Forum Moderators: open
Problem is, I didn't try to send that message! As I read through the attached message I got the idea that it was someone or something attempting to send mail through a cgi mail form on my website - there is not one so perhaps this is why it failed. The return address was set to none@ my domain name...which is not valid.
Here is the body of the returned message:
******
The message identifier is: 19LTds-0000C8-00
The subject of the message is: Ignoreto: Spankyparade@o2.plBEGINABCDFORMMAILwww.mydomain.ca/cgi-sys/formmail.plTSTSendMailTSTENDABCD.
The date of the message is: Thu, 29 May 2003 16:04:52 -0400
The address to which the message has not yet been delivered is:
none@www.mydomain.ca
Delay reason: lowest numbered MX record points to local host
********
I use a robots.txt file but I am not sure that this is a "spider". I would like to be sure that such efforts in the future cannot succeed.
Thanks!
itrainu
If you do not have access to the cgi-sys directory, it may be a script that your sys admin has installed for system wide use.
Try putting the url to the script in your browsers address field and see if you get a responce from the script.
If you do, you need to contact your sys admin and have them use a more secure script.
This will cause your email address or IP to get blackholed.
At one time (last year) my office website was seeing on order of 100-150 hits a day from people checking to see if formmail.pl was installed. Think how bad things might have been if they'd actually found it.
FormMail-Clone
This is FormMail-clone, a clone of FormMail.cgi. It is a clean room version for legal purposes (a less restrictive liscense), but should behave the exact same way as Matt Wright's Original, but contain none of his code.
itrainu
Although I've read of instances where the clone is still vulnerable, I've yet to see it occurr.
This is a sensitive subject in this open forum which is indexed by search engines :( and monitored by (from past experience) some not so honorable lurkers. :(
to say the least... for those that really care, rockstar,
you are included if you care, too... i've been keeping a
manually generated log from all formmail.* and mailto.*
scans of my system... if you are interested, and if the
moderators allow it, the url is
[wpusa.dynip.com...]
the interesting part is the pattern followed and how
persistent these guys are... the funny part is that i have
never had a formmail or mailto script of program on my
site... the most funny part is that they seem to assume that
my site is running winsomething software...
sorry guys, but that will /never/ happen :wink: