Home Private Messages Search
CPG Dragonfly™ CMS Dedicated Server & Bandwidth Sponsored by DedicatedNOW
Toggle Content
 
Forums ⇒ CMS (All) ⇒ Security ⇒ Spam being sent from my domain - is it DragonFly?


Spam being sent from my domain - is it DragonFly?
Post any security related questions in here.
Please send discovered reports to security @ cpgnuke.com
Do Not post links to exploits or hacker sites - your post will be edited/deleted.
If you think you've been hacked, FIRST go through your server logs.

Go to page 1, 2  Next
Post new topic    Reply to topic    Printer Friendly Page     Forum Index ⇒  Security

View previous topic :: View next topic  
Author Message
rosbif
500+ Posts Club
500+ Posts Club

Offline Offline
Joined: Jan 13, 2005
Posts: 593
Location: Paris, France
PostPosted: Wed Dec 23, 2009 9:10 pm
Post subject: Spam being sent from my domain - is it DragonFly?

I am suddenly receiving 50-60 emails bounced back to me per hour from my domain where I have DragonFly hosted. My host support (Site5) is telling me it is a script on my index.html page that has a security hole. They think it is the 'send to a friend' link being used.

Here is the reply from my host:

Quote::
X-PHP-Script: www.chantillyexpat.com/index.php for 200.177.228.4

I have checked this site and it looks like you have "send to a friend"
links on your articles. It appears that this is being abused to send out a large amount of messages. Are all of the bouncebacks trying to be sent to marketingexpert @ krim.ws or are they to random email addresses? Thanks. Here are the logs of the message being sent from the server:

2009-12-23 13:45:44 1NNX9O-00086Z-NN <= chantill @ milton.site5.com U=chantill P=local S=1064 id=0aebd4e2c99732724736ca7e14443728@www.chantillyexpat.com
2009-12-23 13:45:46 1NNX9O-00086Z-NN ** marketingexpert @ krim.ws R=lookuphost T=remote_smtp: SMTP error from remote mail server after RCPT TO:<marketingexpert@krim.ws>: host mx1.hqhost.net
[88.214.192.192]: 550 5.1.1 <marketingexpert@krim.ws>... User unknown
2009-12-23 13:45:46 1NNX9W-000888-Eo <= <> R=1NNX9O-00086Z-NN U=mailnull P=local S=2052
2009-12-23 13:45:47 1NNX9O-00086Z-NN Completed

He also said:

Quote::
The spam is definitely originating from the script running on your site at index.php. It is possible that there is a security hole in the application that is allowing remote users to send spam. I would suggest updating the script and any plug-ins/modules to the latest versions.

Any ideas?


rosbif's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
ChantillyExpat.com - Others-
Back to top
View user's profile Visit poster's website
Dizfunkshunal
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Mar 23, 2006
Posts: 2064

PostPosted: Wed Dec 23, 2009 9:27 pm
Post subject: Re: Spam being sent from my domain - is it DragonFly?

can you send me a copy of you index.php? pm it do not post it in the forums.


and i can see all your debug info which should only be seen by admin !!!
error in template.

_________________
Diz Web Design Status: Open (Use of resources requires registration.)

Dizfunkshunal's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Multiple Setups
Back to top
View user's profile Send e-mail Visit poster's website Yahoo Messenger
rosbif
500+ Posts Club
500+ Posts Club

Offline Offline
Joined: Jan 13, 2005
Posts: 593
Location: Paris, France
PostPosted: Wed Dec 23, 2009 9:31 pm
Post subject: Re: Spam being sent from my domain - is it DragonFly?

done


rosbif's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
ChantillyExpat.com - Others-
Back to top
View user's profile Visit poster's website
Dizfunkshunal
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Mar 23, 2006
Posts: 2064

PostPosted: Wed Dec 23, 2009 9:45 pm
Post subject: Re: Spam being sent from my domain - is it DragonFly?

disable the Tell a friend module until you can put captcha in it or set it to registered users only. index.php is fine at least i didn't see anything out of sorts.

Send to a friend in news to

_________________
Diz Web Design Status: Open (Use of resources requires registration.)

Dizfunkshunal's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Multiple Setups
Back to top
View user's profile Send e-mail Visit poster's website Yahoo Messenger
rosbif
500+ Posts Club
500+ Posts Club

Offline Offline
Joined: Jan 13, 2005
Posts: 593
Location: Paris, France
PostPosted: Wed Dec 23, 2009 9:47 pm
Post subject: Re: Spam being sent from my domain - is it DragonFly?

My Tell a Friend has captcha already. I presume I need to remove the link to 'send to a friend' from the articles?

My host has blocked the IP address that was sending these emails and I've done the same in DF. Is there anything else I can do?


rosbif's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
ChantillyExpat.com - Others-
Back to top
View user's profile Visit poster's website
Dizfunkshunal
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Mar 23, 2006
Posts: 2064

PostPosted: Wed Dec 23, 2009 9:48 pm
Post subject: Re: Spam being sent from my domain - is it DragonFly?

Send to a friend in the news

there not stupid spammers i mean they use proxy or zombies.

_________________
Diz Web Design Status: Open (Use of resources requires registration.)

Dizfunkshunal's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Multiple Setups
Back to top
View user's profile Send e-mail Visit poster's website Yahoo Messenger
Dizfunkshunal
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Mar 23, 2006
Posts: 2064

PostPosted: Wed Dec 23, 2009 9:51 pm
Post subject: Re: Spam being sent from my domain - is it DragonFly?

send me your_theme/templates/ footer.html to so i can fix the bottom.

_________________
Diz Web Design Status: Open (Use of resources requires registration.)

Dizfunkshunal's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Multiple Setups
Back to top
View user's profile Send e-mail Visit poster's website Yahoo Messenger
rosbif
500+ Posts Club
500+ Posts Club

Offline Offline
Joined: Jan 13, 2005
Posts: 593
Location: Paris, France
PostPosted: Wed Dec 23, 2009 9:51 pm
Post subject: Re: Spam being sent from my domain - is it DragonFly?

SO I need to edit some file to stop the send to a friend link?


rosbif's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
ChantillyExpat.com - Others-
Back to top
View user's profile Visit poster's website
Dizfunkshunal
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Mar 23, 2006
Posts: 2064

PostPosted: Wed Dec 23, 2009 9:52 pm
Post subject: Re: Spam being sent from my domain - is it DragonFly?

or add captcha to it im not sure how to add the captcha but you could comment out the send a friend links

What theme are you using?

_________________
Diz Web Design Status: Open (Use of resources requires registration.)

Dizfunkshunal's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Multiple Setups
Back to top
View user's profile Send e-mail Visit poster's website Yahoo Messenger
rosbif
500+ Posts Club
500+ Posts Club

Offline Offline
Joined: Jan 13, 2005
Posts: 593
Location: Paris, France
PostPosted: Wed Dec 23, 2009 10:08 pm
Post subject: Re: Spam being sent from my domain - is it DragonFly?

I've removed the link from the template file for now. No idea how to add a captcha to it. This seems a pretty serious hole!


rosbif's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
ChantillyExpat.com - Others-
Back to top
View user's profile Visit poster's website
rosbif
500+ Posts Club
500+ Posts Club

Offline Offline
Joined: Jan 13, 2005
Posts: 593
Location: Paris, France
PostPosted: Wed Dec 23, 2009 10:10 pm
Post subject: Re: Spam being sent from my domain - is it DragonFly?

I've pm'd you my footer too. What's up with that??


rosbif's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
ChantillyExpat.com - Others-
Back to top
View user's profile Visit poster's website
Dizfunkshunal
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Mar 23, 2006
Posts: 2064

PostPosted: Wed Dec 23, 2009 10:57 pm
Post subject: Re: Spam being sent from my domain - is it DragonFly?

all the debug info at bottom should only be seen by admin not everyone
fixed and sent back
I think there is a thread running around here that shows how to add captcha.

_________________
Diz Web Design Status: Open (Use of resources requires registration.)

Dizfunkshunal's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Multiple Setups
Back to top
View user's profile Send e-mail Visit poster's website Yahoo Messenger
rosbif
500+ Posts Club
500+ Posts Club

Offline Offline
Joined: Jan 13, 2005
Posts: 593
Location: Paris, France
PostPosted: Thu Dec 24, 2009 9:49 am
Post subject: Re: Spam being sent from my domain - is it DragonFly?

Thanks Diz.. I've removed the link to send a friend and renamed the friend.php file but I am still getting bounced back messages - 150 overnight so I dread to think how many got through...

What else can I do?


rosbif's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
ChantillyExpat.com - Others-
Back to top
View user's profile Visit poster's website
Dizfunkshunal
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Mar 23, 2006
Posts: 2064

PostPosted: Thu Dec 24, 2009 3:37 pm
Post subject: Re: Spam being sent from my domain - is it DragonFly?

You removed the ability to tell a friend. All you really can do now is figure out how to add captcha. this thread might help you dragonflycms.org/Forum...t=captcha/

_________________
Diz Web Design Status: Open (Use of resources requires registration.)

Dizfunkshunal's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Multiple Setups
Back to top
View user's profile Send e-mail Visit poster's website Yahoo Messenger
NanoCaiordo
Developer
Developer

Offline Offline
Joined: Jun 29, 2004
Posts: 3878
Location: Melbourne, AU
PostPosted: Sat Dec 26, 2009 5:43 am
Post subject: Re: Spam being sent from my domain - is it DragonFly?

PHP installed on your server its already patched with php mail headers but its not picking up the correct file.
Quote::
X-PHP-Script: www.chantillyexpat.com/index.php for 200.177.228.4

Try to use the attached includes/classes/phpmailer.php at least you will know which file is actually been abused.

This file will be included in 9.2 and 10.

_________________
.:: I met php the 03 December 2003 :: Unforgettable day! ::.

Linux 64bit / Apache 2.2 / PHP 5.4 / MySQL 5.5.22 / v9, v10
Linux 32bit / Apache 2.2 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10
Windows 64bit / IIS 7.5 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10


NanoCaiordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
mixed
Back to top
View user's profile Visit poster's website Photo Gallery
Display posts from previous:   
Post new topic    Reply to topic    Printer Friendly Page    Forum Index ⇒  Security
Page 1 of 2
All times are GMT
Go to page 1, 2  Next



Jump to:  


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum


 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Fixed .ico Expires header.
· Removed domain name from cookies so subdomains wont access them anymore.
· CSS and JS, case insensitives.
· CSS and JS, send correct HTTP 1.1 headers and fixed issues where themes and...
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.

devamı...

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy