LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 06-23-2015, 05:15 PM   #1
pittendrigh
Member
 
Registered: Jun 2014
Posts: 32

Rep: Reputation: Disabled
Spam email attempts


I have a CentOS virtual dedicated server.
I also have a home rolled email form that nulls out the RepyTo CC and BCC headers and aborts during POST processing if the "from" field has more than one address. POST processing aborts on a half a dozen other suspicious conditions too. Any subsequent email that is actually sent is hard-coded to go to me only.

Still, about a half a dozen times a month I get email similar to the following. Somehow I doubt this exploits my email form because, if and when my codes ever do get to the actual "mail" stage my codes pre-pend certain hidden text to the posted message, only one line of code before the send function call.

When I see email like this my pre-pended text is never part of the message. So if my form isn't to blame how are they doing this? Why are some parts gibberish and some parts well-formed? I have a hunch I'd still get this mail, every now and then, even if I erased my email form. But of course I could be wrong. Perhaps I will take the form away for a month or so, and simply print an image of my email address. If I still got mail like this then, I'd know for sure.

mailTo: http://oltvtrfpzsok.com/
zjB9p0 <a href="http://xzrooovikdie.com/">xzrooovikdie</a>,
baovhcibaupu,
[link=http://rafqccefiizp.com/]rafqccefiizp[/link],
http://rwfjnuffwyuq.com/

Last edited by pittendrigh; 06-23-2015 at 05:20 PM.
 
Old 06-24-2015, 02:17 PM   #2
joe_2000
Senior Member
 
Registered: Jul 2012
Location: Aachen, Germany
Distribution: Void, Debian
Posts: 1,016

Rep: Reputation: 308Reputation: 308Reputation: 308Reputation: 308
Can't you just compare the email's timestamp to your webserver log and see if your contact form had a hit at that point in time? If you are lucky and it's a user agent easily distinguishable from legitimate visitors you might even be able to htaccess-block it...
 
Old 06-24-2015, 02:33 PM   #3
pittendrigh
Member
 
Registered: Jun 2014
Posts: 32

Original Poster
Rep: Reputation: Disabled
Good idea
Next time I'll look
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Spam or not spam email? linustalman Linux - Security 1 08-25-2014 09:43 AM
email sent to spam mad_penguin Linux - Newbie 2 10-25-2012 11:45 PM
attempts to email unknown user hammering sendmail rwilcher Linux - Enterprise 11 10-22-2009 02:37 PM
SELinux Errors when a PHP program attempts to send out email poorboyiii Fedora 3 02-28-2008 06:18 PM
Spam email mickeyboa Fedora 10 08-23-2005 11:39 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 04:04 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration