SitePoint Sponsor

User Tag List

Results 1 to 7 of 7

Thread: Spamming

  1. #1
    SitePoint Addict
    Join Date
    Aug 2004
    Location
    Norway
    Posts
    355
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Spamming

    Someone have recently started spamming on my forum and it all looks like its coming from my email address and my site.

    This is the message and the headers
    Return-path: <mb83947e@bne009m.server-mail.com>
    Envelope-to: admin(at)librarium-online.com
    Delivery-date: Thu, 13 Oct 2005 08:18:28 -0400
    Received: from librariu by interblaster.phantom.site5.com with local-bsmtp (Exim 4.52)
    id 1EQ22V-0006s6-Di
    for admin(at)librarium-online.com; Thu, 13 Oct 2005 08:18:28 -0400
    X-Spam-Checker-Version: SpamAssassin 3.1.0 (2005-09-13) on
    interblaster.phantom.site5.com
    X-Spam-Level:
    X-Spam-Status: No, score=-2.6 required=5.0 tests=BAYES_00 autolearn=ham
    version=3.1.0
    Received: from [203.147.165.55] (helo=bne009m.server-mail.com)
    by interblaster.phantom.site5.com with smtp (Exim 4.52)
    id 1EQ22U-0006r6-Rl
    for admin(at)librarium-online.com; Thu, 13 Oct 2005 08:18:27 -0400
    Received: (qmail 2271 invoked by uid 21857); 13 Oct 2005 12:18:20 -0000
    Date: 13 Oct 2005 12:18:20 -0000
    Message-ID: <20051013121820.2270.qmail@bne009m.server-mail.com>
    Content-Type: TEXT/PLAIN; charset=US-ASCII
    To: admin(at)librarium-online.com
    From: junk@klik.to (junk)
    Subject: Re: New Private Message at Librarium Online
    X-Antivirus-Scanner: This message has been scanned by ClamAV - CLEAN.
    and the message

    Hey You got the wrong address but maybe you should check out http://www.GMAIL.COM.AU
    Is there something I can do? and please move this to the right topic if I have posted it in the wrong forum.

    Thanks

  2. #2
    Compulsive Clubber icky_bu's Avatar
    Join Date
    Aug 2003
    Location
    Portugal
    Posts
    351
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Paste those headers at www.spamcop.com and let it figure out where the spam is coming from, then try alert the ISP envolved. Might not result in anything because spoofing nowadays is top notch, but it could help.

    Wish you luck

  3. #3
    Programming Team silver trophybronze trophy
    Mittineague's Avatar
    Join Date
    Jul 2005
    Location
    West Springfield, Massachusetts
    Posts
    17,189
    Mentioned
    191 Post(s)
    Tagged
    2 Thread(s)

    spam from self

    I seriously doubt if gmail is the spammer. My bet is that this was a test of your contact form's security. You should ensure that Bcc headers can't be added to the Email Address input field and passed into the send mail script.

  4. #4
    Compulsive Clubber icky_bu's Avatar
    Join Date
    Aug 2003
    Location
    Portugal
    Posts
    351
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Who said anything about gmail? Look closer at the address: gmail.com.au
    Nothing to do with google.

  5. #5
    Programming Team silver trophybronze trophy
    Mittineague's Avatar
    Join Date
    Jul 2005
    Location
    West Springfield, Massachusetts
    Posts
    17,189
    Mentioned
    191 Post(s)
    Tagged
    2 Thread(s)

    google

    Quote Originally Posted by icky_bu
    Who said anything about gmail? Look closer at the address: gmail.com.au
    Nothing to do with google.
    Who said anything about google? Take a closer look at the page at that address:
    PLEASE NOTE THAT GMAIL.COM.AU IS NOT IN ANYWAY CONNECTED TO GOOGLE OR THE GOOGLE PRODUCT GMAIL.
    The point of my last post is that most likely the contact form was being tested to see if it could be used to send spam, not that it was used to send spam from gmail(.com.au), although that is possible too. Do you know that gmail.com.au is not legitimate? Maybe they could be reported or sued?

  6. #6
    SitePoint Addict
    Join Date
    Aug 2004
    Location
    Norway
    Posts
    355
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I have gotten this a few times before also. How can I check if the gmail au is legitimate?

  7. #7
    Programming Team silver trophybronze trophy
    Mittineague's Avatar
    Join Date
    Jul 2005
    Location
    West Springfield, Massachusetts
    Posts
    17,189
    Mentioned
    191 Post(s)
    Tagged
    2 Thread(s)

    legit?

    A few times before? That makes me think they are using your form to send spam from your server. A uwhois search does not give any information, and there are conflicting opinions in online forum discussions. http://www.computerforum.com/showthread.php?t=22736
    http://forums.whirlpool.net.au/forum...fm/404883.html
    I guess you could report your suspicions to the AUDA
    If they are only pestering you to use their email service, and it's not so much of a priority as it is an annoyance, then I would do as icky_bu suggested and report them, try to block them, and hope for the best.


Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •