Nexology Community
 
     
 
   

Go Back   Nexology Community > Nexus Zone > News and Announcements

Reply
 
LinkBack Thread Tools Display Modes
Old 04-16-2002, 09:27 AM   #1
HN Top Canine
 
NexDog's Avatar
 
Join Date: Jan 2002
Location: The Nexus
Posts: 13,347
Exclamation The war on Spam

The war on spam is long and arduous and we are going to start getting tough. Obvious people signing up for the cheapest plan and immediately mailbombing happens every now and then but they are caught quickly and measures are taken.

There is another problem: Formmail.

At the moment spam is relaying through Beta particularly heavily. Alpha seems to have quietened down a little but the spam is still there.

This is everyone's problem!

Spam will slow the mail server down and enough spam gets through, it's only a matter of time until our IPs get blacklisted. Spammers are exploiting your formmail scripts, in particular Matt's Archive Formmail 1.6. If you are using this script, upgrade to 1.9 immediately. 1.6 is totally exploitable.

There are 97 instances of formmail on Alpha and 42 on Beta. Alot are Matt's scripts. It's time to start locking down these scripts. Upgrading that script, if you have it, will help.

If you have a custom script, you should send it to us for a security review.
__________________
Laurence - [HostNexus Administrator]

- Need Support? Quickest reponses are found at the Support Helpdesk!
- Stay in touch! Make sure you are subscribed to our Lists.
NexDog is offline   Reply With Quote
Old 04-16-2002, 09:52 AM   #2
Registered User
 
Join Date: Mar 2002
Location: chicago
Posts: 425
I don't have any form mail installed but I used to use alienform. Are you aware of any problems with that program before I set it up?
mobstory is offline   Reply With Quote
Old 04-16-2002, 11:27 AM   #3
Fox
I ain't no llama...
 
Fox's Avatar
 
Join Date: Jan 2002
Location: Michigan USA
Posts: 1,137
Is our very own HN Mike's Simple Form a problem at all?
__________________
Fox
I get by with a lotta help from my friends...

Twitter Spirit

Say Hello to U.P. North Michigan

Visit Pine Stump

Old Thoughts
Fox is offline   Reply With Quote
Old 04-16-2002, 12:22 PM   #4
Registered User
 
miro's Avatar
 
Join Date: Jan 2002
Location: USA
Posts: 302
Quote:
it's only a matter of time until our IPs get blacklisted
I have already had email bounce more than once from spam-blockers
__________________
* * * * * * * * * * * *
I wonder as I wander.
miro is offline   Reply With Quote
Old 04-16-2002, 04:54 PM   #5
VP of Bottled Water
 
smort's Avatar
 
Join Date: Apr 2002
Location: OC California
Posts: 14
I had bounced email with my PREVIOUS web host due to their being blacklisted. I've had no problems here with email, and don't use form mail. I'm not even sure what that is!
__________________
"I'm not 40-something. I'm $39.95 plus shipping and handling."

-----

www.smort.com
www.thewritingfreak.com
smort is offline   Reply With Quote
Old 04-16-2002, 09:45 PM   #6
HN Tech Support
 
Mike's Avatar
 
Join Date: Jan 2002
Location: Detroit USA
Posts: 3,060
Thumbs up

Fox and Everyone Else,

The SimpleForm CGI script available here is reasonably secure. I had built in spam protection when I made it.

- Mike
Mike is offline   Reply With Quote
Old 04-17-2002, 05:34 AM   #7
NetPrism IT
 
Nelix's Avatar
 
Join Date: Mar 2002
Location: Tasmania, Aust
Posts: 1,473
Any chance of an Official PHP formail script any time soon???
__________________
Cheers Adrian
__________________
Nelix is offline   Reply With Quote
Old 04-17-2002, 07:15 AM   #8
HN Top Canine
 
NexDog's Avatar
 
Join Date: Jan 2002
Location: The Nexus
Posts: 13,347
Not PHP but Matt's Archive Scripts Formail ver1.9 is secure for now.
__________________
Laurence - [HostNexus Administrator]

- Need Support? Quickest reponses are found at the Support Helpdesk!
- Stay in touch! Make sure you are subscribed to our Lists.
NexDog is offline   Reply With Quote
Old 04-17-2002, 08:17 AM   #9
NetPrism IT
 
Nelix's Avatar
 
Join Date: Mar 2002
Location: Tasmania, Aust
Posts: 1,473
my formail is setup so that it doesnt have a receipant email address field - it is just sent to my email address.
could this still mean ppl could u it for spamming???
__________________
Cheers Adrian
__________________
Nelix is offline   Reply With Quote
Old 04-17-2002, 08:12 PM   #10
Registered User
 
Darkman's Avatar
 
Join Date: Apr 2002
Location: Sydney, Oz
Posts: 1,006
Matt's Archive Formmail has been revised for PHP as well, and its secure as well... its avaiable to download...
Darkman is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 06:41 AM.


Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.0 RC1
Copyright ©2001 - 2009, HostNexus