vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB4 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=251)
-   -   Email Spam! (https://vborg.vbsupport.ru/showthread.php?t=297013)

CPWerks 04-09-2013 03:26 AM

Email Spam!
 
I've been getting 100's of these emails throughout the last 24 hours and I have no clue what to do! I completely disabled the contact us option from my forum, I even banned the IP associated with this emails from the site yet I still keep getting these random emails. Does anyone have any other suggestions?

Quote:

The following message was sent to you via the XXX Contact Us form by ouiqfeyv ( mailto:sample@email.tst ).

--------------------------------

20

--------------------------------

Referring Page:
IP Address: 114.77.63.103
User Name: Unregistered
User ID: 0
Email: sample@email.tst
Quote:

The following message was sent to you via the XXXX Contact Us form by irskpjiw ( mailto:sample@email.tst ).

--------------------------------

20" or (sleep(4)+1) limit 1 --



--------------------------------

Referring Page:
IP Address: 114.77.63.103
User Name: Unregistered
User ID: 0
Email: sample@email.tst
Thanks guys.

Bluemax712 04-09-2013 03:58 AM

Maybe they are faking your Contact Us form and connecting directly to your Email Server port 25 to deliver the message - that way a normal .htaccess block on the Web Server page wouldn't help.

Can you contact your Web Host to try and block the IP from entire server?

CPWerks 04-09-2013 04:06 AM

It's possible. I did contact them and they did ban the IP a few hours ago but I am getting email still as I type this. This is driving me crazy! =/

Bluemax712 04-09-2013 04:12 AM

You can try changing the Contact Us email to something different - like a temp email account
to see if the messages show up there - at least you will know if they are using the form or not.

Also - do you know how to read all the email headers? ( it's usually not shown in most email clients by default)
-to verify where the message came from

CPWerks 04-09-2013 04:18 AM

Hmm, okay let me try that. By the way, had 1200 emails Queued, disabled the flood check and increased the number of emails per batch to 500. Queued emails are down to 0 and Im still getting emails. Though they're from about 30 minutes ago. Let's see if they stop now that nothing is in the queue.

Bluemax712 04-09-2013 04:27 AM

1200! - they sound pretty desperate to contact you
maybe it's an important sale on Nike Shoes or Ipads
you don't want to miss out

CPWerks 04-09-2013 04:27 AM

LOL tell me about it.

ForceHSS 04-09-2013 05:31 PM

Don't let guests use the contact us


All times are GMT. The time now is 05:55 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01095 seconds
  • Memory Usage 1,725KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (2)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (8)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete