Forum Moderators: phranque

Message Too Old, No Replies

Weird Hits on my logs - Help

What is this on my logs and error logs? Should I be worried?

         

PinkPanther

9:00 pm on Oct 1, 2002 (gmt 0)

10+ Year Member



I haven seen similar things before - but this one is the oddest. I was hit hard today, below are a few:

adsl-67-38-253-140.dsl.bcvloh.ameritech.net - - [01/Oct/2002:12:04:53 -0400] "GET /cgi-bin/formmail.pl?recipient=hogporn@yahoo.com&subject=http://www.nismedia.com/cgi-bin/formmail.pl&body=52065945&email=nmpbeixdd@aol.com HTTP/1.1" 404 301 "-" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"

adsl-67-38-253-140.dsl.bcvloh.ameritech.net - - [01/Oct/2002:12:04:53 -0400] "GET /cgi-local/formmail.pl?recipient=hogporn@yahoo.com&subject=http://www.nismedia.com/cgi-local/formmail.pl&body=25888467&email=uxectannb@aol.com HTTP/1.1" 404 303 "-" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"

adsl-67-38-253-140.dsl.bcvloh.ameritech.net - - [01/Oct/2002:12:04:53 -0400] "GET /cgi-local/FormMail.pl?recipient=hogporn@yahoo.com&subject=http://www.nismedia.com/cgi-local/FormMail.pl&body=35369373&email=nhxvvuxpt@aol.com HTTP/1.1" 404 303 "-" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"

On my error logs, I did see hits afterhits from this IP.

The question is, what is this, who is doing it, should I be worried?

Thanks,
Pink :)

Big_Balou

9:18 pm on Oct 1, 2002 (gmt 0)

10+ Year Member



PinkPanther,

it looks like some one is trying to see if you have an old version of formail that they can exploit. From the looks of it if the example you gave finds a vulnerable script it sends an email to the oh so bright scripter :(. If your server doesn't use formail no prob but if it does you need to make sure that it has been updated to the latest version.

Here is another thread about this here [webmasterworld.com]

<added> Just took another look at the examples. They are getting 404's so it may be that you either aren't using formail or already have an updated copy</added>

[edited by: Big_Balou at 9:23 pm (utc) on Oct. 1, 2002]

amoore

9:22 pm on Oct 1, 2002 (gmt 0)

10+ Year Member



And another here:
[webmasterworld.com...]

PinkPanther

9:30 pm on Oct 1, 2002 (gmt 0)

10+ Year Member



Big_Balou,

My server uses formmail and so do I.

>From the looks of it if the example you gave finds a vulnerable script it sends an email to the oh so bright scripter<

The scripter meaning who exactly?

I am sorry, how can someone exploit a form mail? Sorry, I not too sure that is all :)

Would you suggest that I contact my web host as well?

Thanks so much.

Pink ;)

PinkPanther

9:38 pm on Oct 1, 2002 (gmt 0)

10+ Year Member



Actually my host uses a Templated Mailer CGI. Am I still in danger?

Pink :)

Big_Balou

9:47 pm on Oct 1, 2002 (gmt 0)

10+ Year Member



Pink,

sorry if I wasn't clear. When I refered to the scripter I meant the person who is using a script to automatically check for sites that are using an older version of formail.

I would defintely contact my host to see if they have either upgraded to formail 1.9 or have installed the patch available for 1.6. Here is a link [online.securityfocus.com] that discusses the exploit in detail.

<added> oops...was doing a search and didn't see your reply. As far as I know if you aren't using formail.cgi you should be in good shape...if I'm wrong someone will come by and correct me</added>

PinkPanther

10:09 pm on Oct 1, 2002 (gmt 0)

10+ Year Member



Big,

Most awesome. Thanks - I am using tmail.cgi and am planning on using php as I continue. I hate spammers :(

Thanks so much again ;)

Pink