Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 7 of 7
  1. #1
    Member
    Join Date
    May 2003
    Posts
    32

    Default Auto-generated Spam from Cpanel

    Hi,

    All domains on our server reveived many similar automatically generated spam email (i.e. from an email address to the same email address) with nonsense message. The email looks like this:



    -------------------
    Return-path: <domain@my.server.com>
    Envelope-to: Ok5cj2@domain.com
    Delivery-date: Fri, 29 Aug 2003 21:01:10 -0500
    Received: from domain by my.server.com with local (Exim 4.20)
    id 19sv38-0007PG-E8
    for Ok5cj2@domain.com; Fri, 29 Aug 2003 21:01:10 -0500
    To: Ok5cj2@domain.com
    From: Ok5cj2@domain.com
    Subject: http://www.domain.com/cgi-sys/formmail.pl (200.71.42.92:80) bcc: bagnallb@aol.com39b1ENHLY z5WXSqZq EqPLje8 vxFmHz6 x c56 nQcF9vPcciOg796p WeRNnsAfz v oimd1iE7sZuM uOjEjH2 ssFÿFFFFCCabcdefghijklmnopqrstuvqxyzABCDEFGHIJKLMNO.
    Message-Id: <E19sv38-0007PG-E8@my.server.com>
    Date: Fri, 29 Aug 2003 21:01:10 -0500
    --------------------



    Does anyone have the same problem? How to fix it?

    "domain.com" does not use FormMail script for email.

    Any ideas?

    cPanel.net Support Ticket Number:
    Last edited by jdan6@2003; 08-30-2003 at 05:00 PM.

  2. #2
    Registered User
    Join Date
    Aug 2003
    Posts
    2

    Default

    i got the same thing on one of my accounts.

    cPanel.net Support Ticket Number:

  3. #3
    Member nyjimbo's Avatar
    Join Date
    Jan 2003
    Location
    New York
    Posts
    1,105

    Angry

    Same here.

    This email "bagnallb@aol.com " concerns me alot.



    cPanel.net Support Ticket Number:
    "A dog has raised it’s hind leg on the age of nevermore !"
    -- Rolf

  4. #4
    FWC
    FWC is offline
    Member
    Join Date
    May 2002
    Location
    Ontario, Canada
    Posts
    354

    Default

    In Tweak Settings in WHM check:

    Silently Discard all FormMail-clone requests with a bcc: header in the subject line

  5. #5
    Member Stefaans's Avatar
    Join Date
    Mar 2002
    Location
    Vancouver, Canada
    Posts
    445

    Default

    So it seems to be not "automatically generated" spam e-mail. Rather it's a real-live attempt to use your cgi-sys/formmail scripts!

    There has been a lot of talk on the Forum regarding this that will show you how to disable it if you want to. The option to diable the BCC's seems to fix the latest vulnerability.

    cPanel.net Support Ticket Number:

  6. #6
    FWC
    FWC is offline
    Member
    Join Date
    May 2002
    Location
    Ontario, Canada
    Posts
    354

    Default

    Originally posted by Stefaans
    There has been a lot of talk on the Forum regarding this that will show you how to disable it if you want to. The option to diable the BCC's seems to fix the latest vulnerability.
    Vulnerability is a bit strong. The BCC trick doesn't work. The emails don't get sent off server. The Tweak just prevents the local delivery of the failed attempts.

  7. #7
    Member
    Join Date
    Feb 2003
    Location
    Sachse, TX
    Posts
    567

    Default

    Agreed. It's not even a vulnerability.

    Just a test/probe of your services much like fraudsters would do a test/fake new account signup.... Think people.

    Brenden

    cPanel.net Support Ticket Number:

Similar Threads & Tags
Similar threads

  1. Spam Injection, generated on fake emails
    By tangowebs in forum New User Questions
    Replies: 1
    Last Post: 03-31-2010, 03:43 PM
  2. Invalid CSRs generated with cPanel
    By mholt in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 01-13-2009, 09:11 AM
  3. Change the way UIDs are generated
    By webebo in forum E-mail Discussions
    Replies: 0
    Last Post: 08-27-2007, 08:41 AM
  4. Where/How do stats get generated
    By jrehmer in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 09-11-2006, 05:20 PM
  5. using sitestudios java/jdk for cpanel generated domain
    By Harryhood in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 08-26-2005, 07:33 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube