\/span> <span class=\"hps\">no diret\u00f3rio<\/span>:<\/span><\/p>\n<p>&nbsp;<\/p>\n<table border=\"1\">\n<tbody>\n<tr>\n<td>ls -lahtr \/userna5\/public_html\/data<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span lang=\"pt\"><span lang=\"pt\"><span id=\"result_box\" lang=\"pt\"><\/span><br \/>\n<span id=\"result_box\" class=\"short_text\" lang=\"pt\"><span class=\"hps\">Neste<\/span> <span class=\"hps\">caso<\/span> <span class=\"hps\">recebemos de volta<\/span>:<\/span><\/span><\/span><\/p>\n<p>&nbsp;<\/p>\n<table border=\"1\">\n<tbody>\n<tr>\n<td>drwxr-xr-x 17 userna5 userna5 4.0K Jan 20 10:25 ..\/<br \/>\n-rw-r&#8211;r&#8211; 1 userna5 userna5 5.6K Jan 20 11:27 mailer.php<br \/>\ndrwxr-xr-x 2 userna5 userna5 4.0K Jan 20 11:27 .\/<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span lang=\"pt\"><span lang=\"pt\"><br \/>\n<span id=\"result_box\" lang=\"pt\"><span class=\"hps\">Como podemos<\/span> <span class=\"hps\">ver, h\u00e1 um<\/span> <span class=\"hps\">script chamado<\/span> <span class=\"hps\">mailer.php<\/span> <span class=\"hps\">neste diret\u00f3rio.<\/span><\/span><\/span><\/span><\/p>\n<p><strong>Passo 4<\/strong> &#8211; <span id=\"result_box\" lang=\"pt\"><span class=\"hps\">Sabendo<\/span> <span class=\"hps\">o script<\/span> <strong><span class=\"hps\">mailer.php<\/span><\/strong> <span class=\"hps\">estava enviando<\/span> <span class=\"hps\">e-mail<\/span> <span class=\"hps\">pelo<\/span> <span class=\"hps\">Exim<\/span>, podemos agora <span class=\"hps\">dar uma olhada no<\/span> <span class=\"hps\">log de acesso<\/span> <span class=\"hps\">Apache<\/span> <span class=\"hps\">para ver<\/span><span class=\"hps\">os endere\u00e7os IP<\/span> que <span class=\"hps\">est\u00e3o acessando<\/span> <span class=\"hps\">este script<\/span> <span class=\"hps\">usando o seguinte comando<\/span>:<\/span><\/p>\n<p>&nbsp;<\/p>\n<table border=\"1\">\n<tbody>\n<tr>\n<td>grep &#8220;mailer.php&#8221; \/home\/userna5\/access-logs\/example.com | awk &#8216;{print $1}&#8217; | sort -n | uniq -c | sort -n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span lang=\"pt\"><span lang=\"pt\"><br \/>\n<span id=\"result_box\" class=\"short_text\" lang=\"pt\"><span class=\"hps\">Voc\u00ea deve<\/span> <span class=\"hps\">receber de volta<\/span> <span class=\"hps\">algo semelhante a isto<\/span>:<\/span><\/span><\/span><\/p>\n<p>&nbsp;<\/p>\n<table border=\"1\">\n<tbody>\n<tr>\n<td>2 123.123.123.126<br \/>\n2 123.123.123.125<br \/>\n2 123.123.123.124<br \/>\n7860 123.123.123.123<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span id=\"result_box\" lang=\"pt\"><br \/>\n<span id=\"result_box\" lang=\"pt\"><span class=\"hps\">Podemos ver que o<\/span> <span class=\"hps\">endere\u00e7o IP<\/span> <strong><span class=\"hps\">123.123.123.123<\/span><\/strong> <span class=\"hps\">est\u00e1 usando<\/span> <span class=\"hps\">o script<\/span> <span class=\"hps\">mailer<\/span> <span class=\"hps\">em uma natureza<\/span> <span class=\"hps\">mal-intencionada.<\/span><\/span><\/span><\/p>\n<p><strong>Passo 5<\/strong> &#8211; <span id=\"result_box\" lang=\"pt\"><span class=\"hps\">Se voc\u00ea encontrar um<\/span> <span class=\"hps\">endere\u00e7o<\/span> <span class=\"hps\">IP<\/span> <span class=\"hps\">malicioso<\/span> com <span class=\"hps\">envio de um grande<\/span> <span class=\"hps\">volume de e-mails<\/span> <span class=\"hps\">a partir de um<\/span> <span class=\"hps\">script, voc\u00ea<\/span> <span class=\"hps\">deve<\/span> <span class=\"hps\">bloquea-lo<\/span><span class=\"hps\">no<\/span> <span class=\"hps\">firewall<\/span> <span class=\"hps\">do servidor<\/span> <span class=\"hps\">para que<\/span> <span class=\"hps\">ele n\u00e3o possa<\/span> <span class=\"hps\">tentar se conectar<\/span> <span class=\"hps\">novamente. Ou se preferir poder\u00e1 remover o script por completo.<\/span><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Neste guia vamos ensinar como usar os logs do Exim em seu VPS\/Cloud ou servidor dedicado para encontrar poss\u00edveis tentativas de spammers\u00a0usando\u00a0scripts para envio de e-mails n\u00e3o solicitados, a fim de retransmitir o spam de seu servidor. Como \u00e9 que o spam s\u00e3o enviados do meu servidor? Voc\u00ea pode ter um recurso de &#8220;informar a [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[455,1,730,830,725,42,51,495,514,271,74,501,548],"tags":[349,378,945,369,941,942,206,377,943,944],"class_list":["post-4105","post","type-post","status-publish","format-standard","hentry","category-apache2","category-viazap","category-clusterweb","category-debian","category-hospedagem","category-leitura-recomendada","category-linux-linuxrs","category-profissional-de-ti","category-programacao","category-seguranca-2","category-servidor-de-e-mail","category-shell-script","category-ubuntu-2","tag-com","tag-como","tag-cpanel","tag-em","tag-localizar","tag-realizando","tag-scripts","tag-servidores","tag-spam","tag-whm"],"_links":{"self":[{"href":"https:\/\/blog.clusterweb.com.br\/index.php?rest_route=\/wp\/v2\/posts\/4105","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.clusterweb.com.br\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.clusterweb.com.br\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.clusterweb.com.br\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.clusterweb.com.br\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4105"}],"version-history":[{"count":2,"href":"https:\/\/blog.clusterweb.com.br\/index.php?rest_route=\/wp\/v2\/posts\/4105\/revisions"}],"predecessor-version":[{"id":4107,"href":"https:\/\/blog.clusterweb.com.br\/index.php?rest_route=\/wp\/v2\/posts\/4105\/revisions\/4107"}],"wp:attachment":[{"href":"https:\/\/blog.clusterweb.com.br\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4105"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.clusterweb.com.br\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4105"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.clusterweb.com.br\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4105"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}