Web Hosting Talk







View Full Version : AOL spider at aol.com


EpicServers
08-18-2003, 12:15 PM
I'm getting a really weird formmail reply from my server. I use Cpanel and WHM:

This message was created automatically by mail delivery software. A message that you sent has not yet been delivered to one or more of its recipients after more than 24 hours on the queue on water.mainlandhosting.com.

The message identifier is: 19oA5Y-000633-0M
The subject of the message is: http://mywebsiteaddress/cgi-sys/formmail.pl (195.166.50.19:80) bcc: bagnallb@aol.comy s5xWdmUPxyGX cKbW jSYgZ xIQ7 c 7uFH4oS0JcR9GSI8S 2n8JTTlI nW ODv QB41RApO2Ym1212HG sGBd4˙FFFFCCabcdefghijklmnopqrstuvqxyzABCDEFGHIJK.
The date of the message is: Sat, 16 Aug 2003 19:04:00 -0400

The address to which the message has not yet been delivered is:

qdzMWluY86@mywebsiteaddress
Delay reason: lowest numbered MX record points to local host

No action is required on your part. Delivery attempts will continue for some time, and this warning may be repeated at intervals if the message remains undelivered. Eventually the mail delivery software will give up, and when that happens, the message will be returned to you.


I check in my log file and saw that a last login was from a spider@aol thing. Does this have to do with someone putting a spider through my system to retrieve illegal information? I'm getting this at one of my sites and a friend is also.

BTW I do not use CGI nor does the other user.

superiorhost
08-18-2003, 02:16 PM
Hi,
It looks like your host has not disables the system formmail. It has a vunerability in it that is letting people spam through his server using anydomain@ that they want...

Tell him (politely) to look at cpanel.net and get them disabled asap before he gets the server blacklisted by AOL and other big ISPs and ligit emails start bouncing.

Best of luck,

Tim L

Burhan
08-18-2003, 04:03 PM
Having exact same problem here. I wish there was a way for me to disable formmail from my cpanel (I'm not the host, just a client).

I already sent an email off to my host, I'm hoping that they can get to this soon, I don't want my site to be blacklisted, especially since I'm just about to start a new service section.

Why don't people disable formmail to begin with? Seems like its more trouble than its worth.

If I delete the actual .cgi file, will that fix this problem? Or cause more headaches for my host? (I'm on shared hosting).