Page 1 of 1

Still spam coming thru

Posted: Fri Feb 24, 2006 10:51 am
by ichnation
Yesterday i suffered from a spam attack that came trhough the default contact form. :'( All was caused by me, missing the latest upgrade from december. (BTW: did I miss the post on secunia?)

Of course, i quickly upgraded to 0.11.2, the latest release. Indeed, the flood stopped. today, I found a new message that came in through the apache user on my account.The date is also set today. Possibly our friends already found out how to escape the new form.

Im running the 'default' contact form, version 1.1. I should also be telling its a fedora core 3 box, PHP Version 4.4.2, Apache/1.3.34 in case of any relevance.

I have a few questions:
* has anyone seen similar messages coming through ?
* is anyone aware of a new possible vullnerability?
* is there a way already provided to prevent such abuse, or a workaround with a different form system?

Thanx!

Below are the headers of this mail. Anyone listening  ;)  I took off my domain.com and replaced it by domain.com.

Code: Select all

From - Fri Feb 24 10:59:57 2006
X-Account-Key: account1
X-UIDL: 014d33a1cfa950be77dd502dcc86e879
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
>From domain@domain.com Fri Feb 24 10:58:32 2006
Return-path: <domain@domain.com>
Envelope-to: barry@voeten.com
Delivery-date: Fri, 24 Feb 2006 10:58:32 +0100
Received: from apache by server22.domain.com with local (Exim 4.50)
	id 1FCZia-0007dO-5D
	for domain@domain.com; Fri, 24 Feb 2006 10:58:32 +0100
To: domain@domain.com
Subject: the4202@domain.com
From: nryContent-Type: multipart/alternative@domain.com; boundary=ee5f3535e7c3978ad56791c0fb48c251MIME-Version: 1.0Subject: rayvolver an took out a policy on his life. ladybcc: WintOlympLovr99@recipient-domain.comThis is a multi-part message in MIME format.--ee5f3535e7c3978ad56791c0fb48c251Content-Type: text/plain; charset="us-ascii"MIME-Version: 1.0Content-Transfer-Encoding: 7bitto him. o wan hears or wants to hear annything about it. h nex time we see ye, 
	ye come out lookin pale an emacyated an much younger an betther lookin thin annywan iver raymimbers--ee5f3535e7c3978ad56791c0fb48c251--. <the4202@domain.com>
Reply-To: the4202@domain.com
Message-Id: <E1FCZia-0007dO-5D@server22.domain.com>
Date: Fri, 24 Feb 2006 10:58:32 +0100


the4202@domain.com
 

Re: Still spam coming thru

Posted: Wed Jun 21, 2006 7:25 pm
by Tanner
I realize that this is an old thread now, but as of recently I too have started receiving these same types of "spam" messages coming through the default contact form, where the Subject and From fields are always set to "something@MYdomain.com".

Is there any known way to prevent these sort of attacks/floods using the default contact form? Thank you. I'm using CMSMS 0.12.1.

Re: Still spam coming thru

Posted: Wed Jun 21, 2006 7:49 pm
by Dr.CSS
if you use FeedbackForm module it has "captcha" image with graphic letters/symbols/numbers for spambot anti fill

Re: Still spam coming thru

Posted: Wed Jun 21, 2006 9:06 pm
by danielbone1
I am confused again.  Not hard to confuse me though really.

Mark you mentioned the feedback form mod and captcha in the same sentence.  Does the feedback form mod have this
technology built in somehow.  I have the latest version I believe and can't seem to see the captcha option.

Thanks,
Dan

Re: Still spam coming thru

Posted: Wed Jun 21, 2006 10:09 pm
by Dr.CSS
sorry my confusing my self diregard last post...  :-X

Re: Still spam coming thru

Posted: Mon Jun 26, 2006 12:33 pm
by Tony Cipriani
I'm using the contact_form email and I'm also seeing these same spam messages from  somenumber@domainame coming through.

Dan, or anyone else,  does the feedback form you mention solve the problem or not ?

Re: Still spam coming thru

Posted: Mon Jun 26, 2006 10:32 pm
by danielbone1
Tony C ::  I am still receiving a good deal of spam thru the feedback form mod.  I think that there has been a discussion on how to stop it
somewhere on the forum.  I haven't had time to dive into it as of yet.

Dan

Re: Still spam coming thru

Posted: Tue Jun 27, 2006 8:38 am
by Tony Cipriani
TNX people  :)

and thanks for the tip about the Master Feedback script.

Re: Still spam coming thru

Posted: Tue Jun 27, 2006 11:40 pm
by Dr.CSS
Tony Cipriani wrote: I'm using the contact_form email
i'm no PHP wiz but can't we add the captcha funtion to the contact_form... it's in Comments...