Forum Moderators: phranque

Message Too Old, No Replies

Got hacked?

wierd user agent, Spam Collect 1.1

         

shasan

2:52 am on Jun 16, 2005 (gmt 0)

10+ Year Member



So i turn on my email today and see a couple of contacts in my inbox from my website. One of them said this:

"I just like spam! I'm collocting junk email..."

[sent using my 'contact us' form]

ANOTHER message sent to me using the script I use for my 'email this page to a friend' functionality, only the script had been POSTed to using something other than the form provided on the page.

And another email confirming a subscription to my newsletter.

All these three instances bore the name JAPHspam, and in my logs, I pinpointed the IP.. here are the instances.. (edited)

<some ip> - - [15/Jun/2005:11:32:04 -0500] "GET /myfolder/tutorialpage1.html HTTP/1.1" 200 27076 "-" "Spam_collect/1.1"

<some ip> - - [15/Jun/2005:11:32:16 -0500] "POST /contactscript.php HTTP/1.1" 302 5 "-" "Spam_collect/1.1"

<some ip> - - [15/Jun/2005:11:32:19 -0500] "POST /cgi-bin/newsletter/newsletter-formget.pl HTTP/1.1" 200 1249 "-" "Spam_collect/1.1"

<some ip> - - [15/Jun/2005:11:32:24 -0500] "POST /sendthispage.php HTTP/1.1" 200 12401 "-" "Spam_collect/1.1"

The IP fails to resolve to anything.

Has anyone seen this Spam_collect/1.1 thing before? Or gotten an email from JAPHspam?

[edited by: physics at 6:08 pm (utc) on June 16, 2005]
[edit reason] oops, no specific ips please [/edit]

Dijkgraaf

3:03 am on Jun 16, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



The IP address is from an ISP in China.
I'd say they are looking for vunerable web based forms they can use to spam people with.
They are posting directly to the pages, probably using an automated script.
I have seen similar things hitting my guestbook, but not this one, but I'm blocking most of them allready.