Results 1 to 8 of 8

Thread: INI file issue

  1. #1
    Join Date
    Apr 2007
    Posts
    4

    Default INI file issue

    Hi,

    I recently implemented Formmail ver 7.14 and used the INI file to hide my "send to" email from spammers. I placed the formmail.ini file into the /_private folder so it can't be seen by humans or read by bots. I also created a brand new, never used email address for use in the INI which does not use any "catch all" features. Nowhere in my website is the new email address appear. The install tested great, but within the hour I started receiving porn spam. How could this be if a bot cannot access the INI file containing the address?

    Thanks In Advance For Any Insight.

  2. #2
    Join Date
    Dec 2003
    Posts
    3,980

    Default Re: INI file issue

    Hi,

    What sort of spam? Is it direct email or spam submitted via the form?

    If it's direct email, then I think the possibilities are:
    1. The _private folder isn't protected. Can you open the INI file via a browser?
    2. The email address you used is something that could be guessed. Spammers often just send to common names in the "hope" that such an address exists.
    3. If you're on a shared hosting system, perhaps someone has logged into the computer via Telnet or SSH and just grabbed the email address directlry out of the INI file.
    Russell Robinson - Author of Tectite FormMail and FormMailDecoder
    http://www.tectite.com/

  3. #3
    Join Date
    Apr 2007
    Posts
    4

    Default Re: INI file issue

    Thanks for your earlier reply,

    It's submitted via the form I guess. It includes form information like name, email address (bogus), and message body. The body contains the same set of porn related links each time. Seems like an awful lot of work for such a small gain.

    1. The _private folder is secure. Can't see the INI from a browser, unless you securely logon.

    2. The email receive address is: registerme@ , not terribly common.

    3. No shared hosting, no one else has access.

    Thanks Again,

  4. #4
    Join Date
    Dec 2003
    Posts
    3,980

    Default Re: INI file issue

    Hi,

    If it's form spam, then they haven't got your email address....they're just submitting bogus forms.

    Upgrade to version 7.15 and and enable the ATTACK_DETECTION_MANY_URLS and/or ATTACK_DETECTION_MANY_URL_FIELDS settings.

    You need to read about these settings to some extent before setting them. Read the documentation above the settings.
    Russell Robinson - Author of Tectite FormMail and FormMailDecoder
    http://www.tectite.com/

  5. #5
    Join Date
    Apr 2007
    Posts
    4

    Thumbs up Re: INI file issue

    Thanks Russell,

    I changed the ATTACK DETECTION MANY section and it halted the spams.
    You've got a great product.

    Thanks Again

  6. #6
    Join Date
    Mar 2007
    Posts
    26

    Default Re: INI file issue

    you should add the image verify CAPTCHA too, that can get rid of form abuse by spammers.

  7. #7
    Join Date
    Apr 2007
    Posts
    4

    Default Re: INI file issue

    I did add CAPTCHA, and it worked great in testing. The website owner thought it would annoy potential clients. He may have me implement it in the future if the porn link issue resurfaces, but since the spam has dropped to zero, he's holding off.

    Thanks,

    Roger

  8. #8
    Join Date
    Mar 2007
    Posts
    26

    Default Re: INI file issue

    i edited my CAPTCHA just to have 4 characters with a smaller neater box, also with the noise away from the characters, so not to annoy visitors so much but still implement it for a little added security.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Required Fields Issue
    By sportess in forum FormMail Subscription Support
    Replies: 3
    Last Post: 06-Oct-2005, 08:10 PM
  2. MAC OS X issue - anyone else having trouble?
    By Anasazi in forum FormMail Subscription Support
    Replies: 0
    Last Post: 27-Apr-2005, 07:54 PM
  3. good_template issue, please advise...
    By nhouse in forum FormMail Subscription Support
    Replies: 4
    Last Post: 08-Mar-2005, 08:56 PM
  4. Form attachments - encoding issue
    By mark70 in forum FormMail Subscription Support
    Replies: 5
    Last Post: 06-Oct-2004, 07:45 PM
  5. file upload issue - everything else is perfect.
    By baergnat in forum FormMail Subscription Support
    Replies: 3
    Last Post: 20-Sep-2004, 08:02 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •