iEntry 10th Anniversary Forum Rules Search
WebProWorld
Register FAQ Calendar Mark Forums Read
Internet Security Discussion Forum This forum is for the discussion of security related issues. If you find a new Phishing scheme, spyware, virus or malicious site - let us know about it. If any of the above found you... here's where you ask for help.

Share Thread: & Tags

Share Thread:

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 09-12-2005, 01:18 PM
WebProWorld Member
 
Join Date: Aug 2004
Location: Castle Rock, CO
Posts: 67
fisher318 RepRank 0
Default Contact Form being Hi-jacked - HELP!

Hello,

I have two websites that i have noticed it appears that the contact form is being hi-jacked. I get 10-12 emails in a row from that contact form with bogus email addresses in every field.

How can I tell for sure if the form is being hi-jacked and also, is there an easy way for a non-programmer to make the form more secure?

Thanks in advance for any help anyone can offer.
__________________
EagleTac Store | HID Flashlights
Reply With Quote
  #2 (permalink)  
Old 09-12-2005, 01:39 PM
WebProWorld Pro
 
Join Date: Jun 2004
Location: The Barrens of NE Ohio
Posts: 236
nottheusual1 RepRank 0
Default

That may not be the issue. There are known exploits for FrontPage extensions (older versions) that allow the hijacking of a server via a malformed form input.

What you may be seeing is the occasional errant script-kiddy checking your site for this vulnerability. I wouldn't worry about it, unless you are running an older version of the Frontpage extensions, that is.

We see this on every server a few times a week but don't pay any mind to it - we even see it on sites not using the FP extensions, so the bot's being used to look for the vulnerability aren't that smart, either.

Also, if you are running them, but never use them, it is much preferred to disable the extensions completely. Even most *nix servers have them installed.
__________________
:not_the_usual1
[you decide]
________________
All in my opinion, which, when combined carefully with a $1 bill, gets you a cup of coffee at the corner store.
Reply With Quote
  #3 (permalink)  
Old 09-12-2005, 01:42 PM
WebProWorld Member
 
Join Date: Aug 2004
Location: Castle Rock, CO
Posts: 67
fisher318 RepRank 0
Default

Thanks for the help. So can I assume that by disabling front page extensions on the server accounts, that my sites are pretty much protected from form hi-jacking?

However, the interesting thing, is that I didn't have front page extensions enabled, so then that would have just been a result of them checking my form for vulnerabilities rather than actually utilizing it for spam, correct?
__________________
EagleTac Store | HID Flashlights
Reply With Quote
  #4 (permalink)  
Old 09-12-2005, 01:51 PM
WebProWorld Pro
 
Join Date: Jun 2004
Location: The Barrens of NE Ohio
Posts: 236
nottheusual1 RepRank 0
Default

Well.... At least from that potential vulnerability.

You should also do a few other things, like maybe running php_suexec, but not every machine is the same. If you are running certain software, some easy fixes will break other things. As an example, you can't run MMCache, certain image gallery programs, etc., with php_suexec because it forces PHP to run as a CGI binary.

This would be a good discussion to have with one of the more knowledgeable admins at your host or NOC. Ask about basic stuff like basic server hardening and making sure that visitors can't inject things into your PHP forms and results. This is pretty 101 stuff from the admin end, so it shouldn't be a hard thing for them to help out with.
__________________
:not_the_usual1
[you decide]
________________
All in my opinion, which, when combined carefully with a $1 bill, gets you a cup of coffee at the corner store.
Reply With Quote
  #5 (permalink)  
Old 09-12-2005, 03:14 PM
WebProWorld Member
 
Join Date: Aug 2004
Location: Castle Rock, CO
Posts: 67
fisher318 RepRank 0
Default

Ok, I will. Thanks for the help!
__________________
EagleTac Store | HID Flashlights
Reply With Quote
Reply

  WebProWorld > Webmaster, IT and Security Discussion > Internet Security Discussion Forum

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -4. The time now is 05:58 AM.



Search Engine Optimization by vBSEO 3.3.0