Forum Moderators: coopster

Message Too Old, No Replies

Someone "hacked" my PHP mailinglist??

         

I Will Make It

3:57 pm on Jan 12, 2007 (gmt 0)

10+ Year Member



Hi all!

I'm sorry if my English is hard to understand, but please try ;) I would be very happy for some replies!
-------------------------------------------

Yesterday I got 2 very wierd subscribers to my mailinglist.

(the "mywebsiteurl.no" is made up by me not to give away my real URL)

No. 1: meat3730@mywebsiteurl.no

No. 2: pre7353@mywebsiteurl.no

Since these people signed up for my mailinglist with my website-url as the domain name (the name after the @ in the mail adress) their "Welcome messages" was of course sent to my company email.
This is why I understood something was wrong.

My welcome message begins with: "Hi, 'NAME!,

The first subcriber (meat3730@mywebsiteurl.no) recieved his welcome letter (sent to my email adress) - it was very wierd, looked like this:

Hi bacon Content-Transfer-Encoding: quoted-printable Content-Type: text/html Subject: production in taly bcc: craig@example.com e n, xtremadura, and ndalusia 912119cd5ade363b9120392885c9c38a . ,

The second one (pre7353@mywebsiteurl.no) looked fine.

What I did was to sign up for my own mailing list with a hotmail-account I made, just to check what happened.

And not surprisingly I recieved my "welcome message" from my own mailing script:

Hi (my user name) bacon Content-Transfer-Encoding: quoted-printable Content-Type: text/html Subject: production in taly bcc: craig@example.com e n, xtremadura, and ndalusia 912119cd5ade363b9120392885c9c38a . ,

It looks like these people have done something to my script that will send every mail-adress I recieve to my mailing list also to these fu%#ers... I have of course deleted these "users" from my list.

Do you think they have gotten into my script on the server, or is this just something they have put in the "name field" of my opt-in form? Anyone have a clue how I can prevent it to happen again?

Thanks,

I Will Make It!

[edited by: jatar_k at 4:04 pm (utc) on Jan. 12, 2007]
[edit reason] examplified [/edit]

barns101

5:49 pm on Jan 12, 2007 (gmt 0)

10+ Year Member



I would have initially said that it was an email header injection attempts and that filtering user input would prevent it. However, if you got an altered welcome message when entering legitimate details I'm not sure what's going on. If you want to sticky me your URI I will look at it for you and see if there's anything obviously wrong.