1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

Bastards are spoofing my domain for Spam!!!

Discussion in 'Security' started by amanamission, Sep 11, 2007.

  1. #1
    I've received over two-hundred failure notices from someone sending spam and using made-up e-mails with my domain. I've contacted my host so I don't get my hosting yanked over it...but how can I stop it? I don't believe they have access to my files, or they'd be spoofing a real e-mail...

    FLASH!

    I think I actually figured out what it is in the middle of my post. Oh well, I'll finish anyway, as a warning: my tell-friend script.
    DUH!
    I knew that spammers could use this, I just didn't think they would...right.
    And I went and contacted my host.
    Keep an eye on those tell-friend scripts (just removed the link to mine).
     
    amanamission, Sep 11, 2007 IP
  2. izwanmad

    izwanmad Banned

    Messages:
    1,064
    Likes Received:
    14
    Best Answers:
    0
    Trophy Points:
    0
    #2
    the email address can be spoof .... but, I'm sure the details such as the sender server come with the email
     
    izwanmad, Sep 11, 2007 IP
  3. rcj662

    rcj662 Guest

    Messages:
    4,403
    Likes Received:
    97
    Best Answers:
    0
    Trophy Points:
    0
    #3
    You took it off and have no problems anymore. They might just keep makeing new emails from your domain name.
     
    rcj662, Sep 11, 2007 IP
  4. easterwolf

    easterwolf Well-Known Member

    Messages:
    608
    Likes Received:
    22
    Best Answers:
    0
    Trophy Points:
    108
    #4
    I had the exact same thing happen with a Tell-A-Friend script. Good that you nipped it in the bud.
     
    easterwolf, Sep 11, 2007 IP
  5. amanamission

    amanamission Notable Member

    Messages:
    1,936
    Likes Received:
    138
    Best Answers:
    0
    Trophy Points:
    210
    #5
    Well, the failure notices are still coming in...might be for days. They've been damn busy, that's for sure...I started seeing this an hour ago. 350+ and probably 25 waiting for me when I get back. And that's just the failures. If only my visitors had used it so dilligently! Of course, I've seen hardly any traffic that way. But I'm pretty sure that's how they were doing it, hopefully that's that.
    The worst part is my domain e-mails will probably trip a spam filter now.
    I'm going evangelistic on don't use tell-friend scripts./
     
    amanamission, Sep 11, 2007 IP
  6. scriptman

    scriptman Peon

    Messages:
    175
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #6
    You've taken the link off, but did you remove / rewrite the vulnerable script itself? I am not sure if you were implying that by saying you've removed the link.

    If the script is still there, the spammer would already know the correct request variables to send to it in order to produce E-mail. They don't need a hyperlink. Absolutely make sure the actual script itself has been updated / removed!

    Hope I'm not stating the obvious to you, amanamission!
     
    scriptman, Sep 16, 2007 IP
  7. amanamission

    amanamission Notable Member

    Messages:
    1,936
    Likes Received:
    138
    Best Answers:
    0
    Trophy Points:
    210
    #7
    I've removed the script and blocked the offending IP in both root directory and the domain they were spoofing. The spam failures stopped for several days, but my box just got hit with another 150.
    This IP will not go away. According to Wikipedia, it's an "open proxy" or "zombie computer," so the humans behind this may not realize it's blocked.
    .htaccess just send you to a serve default page. I actually went to the proxy Wiki mentioned, and sure enough, my sites are blocked.
    So it must be on automatic. Nice to be rid of them though, because I never know what's really going on with this crap.
     
    amanamission, Sep 17, 2007 IP
  8. kendo1979

    kendo1979 Peon

    Messages:
    208
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #8
    you might not receive the mail from them, but are you sure they are not still using it?
     
    kendo1979, Sep 18, 2007 IP
  9. amanamission

    amanamission Notable Member

    Messages:
    1,936
    Likes Received:
    138
    Best Answers:
    0
    Trophy Points:
    210
    #9
    I don't really know what the hell they are doing. That's why I started this thread.
    However, I believe that failure notices are a good metric of whether they are sending out spoofs, because I get failure notices from the spam detectors. So if they use my domain in the sending address, I get the failure notice about it.
    They seem to have stopped since I totally deleted the script, but this IP is still living at my site despite being .htaccess banned.
     
    amanamission, Sep 18, 2007 IP
  10. HostJail

    HostJail Active Member

    Messages:
    180
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    58
    #10
    HostJail, Sep 18, 2007 IP
  11. n3o_the_on3

    n3o_the_on3 Well-Known Member

    Messages:
    1,422
    Likes Received:
    62
    Best Answers:
    0
    Trophy Points:
    165
    #11
    There are some smtp grabber net so maybe some hackers used it and got your smtp address and started spamming . But now a days, scammer use phpmailer to spam to the entire e-mail inbox. they can't access the your files but still can manage to send e-mail from a existing e-mail address (like ) whatever most of the time they live in bulk/spam box!
     
    n3o_the_on3, Sep 24, 2007 IP
  12. lkj

    lkj Peon

    Messages:
    729
    Likes Received:
    17
    Best Answers:
    0
    Trophy Points:
    0
    #12
    check on the SPF and how to set-up. Works wonders, however, only with the providers who support it.
     
    lkj, Sep 25, 2007 IP
  13. blowingideas

    blowingideas Peon

    Messages:
    642
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #13
    that's correct lkj.. if your webhost isn't using SPF, then there's no way of stopping email spoofing.
     
    blowingideas, Sep 26, 2007 IP
  14. cav609

    cav609 Active Member

    Messages:
    316
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    58
    #14
    Hi - same thing happening to me. It started just before the weekend and today I got over 300 failure notices in my mailbox. I have a tell-a-friend script too, but the spammers are using one particular mailbox that has nothing to do with the script?

    How so I get their IP address? From the email headers? What do I look for?


     
    cav609, Oct 8, 2007 IP
  15. craigedmonds

    craigedmonds Notable Member

    Messages:
    703
    Likes Received:
    131
    Best Answers:
    0
    Trophy Points:
    235
    #15
    Isnt SPF at the domain/dns level?

    At any rate if someone is spamming through a form on your site SPF makes no difference because the spammer is sending through a form on your web site whose IP probably is cleared through the spf entry on the dns, so if you have a spammable form, fix it or take it off or get blacklisted.

    Also, SPF does not stop the actual spoofing that results in the millions of bounced messages.

    What SPF is good for is working with blacklists becasue if a spammer spoofs your email address (which i sooo easy to do) and send a million email via their local spam server, if any of those spams are reported say to spam cop, spam cop wont black list becasue the sending ip wont match whats in your spf record.

    SPF is handy andan extra measure in keeping your domain name off a blacklist buts its not infallible.
     
    craigedmonds, Oct 10, 2007 IP