PDA

View Full Version : PM system spam attack


Rich99
01-11-2014, 09:00 AM
Hii all. Yet another a spam attack. Although the registration has stopped, and Ive disabled the PM system, somehow im still getiing covered in spa, through the Private Message's. Im getting this:

"Subject: Re:Urgent security update
From: "AV@icosiphci1983.com" <AV@icosiphci1983.com>
Message-ID: <20140103142324.f191dafdfb40@>
MIME-Version: 1.0
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 8bit
X-Priority: 3
X-Mailer: vBulletin Mail via PHP
Date: Sun, 05 Jan 2014 11:09:06 -0600

Dear User
We hasten to inform you that your PC is at risk of infection with the new generation
Please urgently update system to install the update.

Just download and run the update will be installed automatically.
Thank you for your attention
http://fREMOVED.pp.ua/pc.php"

Like i said, ive closed the PM system, yet somehow the user is still sending them out. Any ideas? Should i just remove the PHP script that runs the PM system? Or should i do a re-install? Just nothing i can do about this right now, very frustrating.

kh99
01-11-2014, 10:05 AM
You say it's through the PM system but that looks like an email. If you're continuing to get emails, it could be that they're in the queue. If you look at the admincp main page, in the "Welcome to the vBulletin Admin Control Panel" panel, the last number on the right tells you how many emails are queued.

Rich99
01-15-2014, 05:09 PM
Number of Queued E-Mails 75,288

good grief! what can i possibly do to stop this?

kh99
01-15-2014, 05:33 PM
Well, you could truncate the mailqueue table in the database, but if you do you'll also lose any legitimate emails. If you know a little sql you can probably come up with a query that will only delete the spam (if there's some keyword in the subject or body you can use).

Also, in the admincp under Email Options, you might want to increase the "Number of Emails to Send Per Batch" (although if someone sent tens of thousands of spam messages, maybe you won't need to increase it once those are gone).

ForceHSS
01-16-2014, 12:45 AM
the contact us would be best if you dont allow guests to use this option