Home Private Messages Search
CPG Dragonfly™ CMS Dedicated Server & Bandwidth Sponsored by DedicatedNOW
Toggle Content
 
Forums ⇒ CMS (All) ⇒ Security :: Archives ⇒ mail viruses :: Archived


mail viruses :: Archived
Post any security related questions in here.
Please send discovered reports to security @ cpgnuke.com
Do Not post links to exploits or hacker sites - your post will be edited/deleted.
If you think you've been hacked, FIRST go through your server logs.

Post new topic    Revive this topic    Printer Friendly Page     Forum Index ⇒  Security

Topic Archived View previous topic :: View next topic  
Author Message
kiggga
Nice poster
Nice poster

Offline Offline
Joined: Dec 15, 2004
Posts: 72

PostPosted: Thu Jul 14, 2005 1:36 pm
Post subject: mail viruses

I was previously using the 9.0.4 version with the mail vulnerability. i did the upgrade to fix the problem, but i am receiving emails with viruses that have my website's name in the To field. is this a problem with the mail vulernability from the previous version? and can i stop these emails from coming in?


kiggga's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
linux/apache 1.3.33 (unix) mysql 4.0.22-standard/php 4.3.11/dragonly 9.0.4
Back to top
View user's profile Visit poster's website Photo Gallery
Mystic
Diamond Supporter
Diamond Supporter

Offline Offline
Joined: Jun 25, 2004
Posts: 1312
Location: Spokane, WA USA
PostPosted: Thu Jul 14, 2005 2:53 pm
Post subject: Re: mail viruses

Your address may already be "out there" and the mail is now self-propogating and not coming from your site each time.

Filters may be your best bet. Then again, I'm no expert.

_________________
- |\/|ystic

Mystic's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.6.20-16/Apache/5.0.38/5.2.1/9.0.6.1
Back to top
View user's profile ICQ Number AIM Address Yahoo Messenger
kiggga
Nice poster
Nice poster

Offline Offline
Joined: Dec 15, 2004
Posts: 72

PostPosted: Thu Jul 14, 2005 6:24 pm
Post subject: Re: mail viruses

that could be true...
its bad.. the emails come from mail @ mysite.com, admin @ mysite.com, etc.. and they all say similar things and have a zip file virus attachment in it..

i guess i can filter all email that comes from my domain name.. but that stinks.. lol


kiggga's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
linux/apache 1.3.33 (unix) mysql 4.0.22-standard/php 4.3.11/dragonly 9.0.4
Back to top
View user's profile Visit poster's website Photo Gallery
norbie
Silver Supporter
Silver Supporter

Offline Offline
Joined: Jun 29, 2004
Posts: 737
Location: Norbie's World
PostPosted: Thu Jul 14, 2005 7:23 pm
Post subject: Re: mail viruses

I had the same problem for a while.

It's probably completely unrelated to Dragonfly CMS.

The Mytob worm was on one of my user's computers, and it cleverly looked at the last visited website from Internet History (my site) to 'spoof' my domain name. <-- Making it look as if the emails were from me!

It can be taken care of quite easily if the ISP is helpful.

You need to see the Message Headers of the emails so you can see the originating IP address of the email. If you're using Outlook, you can see this via View -> Options. I think. Or something like that. Do a quick search for 'email headers' in outlook's help.

Once you have found the IP address in the email header, you can do a WHOIS search for it to find the ISP of that computer.

Try doing a WHOIS search at www.ripe.net and www.apnic.net and www.arin.net first.

Let me know if you have any problems Wink

_________________
Norbie

www.norbiesworld.co.uk

norbie's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux / Apache Custom Version / 4.0.26-standard (client: 5.0.15) / 4.4.4 / 9.1.1
Back to top
View user's profile Send e-mail Visit poster's website MSN Messenger
tank
Gold Supporter
Gold Supporter

Offline Offline
Joined: Apr 20, 2004
Posts: 824
Location: Houston, Texas USA
PostPosted: Thu Jul 14, 2005 9:14 pm
Post subject: Re: mail viruses

I would agree that it's unrelated to DF. It's indicative of most mail viruses to spread that way.

_________________
Search is your friend

tank's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Fedora Core 1, Apache 1.3.33, Mysql 4.1.14, PHP 5.0.5 w/ APC cache, Dragonfly 9.0.6.1
Back to top
View user's profile Visit poster's website
Display posts from previous:   
Post new topic    Revive this topic    Printer Friendly Page    Forum Index ⇒  Security
Page 1 of 1
All times are GMT

Archive Revive
Username:
This is an archived topic - your reply will not be appended here.
Instead, a new topic will be generated in the active forum.
The new topic will provide a reference link to this archived topic.
 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Fixed .ico Expires header.
· Removed domain name from cookies so subdomains wont access them anymore.
· CSS and JS, case insensitives.
· CSS and JS, send correct HTTP 1.1 headers and fixed issues where themes and...
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.

閱讀詳細內容...

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy