WebProWorld Part of WebProNews.com
Page One Link To Us Edit Profile Private Messages Archives FAQ RSS Feeds  
 

Go Back   WebProWorld > Webmaster, IT and Security Discussion > Internet Security Discussion Forum
Subscribe to the Newsletter FREE!


Register FAQ Members List Calendar Arcade Chatbox Mark Forums Read

Internet Security Discussion Forum This forum is for the discussion of security related issues. If you find a new Phishing scheme, spyware, virus or malicious site - let us know about it. If any of the above found you... here's where you ask for help.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 11-26-2005, 10:20 PM
WebProWorld Member
 

Join Date: Jun 2004
Posts: 35
asya RepRank 0
Default Help!! My mailbox has been hijacked

This is a little unnerving. This morning, I logged on to my site's default mailbox, and found there were 354 messages waiting for me. They were all Mail Delivery Notices from my server.

Apparently, someone has used my mail id to send around 354 (or more if they actually made it to some inboxes) spam emails around the web.

This is bizzare! I am considering putting up an apology on my homepage for people who have been badgered with this nuisance, but what else can I do? I certainly cannot allow this to happen for the second time. Please advise!!!
Reply With Quote
  #2 (permalink)  
Old 12-05-2005, 10:31 AM
netman4ttm's Avatar
WebProWorld Veteran
 

Join Date: Aug 2003
Location: Virginia
Posts: 386
netman4ttm RepRank 1
Default

Use sender policy frame work


http://www.openspf.org/
__________________
"The future is here. It's just not evenly distributed.
Reply With Quote
  #3 (permalink)  
Old 12-06-2005, 05:05 PM
dharrison's Avatar
Moderator
WebProWorld Moderator
 

Join Date: May 2005
Location: Essex, UK
Posts: 1,424
dharrison RepRank 3dharrison RepRank 3
Default

Hi Asya

Can I 1st of all ask what type of communication you use on your website: an email address direct on your website or a CGi form script called formmail.pl from MSA?

If its a direct mail link, can I suggest that you rethink and use an enquiry form? It won't stop the amount of spam you receive altogether but it should reduce it considerably.

If, however, its the formmail problem, then go back to the site where you got it from and try downloading the latest version. If its the site I'm thinking it is, they recommend that you download a new version on a regular basis as this reduces any potential misuse. Or even try renaming it eg m2me1.pl

I have had this problem a couple of times in the past as a result of both of these factors. Although email link did tend to result in excessive spam mail rather than the misuse you are experiencing.

HTH
__________________
Deb Harrison
DVH Design
Essex Web Design | Web Design Blog
Reply With Quote
  #4 (permalink)  
Old 12-07-2005, 02:19 PM
kgun's Avatar
WebProWorld 1,000+ Club
 

Join Date: May 2005
Location: Norway
Posts: 5,124
kgun RepRank 3kgun RepRank 3
Default The easy solution

write your email address on a picture and embed that on the site.

If you use a form, use PHP. The hard solution. Encrypt the communication.

If it is a emailharvesting bot, make a script that returns 1 million random email addresses. May be the last time they try.
Reply With Quote
  #5 (permalink)  
Old 12-21-2005, 06:21 AM
WebProWorld Member
 

Join Date: Dec 2005
Posts: 66
blinded RepRank 0
Default

change password and try to check your system with antyspy ware pro. like norton or outpost.
__________________
WwW.LookForLinks.Com
Reply With Quote
Reply

  WebProWorld > Webmaster, IT and Security Discussion > Internet Security Discussion Forum
Tags: , , ,



Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Search Engine Optimization by vBSEO 3.2.0