Forum Moderators: DixonJones
I found these four links in my stats pages as 404 errors.
The thing is my site doesnt use a database, doesnt have any formail scripts installed, doesnt use ASP, and I dont know why it shows a DLL file as well.
Why would some one be searching for this stuff?
Where my site is hosted they were recently changing email servers and had a few DNS problems, would this effect the web server and my site, or is it someone searching for something?
Craig
Just looking at where I posted this and I know it is going to be moved.. sorry about that :)
2nd try a get a backdoor program into the exec area then take control of the server.
DaveN
Lucky I dont have any of these installed and I have complete back ups of everything for all my sites with these guys!
Craig
why would the fact that you have been getting those errors for month make you think itīs not a hack? Thatīs certainly not a stringent conclusion.
There are scriptīs out there that you run and that automatically and systematically scan ip addresses and check the servers for those files and misconfigurations.
Andreas
My memory is a bit hazy, but when I first encountered this, I searched the Microsoft Knowlege Base to find the answer.
Probably not a hack, just a right-click error, an incompetent user, or both.
Jim
Some of the possible uses of this script are:
1) You want to have a form that will be mailed to you, but aren't sure how to write the CGI script for it.
2) You are the webmaster of your site and want to allow users to use forms, but not to have their own cgi-bin directories, which can cause security risks to your system. You can set this script up and then allow all users to run off of it.
3) Want to have one script to parse all of your html forms and mail them to you.
If you can get control over the /cgi-bin/formmail.cgi you can send thousands of email via it until your systems goes pop.
It's an automated bit of software checking you out
DaveN
One of my clients (who is listed in Yahoo), is regularly scanned (unsuccessfully).
We are hosted on the same server, both in dmoz, but she is in Y and I'm not. I strongly suspect that these scanner are finding her through her Yahoo listing.