Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 05-18-2003, 01:09 PM   #1
psyko514
See sig. Join Epic Cash.
 
Join Date: Oct 2002
Location: Montreal, Quebec. ICQ: 214702014
Posts: 22,366
Need help RE: Spam... what's all this mean?

First, I got an email like this:

BEGINABCDFORMMAIL*MYDOMAIN*.com/cgi-sys/formmail.plTSTSendMailTSTENDABCD

where *MYDOMAIN* is one of my domain names.

and then approx 300 emails similar to this:

The original message was received at Sun, 18 May 2003 07:05:10 -0400 (EDT)
from server10.webhost.com [66.XXX.XXX.212]


*** ATTENTION ***

Your e-mail is being returned to you because there was a problem with its delivery. The address which was undeliverable is listed in the section labeled: "----- The following addresses had permanent fatal errors -----".

The reason your mail is being returned to you is listed in the section labeled: "----- Transcript of Session Follows -----".

The line beginning with "<<<" describes the specific reason your e-mail could not be delivered. The next line contains a second error message which is a general translation for other e-mail servers.

Please direct further questions regarding this message to your e-mail administrator.

--AOL Postmaster



----- The following addresses had permanent fatal errors -----
<[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>

----- Transcript of session follows -----
... while talking to air-yb03.mail.aol.com.:
>>> RCPT To:<[email protected]>
<<< 550 jusev IS NOT ACCEPTING MAIL FROM THIS SENDER
550 <[email protected]>... User unknown
>>> RCPT To:<[email protected]>
<<< 550 MAILBOX NOT FOUND
550 <[email protected]>... User unknown
>>> RCPT To:<[email protected]>
<<< 550 MAILBOX NOT FOUND
550 <[email protected]>... User unknown
>>> RCPT To:<[email protected]>
<<< 550 MAILBOX NOT FOUND
550 <[email protected]>... User unknown
>>> RCPT To:<[email protected]>
<<< 550 MAILBOX NOT FOUND
550 <[email protected]>... User unknown
>>> RCPT To:<[email protected]>
<<< 550 jusenuf00 IS NOT ACCEPTING MAIL FROM THIS SENDER
550 <[email protected]>... User unknown
>>> RCPT To:<[email protected]>
<<< 550 MAILBOX NOT FOUND
550 <[email protected]>... User unknown
__________________

Bad Girl Bucks
- 50% Revshare through CCBill.
Promote BrandyDDD, Pixie's Pillows, Action Allie and more!

Phoenix Forum Pics | Webmaster Access Montreal pics
email: psyko514(a)gmail.com | icq: 214-702-014
psyko514 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-18-2003, 01:12 PM   #2
psyko514
See sig. Join Epic Cash.
 
Join Date: Oct 2002
Location: Montreal, Quebec. ICQ: 214702014
Posts: 22,366
now it seems to me somebody is not only using my server to send out spam, but they're using me as a reply-to address as well, so i'm getting all the bounced emails? am i correct?
__________________

Bad Girl Bucks
- 50% Revshare through CCBill.
Promote BrandyDDD, Pixie's Pillows, Action Allie and more!

Phoenix Forum Pics | Webmaster Access Montreal pics
email: psyko514(a)gmail.com | icq: 214-702-014
psyko514 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-18-2003, 01:14 PM   #3
Why
MFBA
 
Industry Role:
Join Date: Mar 2003
Location: PNW
Posts: 7,230
it has to do with the headers in your formmail, the email that all errors and bounces to is yours so they are all coming to you.

if you need help securing this hit me on icq.
Why is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-18-2003, 01:15 PM   #4
psyko514
See sig. Join Epic Cash.
 
Join Date: Oct 2002
Location: Montreal, Quebec. ICQ: 214702014
Posts: 22,366
ok, nevermind, problem solved:
found this amongst all the bounced spam:

"There has been a security hole found that allows formail to be used by unauthorized persons. In effect allowing spam to be sent from your domain. This hole is found in the following scripts."
__________________

Bad Girl Bucks
- 50% Revshare through CCBill.
Promote BrandyDDD, Pixie's Pillows, Action Allie and more!

Phoenix Forum Pics | Webmaster Access Montreal pics
email: psyko514(a)gmail.com | icq: 214-702-014
psyko514 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-18-2003, 01:18 PM   #5
vending_machine
Confirmed User
 
Join Date: Jun 2002
Location: Seattle
Posts: 1,062
Quote:
Originally posted by psyko514
ok, nevermind, problem solved:
found this amongst all the bounced spam:

"There has been a security hole found that allows formail to be used by unauthorized persons. In effect allowing spam to be sent from your domain. This hole is found in the following scripts."
Yeah, get the latest formmail script and replace the one you have. The old ones have a serious security hole that spammers love
vending_machine is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.