Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 2 of 2
  1. #1
    Member
    Join Date
    Jan 2003
    Posts
    169

    Default cpanel formmail exploit?

    hi,

    a number of customers have reported receiving bounced emails like this one:

    bewgrock%aol.com@www.domain.com.au

    169P Received: from kajavi by myservername.au with local (Exim 3.36 #1)
    id 193Scf-0003vP-00
    for bewgrock%aol.com@www.domain.com.au; Thu, 10 Apr 2003 13:21:09 +1000
    039T To: bewgrock%aol.com@www.domain.com.au
    034F From: webmaster@www.domain.com.au
    047 Subject: www.domain.com.au/cgi-sys/formmail.pl
    056I Message-Id:
    038 Date: Thu, 10 Apr 2003 13:21:09 +1000


    193Scf-0003vP-00-D
    body: FormMail Test: Test 3 "recipient=user%yourdomain.com@thisdomain.com"


    and I can see in the mail queue numerous frozen messages like that .. anyone know what's going on? Is this some sort of exploit?

  2. #2
    Moderator cPanel Partner NOC Badge dgbaker's Avatar
    Join Date
    Sep 2002
    Location
    Toronto, Ontario Canada
    Posts
    2,773

    Default

    A search of this forum will reveal a wealth of information.

Similar Threads & Tags
Similar threads

  1. FormMail-clone.cgi [was: Security spam hole in cgi-sys/formmail.pl re-write]
    By cpanelnick in forum cPanel and WHM Discussions
    Replies: 175
    Last Post: 04-05-2011, 05:00 AM
  2. mod_security blocking formmail... and formmail SPAM
    By wilfried in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 06-09-2006, 01:29 AM
  3. CPanel Exploit
    By buccaneerob in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 01-17-2005, 08:52 PM
  4. Formmail.pl exploit again...
    By websnail in forum cPanel and WHM Discussions
    Replies: 9
    Last Post: 08-08-2003, 10:13 AM
  5. formmail exploit
    By carperman in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 04-03-2002, 04:00 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube