tomp
09-03-2005, 04:17 PM
In the last couple of weeks we've seen an alarming trend where spammers are attempting to inject code (SMTP data) into a web based form used by our customers. Just this morning they attempted to exploit our contact form at http://www.myriadnetwork.com/contact/contact.php
The warning signs are pretty clear - the person who is suppose to receive the output of your web based contact form will receive a bunch of emails similar to the following - this is a real example of an attempt against our contact form:
A user just filled in the contact form with the following message:
First Name: msfrtaulu@myriadnetwork.com
Last Name: msfrtaulu@myriadnetwork.com
Email: msfrtaulu@myriadnetwork.com
Content-Type: multipart/mixed; boundary=\"===============1725395920==\"
MIME-Version: 1.0
Subject: be293541
To: msfrtaulu@myriadnetwork.com
bcc: mhkoch321@aol.com
From: msfrtaulu@myriadnetwork.com
This is a multi-part message in MIME format.
--===============1725395920==
Content-Type: text/plain; charset=\"us-ascii\"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
nbvbozeiu
--===============1725395920==--
Phone: msfrtaulu@myriadnetwork.com
Current URL: msfrtaulu@myriadnetwork.com
Interests: msfrtaulu@myriadnetwork.com
Message:
msfrtaulu@myriadnetwork.com
These spammers are making multiple attempts to exploit the form, thus you will typically see multiple emails going to the intended recipient.
If you see something like this PLEASE immediately contact support@myriadnetwork.com and reference this post. We need to immediately investigate all such incidents to determine if your web form is vulnerable.
Most typically we see these spammers exploiting these web based forms to send massive amounts of spam to AOL customers which in turn may get us blocked for a period of time by AOL.
We are investigating further safe guards but we need your assistance.
-Tom
The warning signs are pretty clear - the person who is suppose to receive the output of your web based contact form will receive a bunch of emails similar to the following - this is a real example of an attempt against our contact form:
A user just filled in the contact form with the following message:
First Name: msfrtaulu@myriadnetwork.com
Last Name: msfrtaulu@myriadnetwork.com
Email: msfrtaulu@myriadnetwork.com
Content-Type: multipart/mixed; boundary=\"===============1725395920==\"
MIME-Version: 1.0
Subject: be293541
To: msfrtaulu@myriadnetwork.com
bcc: mhkoch321@aol.com
From: msfrtaulu@myriadnetwork.com
This is a multi-part message in MIME format.
--===============1725395920==
Content-Type: text/plain; charset=\"us-ascii\"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
nbvbozeiu
--===============1725395920==--
Phone: msfrtaulu@myriadnetwork.com
Current URL: msfrtaulu@myriadnetwork.com
Interests: msfrtaulu@myriadnetwork.com
Message:
msfrtaulu@myriadnetwork.com
These spammers are making multiple attempts to exploit the form, thus you will typically see multiple emails going to the intended recipient.
If you see something like this PLEASE immediately contact support@myriadnetwork.com and reference this post. We need to immediately investigate all such incidents to determine if your web form is vulnerable.
Most typically we see these spammers exploiting these web based forms to send massive amounts of spam to AOL customers which in turn may get us blocked for a period of time by AOL.
We are investigating further safe guards but we need your assistance.
-Tom