contact.php spam

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • AndrewT
    Administrator
    • Mar 2004
    • 3655

    #1

    contact.php spam

    Many domains are currently being exploited to send spam, specifically to AOL addresses, through a contact.php script that appears to be fairly common. At this time I'm uncertain as to what the name of this script is or what it is a part of but I will update this thread as soon as it is confirmed.

    If you have a domain that is running this contact.php please remove it immediatley otherwise your domain may very well end up suspended as it becomes a target for spammers like many other domains already have.
    Last edited by -Oz-; 11-15-2005, 06:43 PM.
  • AndrewT
    Administrator
    • Mar 2004
    • 3655

    #2
    Since I posted this 12 more accounts have been hit. This doesn't appear to be affecting a single script in particular. I've looked through the accounts and the script names and code differ quite a bit as well. Additionally, the HTTP traffic is not coming from a single IP or IP range at all.

    If you are unsure, your safest bet would be to simply deactivate all PHP mail scripts on your domains for the time being at least.

    Comment

    • -Oz-
      Senior Member
      • Mar 2004
      • 545

      #3
      discuss this further here: http://forums.dathorn.com/showthread.php?t=1987
      Dan Blomberg

      Comment

      • AndrewT
        Administrator
        • Mar 2004
        • 3655

        #4
        Domains are still bieng suspended due to these improperly coded scripts. If you are running PHP contact forms of any kind they need to be fully secured with image verification and input checking for BCC and other headers.

        Comment

        • AndrewT
          Administrator
          • Mar 2004
          • 3655

          #5
          Note that this is also an important problem if your forms send an automated response to the FROM address that is entered into the form. Spammers can then essentially enter the addresses that they want to spam into the FROM field and keep submitting the form.

          Comment

          • AndrewT
            Administrator
            • Mar 2004
            • 3655

            #6
            Please see this thread as well: http://forums.dathorn.com/showthread.php?p=11376

            Comment

            Working...