Spammer Been Spamming My Contact forms

Discussion in 'Site & Server Administration' started by rederick, Feb 14, 2006.

  1. #1
    Hi I have alot of contact forms on various websites. I have been tracking this for a few months I have been getting Quite alot of Spam From my contact forms from this ip

    61.152.169.27

    using the email "greet@hotmail.com"

    Should I just block IP from the server? I really don't want to have to add code to all my contact forms.

    Thanks.
     
    rederick, Feb 14, 2006 IP
  2. digitalpoint

    digitalpoint Overlord of no one Staff

    Messages:
    38,334
    Likes Received:
    2,613
    Best Answers:
    462
    Trophy Points:
    710
    Digital Goods:
    29
    #2
    Just block it.
     
    digitalpoint, Feb 14, 2006 IP
  3. Colleen

    Colleen Illustrious Member

    Messages:
    6,777
    Likes Received:
    725
    Best Answers:
    1
    Trophy Points:
    430
    #3
    rederick, you would just have to put the code to block the ip address in the .htaccess file of all your websites, not much work really.
     
    Colleen, Feb 14, 2006 IP
    bentong likes this.
  4. digitalpoint

    digitalpoint Overlord of no one Staff

    Messages:
    38,334
    Likes Received:
    2,613
    Best Answers:
    462
    Trophy Points:
    710
    Digital Goods:
    29
    #4
    Better yet, if you have shell access, just block them at the network level:
    route add -host 1.2.3.4 reject
    Code (markup):
    1.2.3.4 being their IP address of course. :)
     
    digitalpoint, Feb 14, 2006 IP
  5. rederick

    rederick Peon

    Messages:
    128
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #5
    I ended up doing

    iptables -A INPUT -s 61.152.169.27 -j DROP
    Code (markup):
     
    rederick, Mar 3, 2006 IP
  6. RectangleMan

    RectangleMan Notable Member

    Messages:
    2,825
    Likes Received:
    132
    Best Answers:
    0
    Trophy Points:
    210
    #6
    Most likely he is trying to mail() inject and he could be succeeding and you don't know it. To avoid this I suggest you try a better contact form with captcha.
     
    RectangleMan, Mar 3, 2006 IP
  7. onedollar

    onedollar SEO Consultant for Hire

    Messages:
    3,481
    Likes Received:
    333
    Best Answers:
    0
    Trophy Points:
    0
    #7
    labrocca, can you expand on that please? I have happened this to me as well recently.
     
    onedollar, Mar 3, 2006 IP
  8. rederick

    rederick Peon

    Messages:
    128
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #8
    I do have some checks for things like "Content-Type" and "BCC:" in my form processing script, if it finds these in the posted form variables, the script dies and does not send the mail. These seem to be working alright to stop the injections, I have not moved to image verivication yet.
    This particualar spammer from IP 61.152.169.27 has been submitting contact forms trying to sell chainsaws and stuff in Chinese, so i just used iptables to drop the requests.

    I don't understand how he could be succeeding without me knowing?
     
    rederick, Mar 4, 2006 IP
  9. rehash

    rehash Well-Known Member

    Messages:
    1,502
    Likes Received:
    30
    Best Answers:
    0
    Trophy Points:
    150
    #9
    you may not see what he is doing because he injects another header
    like someone said above, you have to make a strict input checking on subject field and from field...and maybe others..depending on how your form looks like
     
    rehash, Mar 7, 2006 IP
  10. Gold_Hunter

    Gold_Hunter Active Member

    Messages:
    147
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    63
    #10
    i don't have shell access. how can i do to block them ?

    Thank You
     
    Gold_Hunter, Mar 10, 2006 IP
  11. UptimeAgent

    UptimeAgent Peon

    Messages:
    36
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #11
    UptimeAgent, Mar 10, 2006 IP
  12. JEET

    JEET Notable Member

    Messages:
    3,832
    Likes Received:
    502
    Best Answers:
    19
    Trophy Points:
    265
    #12
    Oh so that was chinese... I thought god was filling my contact forms.:D :D :D

    jeet
     
    JEET, Mar 10, 2006 IP