Community Forums
Connect with us on LinkedIn
Closed Thread
Page 1 of 12 1 2 3 11 ... LastLast
Results 1 to 15 of 176
  1. #1
    cPanel Staff cpanelnick's Avatar
    Join Date
    Feb 2003
    Location
    Houston, TX
    Posts
    4,597

    Default FormMail-clone.cgi [was: Security spam hole in cgi-sys/formmail.pl re-write]

    Please update to

    EDGE 4
    RELEASE 5
    or
    STABLE 6

    as soon as possible to close a hole in FormMail-clone.cgi which will allow spammers to send out unwanted email.

    If you do not wish to update you can install a patched binary from:

    http://host.cpanel.net/~nick/FormMail-clone.bin
    into
    /usr/local/cpanel/cgi-sys/FormMail-clone.cgi

    -rwxr-xr-x 4 root wheel 533384 May 18 17:51 formmail.cgi*
    -rwxr-xr-x 4 root wheel 533384 May 18 17:51 FormMail.cgi*
    -rwxr-xr-x 1 root wheel 533384 May 18 17:51 FormMail-clone.cgi*
    -rwxr-xr-x 4 root wheel 533384 May 18 17:51 formmail.pl*
    -rwxr-xr-x 4 root wheel 533384 May 18 17:51 FormMail.pl*


    make sure to replace all formmail scripts

  2. #2
    Member Hoster2k's Avatar
    Join Date
    Jun 2002
    Location
    UK
    Posts
    131

    Default

    they were using formmail.pl with me. Looking at the file sizes though are they all exactly the same thing, FormMail.pl, formmail.pl, FormMail.cgi etc

  3. #3
    Member rpmws's Avatar
    Join Date
    Aug 2001
    Location
    back woods of NC, USA
    Posts
    1,858

    Default

    Just grabbed edge 4.

    tailing logs .. saw hit .. saw mail leave ..panic for 10 seconds ...see mail was legit still watching. Looks like the legit use is still working. That's a plus!!! so far so good. Thank's Nick!
    Just keeping my "eye" on things....
    R. Paul Mathews
    RPMWS - diehard cPanel Nutcase

  4. #4
    Member
    Join Date
    Feb 2002
    Location
    UK
    Posts
    461

    Default

    nick, upgraded to the latest version and now WHM news does not appear in the WHM any more.
    Apache to die or not to die, that is the question...

  5. #5
    cPanel Staff cpanelnick's Avatar
    Join Date
    Feb 2003
    Location
    Houston, TX
    Posts
    4,597

    Default

    Originally posted by SoftmegUK
    nick, upgraded to the latest version and now WHM news does not appear in the WHM any more.
    relax and reload.. it was being updated

  6. #6
    Member
    Join Date
    Feb 2002
    Location
    UK
    Posts
    461

    Default

    lol im relaxed now
    Apache to die or not to die, that is the question...

  7. #7
    cPanel Staff cpanelnick's Avatar
    Join Date
    Feb 2003
    Location
    Houston, TX
    Posts
    4,597

    Default

    Originally posted by rpmws
    Nick ??? is it really you??? thank you GOD!!!! thank you!!!!!!!!!!!!! Now fix Exim from hanging on to local email for hours for no reason so I don't have to run /scripts/newexim every day

    Catch me on aim (cpanelnick) and I should be able to help you out with that.

  8. #8
    Member
    Join Date
    Jan 2002
    Location
    UK
    Posts
    248

    Default

    Originally posted by bdraco
    Catch me on aim (cpanelnick) and I should be able to help you out with that.
    If you'd like to share that, I'm sure we'd all love to know

  9. #9
    Member
    Join Date
    Nov 2002
    Posts
    242

    Default

    I've updated 1 server just fine... but I just tried updating a second server with /scripts/upcp and it is hanging on the following:-

    ..Done
    webmail.....Done
    static-stunnel...........Done
    imap..........Done
    formmail.....Done
    imp.....


    Anything I should be doing here?

  10. #10
    Member
    Join Date
    Nov 2002
    Posts
    242

    Default

    Also,

    I have done the manual stable update, but its given me release...

    now that is weird.

  11. #11
    Member
    Join Date
    Apr 2002
    Posts
    254

    Default

    eesh...perhaps I jumped the gun this morning, but I just disabled the scripts. I hated to do that to our users, however, seems like every other week, there is a new issue with the formmail.

  12. #12
    Member rpmws's Avatar
    Join Date
    Aug 2001
    Location
    back woods of NC, USA
    Posts
    1,858

    Default

    ah ha!!!! hehe

    /cgi-sys/formmail.plbcc:BEWGROCK@aol.comContent-Type HTTP/1.1" 404 -


    since the upcp

    cPanel.net Support Ticket Number:
    Just keeping my "eye" on things....
    R. Paul Mathews
    RPMWS - diehard cPanel Nutcase

  13. #13
    Member
    Join Date
    Jun 2002
    Posts
    137

    Default

    Originally posted by rpmws
    ah ha!!!! hehe

    /cgi-sys/formmail.plbcc:BEWGROCK@aol.comContent-Type HTTP/1.1" 404 -


    since the upcp

    cPanel.net Support Ticket Number:

    i got the exactly same address "BEWGROCK@aol.com" sending mails....

    luckily, it was fixed pretty fast.

    cPanel.net Support Ticket Number:

  14. #14
    Member rpmws's Avatar
    Join Date
    Aug 2001
    Location
    back woods of NC, USA
    Posts
    1,858

    Default

    Originally posted by torwill
    i got the exactly same address "BEWGROCK@aol.com" sending mails....

    luckily, it was fixed pretty fast.

    cPanel.net Support Ticket Number:
    It's the same SOB that has been hitting us all for months. We should all figure out a way to get him really bad like ban him from all our boxes. Nick should block him with the next upcp for everyone so he can't reach half the internet.

    cPanel.net Support Ticket Number:
    Just keeping my "eye" on things....
    R. Paul Mathews
    RPMWS - diehard cPanel Nutcase

  15. #15
    Member
    Join Date
    Jan 2003
    Posts
    276

    Default

    Hello!

    I followed some earlier instructions for this problem and did the following.

    cd /usr/local/cpanel/cgi-sys
    chmod 700 formmail.pl
    chmod 700 FormMail.pl
    chmod 700 formmail.cgi
    chmod 700 FormMail.cgi
    chmod 700 FormMail-clone.cgi

    Can someone please let me know what it should be chmoded to to make the scripts work again??

    Thanks

    cPanel.net Support Ticket Number:
    www.ccccanada.com
    Web and Server Hosting

Closed Thread
Page 1 of 12 1 2 3 11 ... LastLast
Similar Threads & Tags
Similar threads

  1. What type of formial is this?? (cgi-sys/formmail.cgi)
    By wimp in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 10-07-2003, 10:23 AM
  2. formmail.cgi files desapeared few hours ago from /cgi-sys !!
    By manokiss in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 05-26-2003, 09:22 PM
  3. Security spam hole in cgi-sys/formmail.pl re-write
    By andyf in forum cPanel and WHM Discussions
    Replies: 161
    Last Post: 05-18-2003, 05:10 PM
  4. cgi-sys/FormMail.cgi
    By sketchified in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 08-05-2002, 10:06 PM
  5. How to del /sys-cgi/FormMail.cgi Function ??
    By hkewell in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 07-26-2002, 09:45 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube