Solved

Spam using apache

Posted on 2003-11-18
5
297 Views
Last Modified: 2010-03-04
Hi, Im running mandrake 7.2 with sendmail 8.11  and apache 1.3.12 (I know it's old, but its a bit tricky to upgrade that server at the moment). We received some complaints that our server had been used to spam, and when I looked at the sendmail logs, it shows an email being sent nearly every second but it says "from=apache" and I havent got a clue how they're doing this. There are a few websites on that server that have formmail (perl) and php contact pages that have the to field already specified, could this be the cause?

Also, could it be that its because I'm running old versions of apache and or sendmail? Whats the best way to stop this person spamming through my server?
0
Comment
Question by:choccarlm
5 Comments
 
LVL 16

Accepted Solution

by:
_nn_ earned 125 total points
ID: 9769911
If that formmail.pl is the ol' "Matt's" one, then I'd recommend to replace it asap with the one provided at http://nms-cgi.sourceforge.net/
0
 
LVL 15

Expert Comment

by:periwinkle
ID: 9779934
I agree with _nn_ - there were a number of security issues in the old Matt's script archive formmail - see:

http://www.monkeys.com/anti-spam/formmail-advisory.pdf
http://www.toto.com/cgi-bin/periwinkle/newsget?id=A00083
http://www.toto.com/cgi-bin/periwinkle/newsget?id=A00065

(also go to http://www.securityfocus.com/search and search on formmail )
0
 
LVL 22

Expert Comment

by:pjedmond
ID: 9922153
If the formail.pl script is being used to email you only, and you don't mind receiving the odd bit of SPAM, you can configure the formail script to pass all the environemntal variables to the script, and actually start to locate the person responsible for the spamming. I personally hardcode the 'to address' in all my scripts wherever possible in order to prevent this type of abuse of the script.
0

Featured Post

On Demand Webinar - Networking for the Cloud Era

This webinar discusses:
-Common barriers companies experience when moving to the cloud
-How SD-WAN changes the way we look at networks
-Best practices customers should employ moving forward with cloud migration
-What happens behind the scenes of SteelConnect’s one-click button

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Hi, in this article I'm going to teach you how to run your own site, and how to let people in (without IP). I'll talk about and explain each step... :) By the way, everything in this Tutorial is completely free and legal. This article is for …
In Solr 4.0 it is possible to atomically (or partially) update individual fields in a document. This article will show the operations possible for atomic updating as well as setting up your Solr instance to be able to perform the actions. One major …
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
In a recent question (https://www.experts-exchange.com/questions/29004105/Run-AutoHotkey-script-directly-from-Notepad.html) here at Experts Exchange, a member asked how to run an AutoHotkey script (.AHK) directly from Notepad++ (aka NPP). This video…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question