منتدى استراحات زايد

منتدى استراحات زايد (http://vb.ma7room.com/index.php)
-   منتدى أخبار المواقع والمنتديات العربية والأجنبية (http://vb.ma7room.com/forumdisplay.php?f=183)
-   -   Spam via sendmessage.php? (http://vb.ma7room.com/showthread.php?t=97967)

محروم.كوم 05-05-2009 02:20 AM

Spam via sendmessage.php?
 
Not sure if this is just a clever spoof, a bug, or a security issue. But, it looks like someone is able to send spam from my install of vB (via the sendmessage.php). I have been getting one or two the following bounced emails every day for a week or so. (I cleaned it of site, domain, and server names).

Quote:
This message was created automatically by mail delivery software.

A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:

[email protected]
SMTP error from remote mail server after RCPT TO::
host bcgsa.com [206.130.110.179]: 550 5.1.1 ... User unknown

------ This is a copy of the message, including all the headers. ------

Return-path:
Received: from SERVERNAME ([127.0.0.1] helo=localhost)
by DOMAINNAME with esmtp (Exim 4.63)
(envelope-from )
id 1M132x-0000od-U4
for [email protected]; Mon, 04 May 2009 13:37:55 -0500
Date: Mon, 04 May 2009 18:37:47 +0000
To: [email protected]
From: "SITENAME"
Auto-Submitted: auto-generated
Message-ID:
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 8bit
X-Priority: 3
X-Mailer: vBulletin Mail via PHP
X-EZbouncer: http://www.DOMAINNAME/admincp/ezbounce.php?u=
Subject: [email protected]
X-Spam-Report: Spam detection software, running on the system "SERVERNAME.DOMAINNAME", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: Della Riley, This is a message from Kayla Trujillo ( mailto:
) from the SITENAME ( http://www.DOMAINNAME/ ). The message is as follows:
[...]
Content analysis details: (-0.2 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
-1.4 ALL_TRUSTED Passed through trusted hosts only via SMTP
2.5 URI_NOVOWEL URI: URI hostname has long non-vowel sequence
-1.3 AWL AWL: From: address is in the auto white-list


Della Riley,

This is a message from Kayla Trujillo ( mailto: ) from the SITENAME ( http://www.DOMAINNAME/ ).

The message is as follows:

38jkwskkr2m1lzdb
tplnh mzfv
http://wjcwhrvwwdtz.com
msxhfpz idyfjga
http://cwzyvgtldb.com


SITENAME takes no responsibility for messages sent through its system.
The usernames (Della Riley and Kayla Trujillo) do not exist (in my user table), nor does the email address: [email protected].

I notice the ( mailto: ) is blank and the userid is missing from: /admincp/ezbounce.php?u=

Thanks for any assistance or insight.

--RayJ


الساعة الآن 10:04 AM

Powered by vBulletin® Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.5.2 TranZ By Almuhajir


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227