vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Modification Requests/Questions (Unpaid) (https://vborg.vbsupport.ru/forumdisplay.php?f=112)
-   -   Email Exploits using "Nobody" fix? (https://vborg.vbsupport.ru/showthread.php?t=69982)

Illuvatar 09-29-2004 05:08 AM

Email Exploits using "Nobody" fix?
 
We've been getting exploited by folks sending spam as us (and some pretty serious ones too..like that Paypal thing pfbbt) using "Return-Path: <nobody@valinor.warofthering.net>", which we can prevent at the server level by not allowing mail to be sent from "Nobody"

The problem is that VB uses this for all off it's notifications, and when blocked, the notifies to not go out period.

My question is....and I really hope that this can be done....is can the VB code be modified so that the return path uses a valid email address to it's system..like Illuvatar@warofthering.net which is the webmaster email in the admin panel.

I really don't like getting threatned with legal action because of this, and I also don't want to stop my users from taking full advantage of the boards, so if anybody else has run into this and could help me out, it would sure help me out!

Thanks!

PS....this is the same post that I made over at vb.com and they said that VB can be hacked "slightly" to use SMTP for the mail, but that they of course cannot support it.

So....I'm posting it here...hehe......

Can anyone help a fella out? :ermm:

Zachery 09-29-2004 11:25 AM

Quote:

Originally Posted by Illuvatar
We've been getting exploited by folks sending spam as us (and some pretty serious ones too..like that Paypal thing pfbbt) using "Return-Path: <nobody@valinor.warofthering.net>", which we can prevent at the server level by not allowing mail to be sent from "Nobody"

The problem is that VB uses this for all off it's notifications, and when blocked, the notifies to not go out period.

My question is....and I really hope that this can be done....is can the VB code be modified so that the return path uses a valid email address to it's system..like Illuvatar@warofthering.net which is the webmaster email in the admin panel.

I really don't like getting threatned with legal action because of this, and I also don't want to stop my users from taking full advantage of the boards, so if anybody else has run into this and could help me out, it would sure help me out!

Thanks!

PS....this is the same post that I made over at vb.com and they said that VB can be hacked "slightly" to use SMTP for the mail, but that they of course cannot support it.

So....I'm posting it here...hehe......

Can anyone help a fella out? :ermm:

https://vborg.vbsupport.ru/showthread.php?t=67294

:)

Illuvatar 09-29-2004 01:26 PM

Quote:

Originally Posted by Zachery

Thanks Zach! :)


All times are GMT. The time now is 01:00 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01659 seconds
  • Memory Usage 1,718KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (2)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (3)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete