Help - Search - Members - Calendar
Full Version: My Website Is Sending Out Spam Emails.
BleepingComputer.com > Internet & Networking > Web Site Development
   
Matthew Alan
I'm running 3 Fusion News, 1 CopperMine Photo gallery, a phpBB forum, a SMF forum, a MyBB forum, and a custom index.php?id=.

I need to know what is most likely causing this. My host said it was most likely a exploited PHP script, but I don't want/need to go and delete everything. Here is teh IM I had with him:

QUOTE
(09:30:40 AM) ME: hey
(09:32:50 AM) ME: Are you there?
(09:33:56 AM) HOST: Mmhmm...your account has been suspended...either it has been compromised or you are sending spam.
(09:34:18 AM) ME: I dont even use cPanel main, and whats compromised?
(09:34:32 AM) HOST: I don't know - it's not my job to find that out
(09:34:38 AM) HOST: all I know is...your account was sending spam
(09:34:39 AM) ME: I did noticed I got some kind of email about Reply **SPAM** but I thought it was a bot
(09:34:44 AM) HOST: either via an exploited PHP script
(09:34:49 AM) ME: hmmm
(09:34:53 AM) HOST: or some other way
(09:35:05 AM) ME: only php im running is Fusion, and a photo gallery and they dont have a send email feature
(09:35:22 AM) HOST: does't matter
(09:35:26 AM) ME: yeah I know
(09:35:27 AM) HOST: anything can be exploited to send spam
(09:35:43 AM) ME: im just trying to pin what it was.
(09:36:30 AM) HOST: well it's been unsuspended
(09:36:39 AM) HOST: update your scripts
(09:36:42 AM) ME: THanks, ill uninstall all php scripts, and check my coding
(09:36:49 AM) HOST: ok
(09:37:05 AM) ME: sorry about it, ill also delete all email forwarders
(09:37:12 AM) HOST: okay
(09:37:18 AM) HOST: you can proably keep the forwarders
(09:37:23 AM) HOST: they are probably not causing anything
(09:37:28 AM) HOST: i will just let you know if i see anything happen
(09:37:34 AM) ME: thanks
(09:39:41 AM) ME: I dont know if it means anything, but this is the email called RE: **SPAM** I got:
Dear User Thank you for your email. Due to training, we will reply to your enquiry within 5 working days. MBS apologises for any inconvenience this may cause.
(09:39:53 AM) HOST: weird
(09:39:59 AM) HOST: you can probably ignore that


So anybody know what its most likely?
Jim M.
Are you sure you have the most up to date versions of each public script (phpBB and the others)? If so it might be a script you wrote. Do you have any type of contact form? This could be a mail injection attack.
Aldark
That happened to me several years ago. I was told I was spamming pr0n and my acct was blocked. I argued up and down with the (crap)host and I told them that their security was the issue - which later turned out to be the case.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.