Results 1 to 6 of 6

Thread: Using site to Sent Mass Spam Messages

  1. #1
    Join Date
    Sep 2001
    Posts
    180

    Default Using site to Sent Mass Spam Messages

    Today, I have received over 150 messages marked undelivered. Seems like someone is using one of my indexu sites to sent mass spam messages.

    This is a copy of your message, including all the headers. ------

    To:
    Subject: Hello Dear
    From: <erlatb1@yahoo.com>
    X-Mailer: INDEXU_X-Mailer/1.0
    Message-Id: <E1MllBd-0005I7-Ll@cyprus.cyprusexplorer.com>
    Date: Thu, 10 Sep 2009 18:03:49 +0300

    Hello Dear

    My late husband was recently killed in Tagum City Philippine on 22nd May 2008. I am contacting you because I have no other choice than to look for someone who I will trust who will help me by saving the future of my children....


    Any idea how to prevent this?

  2. #2
    Join Date
    Aug 2001
    Location
    Indonesia
    Posts
    3,732

    Default

    Does it send only to you (admin) ?

  3. #3
    Join Date
    Sep 2001
    Posts
    180

    Default

    No, it sents to all members in database. My server is configured messages that have failed to be sent to notifiy me. There are email addresses in database that have changed or unable to receive messages for one reason or another. Now the admin password is quite strong , letters, numbers, capital and small case. How did this person do this?


    Return-path: <nobody@cyprus.cyprusexplorer.com>
    Received: from nobody by cyprus.cyprusexplorer.com with local (Exim 4.69)
    (envelope-from <nobody@cyprus.cyprusexplorer.com>)
    id 1MlsfO-0000uj-Ol
    for dimitriowen@gmail.com; Fri, 11 Sep 2009 02:03:02 +0300
    To: dimitriowen@gmail.com
    Subject: Hello Dear
    From: <erlatb1@yahoo.com>
    X-Mailer: INDEXU_X-Mailer/1.0
    Message-Id: <E1MlsfO-0000uj-Ol@cyprus.cyprusexplorer.com>
    Date: Fri, 11 Sep 2009 02:03:02 +0300

  4. #4
    Join Date
    May 2007
    Location
    NJ, United States
    Posts
    1,651

    Default

    Is this your own dedicated server? Have you checked your server for vulnerabilities? Even if this particular site has now a strong password, if other domains on the server are weak, files can be uploaded to the server to give the spammer complete access to all DB's.
    FSGDAG | IndexU Hosting | Owner
    Website | NiceCoder Script Hosting and More! | Web4URL is For Sale!
    Follow Us On Twitter | FaceBook Profile | YouTube Videos

  5. #5
    Join Date
    Aug 2001
    Location
    Indonesia
    Posts
    3,732

    Default

    Did you also get spam submission? I mean when someone can break the captcha, it is possible to submit [send email] in each detail page. This is the only way to spam indexu users.

    I suggest to use recaptcha instead of default indexu captcha.

  6. #6
    Join Date
    Sep 2001
    Posts
    180

    Default

    Ok, I will try recaptcha

Similar Threads

  1. Mass Changes to Category's
    By FSGDAG in forum INDEXU DELUXE v1.x
    Replies: 5
    Last Post: 11-24-2008, 11:27 PM
  2. Category Mass Edit
    By Bruceper in forum Blocks and Modification
    Replies: 0
    Last Post: 10-30-2007, 02:30 PM
  3. Mass Edit and Claiming Links
    By jovi in forum v5.x
    Replies: 9
    Last Post: 04-14-2007, 01:25 AM
  4. Mass Emailer Hack...!
    By esm in forum v3.2
    Replies: 21
    Last Post: 07-11-2005, 05:35 AM
  5. Mass delete votes and disable ?
    By Frank71 in forum v5.x
    Replies: 0
    Last Post: 02-11-2004, 09:08 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •