Results 1 to 4 of 4

Thread: Notice from my webhost: FormMail being used to spam [RESOLVED: NOT FORMMAIL]

  1. #1
    Join Date
    Apr 2008
    Posts
    11

    Default Notice from my webhost: FormMail being used to spam [RESOLVED: NOT FORMMAIL]

    Edited to correct: THE ERROR WAS NOT CAUSED BY FORMMAIL. An older version of Joomla! was compromised.


    This is the message I've received today from my web host:

    Your account "xxx.com" hosted on server xxxxxxxx.xxx.com is sending out bulk/spam mails and violated our TOS by sending more than 1000 mails per hour. Mails were sent using by the account ops@deta.kz via authentication method. Please check the following for more details.

    2012-03-05 17:28:49 1S4gOf-0007pa-Gf ** gertraud-john@web.de <Gertraud-John@web.de> R=enforce_mail_permissions: Domain dragonmyth.com has exceeded the max emails per hour (1250/1000 (125%)) allowed. Message discarded.

    ad nauseum

    It seems like one of your script is outdated and hackers have exploited it to upload/run vulnerable scripts in the server.

    We had no choice, but to disable offending script and removed all mails in queue from your account.

    Please make sure that your scripts are upto date and not exploited to prevent these kind of issues from happening again.
    =======================

    Okay, from day one (almost from the first hour of use) this script has been hit by spammers and I get numerous script (captcha) failure notices each week. Now, I get this delightful message from my host.

    How can this be fixed? How was it exploited in the first place?

    TIA
    Dami
    Last edited by Dami; 07-Mar-2012 at 12:19 AM. Reason: Must CORRECT

  2. #2
    Join Date
    Mar 2004
    Posts
    2,224

    Default Re: Notice from my webhost: FormMail being used to spam

    mmmmmmm.....

    i've been lurking here for squillions of years and no one has ever reported an exploit in tectite formmail as far as i can remember

    i've used it for years too and never had a problem.

    so, first question: do u know for sure it was tectite formmail that was used?

    if so, more questions:
    • do u have other formmail scripts on ur website?
    • have u altered tectite formmail outside its config section?
    • tectite formmail only sends to the limited email addresses u specified (except for autorespond), so have u setup TARGET_EMAIL properly.
    i know tectite offer guaranteed support, so u might want to buy some support and get it investigated. i think the guarantee means if there's a bug, u get ur money back (and the problem fixed)

  3. #3
    Join Date
    Apr 2008
    Posts
    11

    Default Notice from my webhost: FormMail being used to spam CORRECTION: IT IS NOT FORMMAIL!!

    Thanks for posting, crabtree. I'm checking now with my web host. In the initial email, they just said they'd disabled "the" script without bothering to say which one--unless they just wholesale disabled everything.


    FOUND THE PROBLEM. An older version of Joomla was compromised and IT WAS NOT FORMMAIL!

    Sorry for the false alarm. I am curious how people found my form so fast to spam it.

  4. #4
    Join Date
    Mar 2004
    Posts
    2,224

    Default Re: Notice from my webhost: FormMail being used to spam

    thx for posting back the results.

    all formmail users (and esp tectite) will be glad u confirmed this!

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Spam coming through FormMail
    By daymobrew in forum Community Support
    Replies: 3
    Last Post: 25-Mar-2011, 11:51 PM
  2. Formmail seen as spam
    By HappyCamper in forum Community Support
    Replies: 1
    Last Post: 23-Feb-2011, 06:01 AM
  3. Replies: 15
    Last Post: 25-Feb-2010, 12:50 AM
  4. Help - Potential SPAM with formmail.php
    By fullfocus in forum Community Support
    Replies: 2
    Last Post: 23-Mar-2006, 09:20 PM
  5. PHP FormMail blocked by webhost
    By Mystic_Bovine in forum FormMail Subscription Support
    Replies: 4
    Last Post: 27-Oct-2005, 11:25 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •