PDA

View Full Version : Sendmessage.php Spam


alaska_av8r
10-13-2014, 11:53 PM
I have all email to friend, and anything close to that turned off except for admin and I am still getting bounced messages from spammers that are sending messages from vbulletin. I started noticing 403 errors for some of the spammers, but some in the server log seem to be getting through straight to sendmessage.php and its all from the blog.

Here is a link showing how some folks cured it by removing the code from files, however I need more specific information as to "what code to remove" exactly. http://www.vbulletin.com/forum/forum/vbulletin-3-8/vbulletin-3-8-questions-problems-and-troubleshooting/314981-spam-via-sendmessage-php?p=4016781#post4016781

Can anyone help, I opened a support ticket at vbulletin, but Wayne told me to do what I already had said that I had done. It was as if he didn't even read the ticket.

thanks
tim

ForceHSS
10-14-2014, 12:28 AM
disable guests from sending messages from contact us also check guests user group settings

alaska_av8r
10-14-2014, 10:51 PM
If I do that Force will a person that has problems registering be able to contact me. I have about 1 a week that cannot figure out the registration process.

I have already checked the guest usergroup settings and have all email and send messages turned off.

tim

--------------- Added 1413330818 at 1413330818 ---------------

It appears they are doing a direct access of sendmessage php. I could change the name of that file but I don't know the other files that point to it to edit them as well.

John Lester
10-15-2014, 02:45 AM
Turning off the guest option to "contact us" will prevent them from being able to use the "contact us" link. What I did is create a notice for guests saying if they have trouble registering to please email <address here>.

alaska_av8r
10-15-2014, 09:51 PM
Well what I did so far was on the admincp > settings > options > siteurl page I entered an email address instead of sendmessage.php.

I also changed the name of sendmessage.php to something else, hopefully I can stop this.

ForceHSS
10-16-2014, 12:08 AM
Changing the name won't stop it only disabling it so guests can't use will work. If this is how they are doing it but get in touch with your host ask them to check all logs