Announcement

Collapse
No announcement yet.

Getting hit hard with spam through the "contact us" form

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Getting hit hard with spam through the "contact us" form

    Today, I got hit with tens of drug spam messages throgh the "Contact us" form. All of it is from [email protected],. IP address of 85.255.117.18. Anyone else getting hit today?
    Cyburbia Forums - a third place for urban planners
    http://www.cyburbia.org/forums

  • #2
    Do you have the image verification for this turned on? It was added in 3.5.0.
    Translations provided by Google.

    Wayne Luke
    The Rabid Badger - a vBulletin Cloud demonstration site.
    vBulletin 5 API - Full / Mobile
    Vote for your favorite feature requests and the bugs you want to see fixed.

    Comment


    • #3
      Yes, I do. That's why it seems so strange; who would go thorugh the problem of verifying it just to send spam to one person?

      A traceroute for 85.255.117.18 dies somewhere in West Virginia; not India like I'd expect for this type of spam.

      BTW, I just got hit with nine more spams from
      85.255.117.18.
      Cyburbia Forums - a third place for urban planners
      http://www.cyburbia.org/forums

      Comment


      • #4
        ban the ip at the server level and in vb
        Plan, Do, Check, Act!

        Comment


        • #5
          Actually DNSStuff.com records shows that this IP belongs to a hosting company in Ukraine. They have an abuse e-mail which you can complain to.

          See for details:
          http://www.dnsstuff.com/tools/whois....e.net&email=on
          You're spending millions of dollars on a website?!

          Comment


          • #6
            Originally posted by simsim View Post
            Actually DNSStuff.com records shows that this IP belongs to a hosting company in Ukraine. They have an abuse e-mail which you can complain to.
            I just googled, and found that the IP is responsible for a LOT of spam. I doubt the hosting company is going to do anything about it.
            Cyburbia Forums - a third place for urban planners
            http://www.cyburbia.org/forums

            Comment


            • #7
              I am getting spam through that form from this IP: 84.19.186.155

              I've turned the image verification for guests on so see if that helps.


              The Spam I get uses the URL-BBcode and links to various subpages of http://[REMOVE]beliy.pbwiki.[REMOVE]com
              That's the end of that!

              Comment


              • #8
                Looks like nLayer is one of the primary backbones for this guy too.
                ManagerJosh, Owner of 4 XenForo Licenses, 1 vBulletin Legacy License, 1 Internet Brands Suite License
                Director, WorldSims.org | Gaming Hosting Administrator, SimGames.net, Urban Online Entertainment

                Comment


                • #9
                  Originally posted by cyburbia View Post
                  Today, I got hit with tens of drug spam messages throgh the "Contact us" form. All of it is from [email protected],. IP address of 85.255.117.18. Anyone else getting hit today?
                  I was hit by them for a few days.

                  In the
                  "Allow Unregistered Users to use 'Contact Us'" setting, make sure you have selected the "Yes, but verify image" option from the drop down.

                  I only had mine set to "Yes" not realizing there was another option to verify the image as well. Since applying that setting i haven't received any more spam.
                  Techzonez - Tech News
                  Techzonez Forums - Tech Community

                  Comment


                  • #10
                    Originally posted by Reverend View Post
                    I only had mine set to "Yes" not realizing there was another option to verify the image as well. Since applying that setting i haven't received any more spam.
                    That's the thing - I did have image verification turned on for the contact form. Seems like a LOT of trouble to go through just to spam one person.

                    As far as board registration goes, I've got most free Russian email providers and Yahoo.* among the banned addresses. Just blocking registration from Yahoo addresses stopped 95% of the spam that was posted.

                    EDIT: Amazing. My logs are showing a LOT of posts to vBulletin threads and nonexistent forms for other scripts I don't have (Moveable Type seems to be one of them) from 85.255.113.* to 85.255.117.* .
                    Last edited by cyburbia; Sat 10th Jun '06, 11:33am.
                    Cyburbia Forums - a third place for urban planners
                    http://www.cyburbia.org/forums

                    Comment


                    • #11
                      Originally posted by ManagerJosh View Post
                      Looks like nLayer is one of the primary backbones for this guy too.
                      More stock graphics of the corporate-looking guy staring up at "endless opportunity" or something like that, with the usual skyscrapers in the background, along with liberal use of the word solutions. I don't trust companies like that, for some reason.
                      Cyburbia Forums - a third place for urban planners
                      http://www.cyburbia.org/forums

                      Comment


                      • #12
                        Does the 'contact us' form use the servers sendmail system?

                        Bob

                        Comment


                        • #13
                          Originally posted by Bob Isaac View Post
                          Does the 'contact us' form use the servers sendmail system?

                          Bob
                          I think it uses sendmessage.php.
                          Forums

                          Comment


                          • #14
                            It uses sendmessage.php, which in turn uses the function you selected in your vBulletin Options, either mail() or SMTP.
                            Best Regards
                            Colin Frei

                            Please don't contact me per PM.

                            Comment


                            • #15
                              Oh well, I had hoped I could use sendmail's blocking systems to deal with this.

                              Bob

                              Comment

                              widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                              Working...
                              X