?
Solved

Spam using apache

Posted on 2003-11-18
5
Medium Priority
?
299 Views
Last Modified: 2010-03-04
Hi, Im running mandrake 7.2 with sendmail 8.11  and apache 1.3.12 (I know it's old, but its a bit tricky to upgrade that server at the moment). We received some complaints that our server had been used to spam, and when I looked at the sendmail logs, it shows an email being sent nearly every second but it says "from=apache" and I havent got a clue how they're doing this. There are a few websites on that server that have formmail (perl) and php contact pages that have the to field already specified, could this be the cause?

Also, could it be that its because I'm running old versions of apache and or sendmail? Whats the best way to stop this person spamming through my server?
0
Comment
Question by:choccarlm
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 16

Accepted Solution

by:
_nn_ earned 500 total points
ID: 9769911
If that formmail.pl is the ol' "Matt's" one, then I'd recommend to replace it asap with the one provided at http://nms-cgi.sourceforge.net/
0
 
LVL 15

Expert Comment

by:periwinkle
ID: 9779934
I agree with _nn_ - there were a number of security issues in the old Matt's script archive formmail - see:

http://www.monkeys.com/anti-spam/formmail-advisory.pdf
http://www.toto.com/cgi-bin/periwinkle/newsget?id=A00083
http://www.toto.com/cgi-bin/periwinkle/newsget?id=A00065

(also go to http://www.securityfocus.com/search and search on formmail )
0
 
LVL 22

Expert Comment

by:pjedmond
ID: 9922153
If the formail.pl script is being used to email you only, and you don't mind receiving the odd bit of SPAM, you can configure the formail script to pass all the environemntal variables to the script, and actually start to locate the person responsible for the spamming. I personally hardcode the 'to address' in all my scripts wherever possible in order to prevent this type of abuse of the script.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If your site has a few sections that need to be secure when data is transmitted between the server and local computer, such as a /order/ section for ordering or /customer/ which contains customer data, etc it would of course be recommended to secure…
If you are a web developer, you would be aware of the <iframe> tag in HTML. The <iframe> stands for inline frame and is used to embed another document within the current HTML document. The embedded document could be even another website.
In this video, Percona Solutions Engineer Barrett Chambers discusses some of the basic syntax differences between MySQL and MongoDB. To learn more check out our webinar on MongoDB administration for MySQL DBA: https://www.percona.com/resources/we…
How to fix incompatible JVM issue while installing Eclipse While installing Eclipse in windows, got one error like above and unable to proceed with the installation. This video describes how to successfully install Eclipse. How to solve incompa…
Suggested Courses

800 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question