Forum Moderators: mack

Message Too Old, No Replies

Is someone snooping around my site?

formmail

         

Goober

12:59 pm on Aug 13, 2003 (gmt 0)

10+ Year Member



Howdy,

I've got 3 hits on my website that I found through weba***
and they did not show up in my web stats program. Can someone explain what they mean?

Host: 209.247.34.205 Url: /cgi-sys/formmail.pl Http Code : 200
Date: Aug 13 04:49:43 Http Version: HTTP/1.0 Size in Bytes: 263
Referer: [********.com...]

The hits came from Holland and Gemany and NC.

HELP!

Dave

kevinpate

1:18 pm on Aug 13, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Someone, or some bot type uglie, was testing your system to see if they could access your formmail script so they could spam through your site and bandwidth.

I notice the server code returned was 200. If you're actually using that script, under that name, put it elsewhere in your system and change its name.

I don't use it, I don't have that directory, but I get a few non-USA lookielous near on every day trying to see if it's there or not.

Goober

1:41 pm on Aug 13, 2003 (gmt 0)

10+ Year Member



Thanks Kevinpate,

Is it as simple as renaming the file? From Formail to NormaiL? Should I simply disable the use of it on my site? If I do, then do I redirect mail to a different email on my home pc?

I also have the option of locking the folder through the use of a password. Is that advisable?

Thanks in advance for your help.

Dave

Slade

3:58 pm on Aug 13, 2003 (gmt 0)

10+ Year Member



If you're not using the formmail script (to have a form that's submitted emailed to you), then rename or delete it.

Even if you are using it, you should not have it called formmail.anything because of scripts (like the ones that hit you) that are designed to seek them out, and spam people with them.

claus

4:08 pm on Aug 13, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Just a pointer to two recent threads about this:

1) [webmasterworld.com...]

2) [webmasterworld.com...]

Goober

4:24 pm on Aug 13, 2003 (gmt 0)

10+ Year Member



Thank you so much for your input. It's greatly appreciated.
I'll muddle around and correct it. If I create a bigger problem, I'll come runnin' right back!

<I just checked and my forms all email the data to my mail address of the website. I have never set up formail. The form on the webpage sends the data to the site's main email address. Am I still in doo-doo?>

Thanks again for all the help.

Dave

claus

5:02 pm on Aug 13, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Well then, if you have a file named "formmail.something" anywhere on your system you should still rename it or delete it especially if you don't use it. That way it's probably not secured enough, so perhaps mail-spammers can use it in stead without you knowing about it. It's not good if you suddently face a spam-accusation, so go ahead and zap it anyway :)

/claus

Goober

8:24 pm on Aug 13, 2003 (gmt 0)

10+ Year Member



Howdy,

Just talked to my web hosting company and it seems that there is an increase in the type of activity that is the topic of this thread. I also found out that I don't have a formmail.pl or formmail.* on my site, just a page that explains what it is. It's a help page and it offers an explanation of what formmail is. Ha!

Thanks for helping to point me in the right direction. I also appreciate the posted threads to read. My eyes hurt.

Dave