Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 10-11-2012, 02:35 AM
doob doob is offline
 
Join Date: Dec 2009
Posts: 127
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default spam being sent through Email To Friend - can't stop it

I've disabled Email to Friend for all usergroups and spam is still being sent out from our server.

I am getting bounce backs on undeliverable mail, otherwise I wouldn't even know it was going on. Here's the message being sent out. Please help if you have any experience with this. Thanks!

MIME-Version: 1.0
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 8bit
X-Priority: 3
X-Mailer: vBulletin Mail via PHP
Date: Wed, 10 Oct 2012 20:30:48 -0700

tricia casellini,

This is a message from Sarah4443 ( mailto: ) from the Travelers411 Travel Forums - Travel Deals - Travel Radio Shows. Ask Questions Get Answers! ( http://www.travelers411.com/forums/ ).

The message is as follows:

I made $89.99 last week by filling out 7 surveys!
They only took 12 mins each
Check it out http://removed by doob
Reply With Quote
  #2  
Old 10-11-2012, 03:15 AM
Brandon Sheley's Avatar
Brandon Sheley Brandon Sheley is offline
 
Join Date: Mar 2005
Location: Google Kansas
Posts: 4,678
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

might want to edit out that last link, and don't click it
Reply With Quote
  #3  
Old 10-11-2012, 03:48 AM
doob doob is offline
 
Join Date: Dec 2009
Posts: 127
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thanks for the suggestion, I changed the spammer's link to "removed by doob".

I'm guessing that other VB boards are being hit by the same spam since its obviously a whole in the forum's security.

I'd love to talk with other 3.8 ers to see what they've done to protect against this. My guess is its an sql injection of some sort as I don't think the messages are even being sent by a registered user.
Reply With Quote
  #4  
Old 10-11-2012, 03:55 AM
ForceHSS ForceHSS is offline
 
Join Date: Apr 2008
Posts: 6,357
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

there is a few place in user groups to turn it off make sure you get them all also turn off contact us for guests
Reply With Quote
  #5  
Old 10-11-2012, 04:19 AM
doob doob is offline
 
Join Date: Dec 2009
Posts: 127
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

In AdminCP -> Usergroups ->Usergroup Manager - Usergroup what besides "Can Use Email to Friend" should be turned off?

Is contact-us a likely culprit? Unlike "Email to a Friend", "Contact-Us" is hardwired to only send to a specific email.
Reply With Quote
  #6  
Old 10-11-2012, 04:54 AM
WEBDosser's Avatar
WEBDosser WEBDosser is offline
 
Join Date: Oct 2001
Location: @ MyPC
Posts: 824
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

it's not possible by just turning everything off, i had this a few weeks ago and i was getting hundreds+++ of emails bounced back just like yours..

It is a hack you have installed or a pluggin but i don't know which one as i had lost it with trying to stop them i just took the forum down deleted ALL the files and the database and started again.
Reply With Quote
  #7  
Old 10-11-2012, 06:16 AM
doob doob is offline
 
Join Date: Dec 2009
Posts: 127
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

No products installed and only a few hand coded plugins none of which immediately looks like it would have anything to do with the mail system.
Reply With Quote
  #8  
Old 10-11-2012, 08:11 AM
kh99 kh99 is offline
 
Join Date: Aug 2009
Location: Maine
Posts: 13,185
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I don't know if it's a security hole or what, but I think the option you want to set in the usergroup manager is "Can Email Members" in the General Permissions section. "Can Use Email to Friend" has to do with the "Email this page" link, according to the help for that option.

If you still have the problem you might try looking at your web server logs. If someone's using a security hole to spam all users, it seems like it should be easy to spot.
Reply With Quote
  #9  
Old 10-11-2012, 08:29 AM
doob doob is offline
 
Join Date: Dec 2009
Posts: 127
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Believe I ticked off "Can Email Members' for all groups too, but will double check in the morning.

Based on the mailer-daemon bounce backs I looked at none of the recipients or senders were members. I only looked at a statistically valid sample though, not all of them (there were over a thousand at least).

That's what made me think it was a hole in the Email to a Friend. I'll have to do more research either way, but please keep the suggestions coming.
Reply With Quote
  #10  
Old 10-11-2012, 08:40 AM
kh99 kh99 is offline
 
Join Date: Aug 2009
Location: Maine
Posts: 13,185
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by doob View Post
Based on the mailer-daemon bounce backs I looked at none of the recipients or senders were members.
Well, I guess what I mean is that if many emails are being sent out, then it should show up in the logs as many requests to a single file from the same ip, so you might be able to spot that and see which php file is being used.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 11:44 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.03959 seconds
  • Memory Usage 2,252KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete