Forum Moderators: open

Message Too Old, No Replies

Bot using form mail?

         

itrainu

5:41 pm on Jun 1, 2003 (gmt 0)

10+ Year Member



I received an email from the mailer-daemon that a message I was trying to send had not been delivered for 24 hours...and then the same message after 48 hours.

Problem is, I didn't try to send that message! As I read through the attached message I got the idea that it was someone or something attempting to send mail through a cgi mail form on my website - there is not one so perhaps this is why it failed. The return address was set to none@ my domain name...which is not valid.

Here is the body of the returned message:
******
The message identifier is: 19LTds-0000C8-00
The subject of the message is: Ignoreto: Spankyparade@o2.plBEGINABCDFORMMAILwww.mydomain.ca/cgi-sys/formmail.plTSTSendMailTSTENDABCD.
The date of the message is: Thu, 29 May 2003 16:04:52 -0400

The address to which the message has not yet been delivered is:

none@www.mydomain.ca
Delay reason: lowest numbered MX record points to local host
********
I use a robots.txt file but I am not sure that this is a "spider". I would like to be sure that such efforts in the future cannot succeed.

Thanks!

itrainu

guillermo5000

8:33 pm on Jun 1, 2003 (gmt 0)

10+ Year Member



It would seem that cgi-sys on your system does contain formmail.pl.

If you do not have access to the cgi-sys directory, it may be a script that your sys admin has installed for system wide use.

Try putting the url to the script in your browsers address field and see if you get a responce from the script.

If you do, you need to contact your sys admin and have them use a more secure script.

This will cause your email address or IP to get blackholed.

rbs10025

8:34 pm on Jun 1, 2003 (gmt 0)

10+ Year Member



formmail.pl is a notoriously insecure e-mail CGI which has been heavily used by spammers seeking to disguise their origins. It was originally written c. 1995 and was freely available from a Perl CGI script archive, so ended up being installed on many sites.

At one time (last year) my office website was seeing on order of 100-150 hits a day from people checking to see if formmail.pl was installed. Think how bad things might have been if they'd actually found it.

itrainu

12:16 am on Jun 2, 2003 (gmt 0)

10+ Year Member



Aha - you are both correct ;-) I entered the url [mydomain.ca...] and this is what I received:
FormMail-Clone
This is FormMail-clone, a clone of FormMail.cgi. It is a clean room version for legal purposes (a less restrictive liscense), but should behave the exact same way as Matt Wright's Original, but contain none of his code.

I have filed a help desk response (this is issue #2 today!) but have yet to hear back.
Looks like I might need to be shopping around for a new host. If you know of a good, inexpensive host that provides raw traffic logs, a handful of email addresses, please feel free to sticky me. I am currently paying $12.99 US which is pretty inexpensive compared to what we have around here :-)

itrainu

carfac

4:26 am on Jun 2, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



One quite simple way to deal with this- if you intent to actualy use the script- is to rename it to a new (and whacky!) name. Then you know the name , but it is not the "normal" name.

Otherwise, just delete it and be done with it!

dave

guillermo5000

4:57 am on Jun 2, 2003 (gmt 0)

10+ Year Member



I just sent you my Web host by sticky mail. :-))

wilderness

5:01 am on Jun 2, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Some webhosts have a protection in place which only allows the script to run from within the domain.

Although I've read of instances where the clone is still vulnerable, I've yet to see it occurr.

This is a sensitive subject in this open forum which is indexed by search engines :( and monitored by (from past experience) some not so honorable lurkers. :(

wkitty42

5:25 am on Jun 3, 2003 (gmt 0)

10+ Year Member



wilderness,

to say the least... for those that really care, rockstar,
you are included if you care, too... i've been keeping a
manually generated log from all formmail.* and mailto.*
scans of my system... if you are interested, and if the
moderators allow it, the url is

[wpusa.dynip.com...]

the interesting part is the pattern followed and how
persistent these guys are... the funny part is that i have
never had a formmail or mailto script of program on my
site... the most funny part is that they seem to assume that
my site is running winsomething software...

sorry guys, but that will /never/ happen :wink:

wilderness

6:01 am on Jun 7, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



31 attempts at most any variation you can imagine :)

168.9.253.251 - - [06/Jun/2003:21:45:07 -0700] "POST /cgi-bin/FormMail HTTP/1.0" 404 - "http://mydomain.com" "Mozilla/4.06 (Win95; I)"