Which file is making SPAM emails on machine? Please help!

Discussion in 'Programming' started by amaze, Jun 1, 2009.

  1. #1
    Hi,

    Since yesterday I have just noticed somethinh is creating SPAM emails on our server and sending. Its created by "CF8" so I guess a script of some kind on our server. Is there anywhere that logs such details so I can trace back to the file that is causing the issue?

    I have disabled IIS smtp for the moment, but obviously need to fix ASAP! Please help!

    This is the spam message:

    ++++
    type:  text/plain; charset=UTF-8
    server:  localhost:25
    from:  our-email@removed.com
    to:  nschafer@emailhere.com
    subject:  Hey, Check This Out!
    X-Mailer:  ColdFusion 8 Application Server
    body:  
    body:  Hi Friend,
    body:  
    body:  ===========================================
    body:     The Hands-Down, No-Debate, Quickest,
    body:       Easiest Way To Make Money Online 
    body:  ===========================================
    body:  
    body:  Underground Affiliate Marketer Bares All 
    body:  And Exposes The $2858.05,  $3639.81 & 
    body:  $4483.35 A Day Blueprint So That YOU Can 
    body:  Finally Make Money Online!
    body:  
    body:  Let Me Show You How To Get Cash In The Bank 
    body:  Without A Website, Experience Or Even 
    body:  An Idea!
    body:  
    body:  Click Here: http://virl.ws/mathew/ACF
    body:  
    body:  Plus,See Detals Below On The *NEW* 
    body:  Resources on Demand!
    body:  
    body:  
    body:  ----> http://virl.ws/mathew/ACF
    body:  
    body:  Regards,
    body:  Richard Saints,
    body:  
    body:  http://virl.ws/mathew/ACF
    body:  
    body:  
    body:  To unsubscribe reply Not Interested.
    body:  
    body:  Sent by Richard (ForexInterprices@gmail.com)
    Code (markup):

     
    amaze, Jun 1, 2009 IP
  2. xheartonfire43x

    xheartonfire43x Guest

    Messages:
    16
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Do you still need help with this issue? If so there is an email log in the CF Admin. You have to enable it though I believe which is done in the mail section of the Admin, although this looks like you have something bigger going on. Do you have any kind of email client applications built on CF?
     
    xheartonfire43x, Jun 22, 2009 IP
  3. tbarr60

    tbarr60 Notable Member

    Messages:
    3,455
    Likes Received:
    125
    Best Answers:
    0
    Trophy Points:
    210
    #3
    Do you have any files that use the CFMAIL tag? You may have a file that sends mail from a contact form but someone is exploing it.

    Have you searched the server for any new files using the CFMAIL tag?
     
    tbarr60, Jun 23, 2009 IP