Web Hosting Talk







View Full Version : Help please with odd email


cweb
04-08-2003, 12:16 AM
Hi

I just got an email to webmaster@domain.com (an account on our server) which had the following content:

body: FormMail Test: Test 3 "recipient=user%yourdomain.com@thisdomain.com"

The from header had: <account%aol.com@domain.com>

Is this an attempt at checking the site out for spamming purposes? Or something else?

The site doesn't actually use formmail at all so it seems to me that it would have to be sniffing of some sort.

We run a cpanel (latest version) server.

I'd really appreciate any ideas or advise please as we've never received an email like that before.

Thanx!

TDMWeb
04-08-2003, 06:18 AM
It's someone trying to probe your server to see if it has a weakness that has been discovered in the CPanel cgi-sys/formmai.pl (also formmail.cgi, FormMail.pl, FormMail.cgi).

There's a thread on the forum at http://forums.cpanel.net/ (you need to register) and the advice from other users so far is to disable the Cpanel formmail until DarkOrb get the hole fixed. No update yet from Nick at DarkOrb AFAIK.

cweb
04-08-2003, 08:59 AM
Hi Chris :)

Thanx for the reply.
That was plenty of food for thought there in that thread on cpanel forums about the formmail probes and spam attacks (if that's what you'd call them) that have apparently been quite prevalent across cpanel servers over the last day or so.
Ours are ok (the various formmail scripts sitting in cpanel) as they are chmod'd to 700 now...

Like people were saying on cpanel.net, it'd be good to see these removed entirely from the cpanel script in the future.

Scary stuff to hear about, though! However, I am pleased at least that I know now what the email was all about...

Thanx again :)