Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 7 of 7
  1. #1
    Member
    Join Date
    Apr 2005
    Posts
    9

    Default Contact Us form hijacked?

    Hi Guys,

    My client has a contact us type of form where fields are entered
    and then emailed to the client via some php code.

    But they are receiving 20-30 emails a day from the form containing
    random generated data as if someone or something is dumping
    random data to it as if they are trying to use it for spam.

    I have looked in the access logs and can see the contact us form
    being accessed as well as the php form, but am unsure whats legit
    and whats not.

    How can I stop this? Is there a way?

    Roger.

  2. #2
    Member
    Join Date
    Apr 2003
    Posts
    174
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    You could try one of those image verification things, where the user has to enter the text from a randomly generated image into the form - though I have no idea how to make them

  3. #3
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Dec 2004
    Posts
    392

    Default

    hey

    In the domains logs try see if there is an IP address repeat lots of times trying to access the form.
    Just stick that ip address in the iptables rules and ban the spammer.

    What type of form is it ?
    Are you using the cpanel encrypted formail function or another one (version 1.92 or something like that)??

    Try change the name of the file(formmail), and update your you code to use it.

    cheers
    Andy
    UK Managed Hosting
    UK Linux Support
    The information given above is intended to be advice only.

  4. #4
    Member dory36's Avatar
    Join Date
    Aug 2003
    Posts
    179

    Default

    I have several dozen "contact us" forms on sites I have done, and almost all are getting this stuff.

    The messages all look similar - every field is filled in with the same seemingly random string, followed by "@" and the domain name where the contact us page resides. (My standard "contact us" form requires a properly formatted email address in one of the fields, so there may be many attempts for every one that gets through.

    It is annowing, but it seems to be a couple of dozen messages (per form) and then no more.

  5. #5
    Member
    Join Date
    Feb 2005
    Posts
    147

    Default

    I have an image verification script I made in php, that I intend to release opensource if you need it.

    I would suggest finding one of those forms, and throwing in php code that logs the IP of the submitter, then banning that ip in your firewall as it seems some script kiddie is simply using a tool to automatically fill these out.

    Just an idea.
    - Paul Shepperd
    4 years cpanel exp. 6 years linux exp. 8 years security exp.
    6 years corporate startup/small business exp.
    If I responded, and you want to IM me you can do so, not saying I will for sure have time to help, but my aim is public, thats what its there for. My email is: ME @ pshepperd.com
    " Life is short, make money, and have a good time, live every day to its fullest."

  6. #6
    Member dory36's Avatar
    Join Date
    Aug 2003
    Posts
    179

    Default

    Thanks Paul. Good idea.

    I added the following to the mail being sent to the site owner when someone fills out these forms:


    $Message .= "The inquiry originated at IP address ". $_SERVER['REMOTE_ADDR'] . ".\n\nIf you are getting multiple bogus messages from the same IP address, please forward one or more samples to (my support email), and we will investigate, and possibly block that IP address.\n\n" ;

  7. #7
    BANNED
    Join Date
    Jul 2005
    Posts
    537

    Default

    Try using the formmail.php script from http://tectite.com. It the best formmail script around. If you want, you can install the image verification modification.

Similar Threads & Tags
Similar threads

  1. Need help with Contact form
    By fullspec in forum cPanel and WHM Discussions
    Replies: 9
    Last Post: 04-09-2011, 10:35 AM
  2. Contact Form Mail Address
    By trentbaby in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 05-02-2010, 10:45 PM
  3. PHP Contact Form
    By smithindia8 in forum E-mail Discussions
    Replies: 3
    Last Post: 02-03-2010, 05:51 AM
  4. SPAM sent from php contact form...
    By fred123123 in forum cPanel and WHM Discussions
    Replies: 15
    Last Post: 11-22-2005, 02:43 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube