|
|
 |
Re: FN-FORUM matts formmail.pl scripts
date posted 6th January 2002 23:00
On Sun, 6 Jan 2002, nik butler wrote:
> Ok everyone if your using the formmail.pl script for form mail then go check your logs. Seems bluedotmail.com have been relaying spam through these scripts on other peoples websites. You should scan your logs
>
> bluedotmail.com - - [06/Jan/2002:04:05:59 +0000] "GET /cgi-bin/formmail.pl?(=Hey
> +hun,+just+wanted+to+tell+you+I+finally+got+my+new+adult+Webcam+up+and+it's+tota
> lly+FREE!+Come+take+a+peek+at+http://www.kristisosexy.com/livecams+:)+Love,+Heat
> [EMAIL REMOVED]@[EMAIL REMOVED]@
> [EMAIL REMOVED]@hotmail.com&subject=Re:+what's+up? HTTP/1.0"
> 200 817 "-" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; T312461)"
>
>
> Here the 200 817 shows the operation was succesful, we changed the script to another name .pl and they have been getting 403s'
>
>
> if you discover you have been hit please realise that bluedotmail.com may not be the culprits but the victims of a clever relayer.
>
>
> Regards
> nik
>
This is a problem with all the formail script written by matt. To be
honest I would say that is someone really wants something like this that
they use there own and hardcode the domain into it. That way it can't be
abused
Rus
--
http://www.rusnet.info - Linux all the way
Websites + Email + Domain registration + Consultancy
|
 |
|