This morning at about 5 o'clock I was a victim of an interesting crack attempt to relay spam through my website.
I'm using the feedbak.module on my site for ... uhhh ... getting feedback. ;-)
The attacker used this 'web2email'-feature of my website to possibly compromise my site and enslave it as a spam bot.
The way it is done in general is decribed en detail at this site:
http://www.anders.com/cms/75/Crack.Attempt/Spam.Relay
The email-address that occurred in the above mentioned BCC-field was also 'bergkoch8@aol.com'. A search for 'bergkoch8@aol.com' at google returned about 16.000 (!) results. So it seems to be a new spam-method I'm experiencing here.
From what I understand it is important to check and strip fields for carriage return and newline characters used directly in email headers.
As I'm not very confident with coding PHP I'm wondering how I could code this checking-mechanism into the feedbak.module. Maybe someone could point me into the right direction or even the developers of the module could apply a patch for this leak.
It seems to me that it is not very difficult for someone gifted with good programming skills but it sure would have a great benefit for the community.
Tahnk you all very much.
Comments
feedback.module vulnerable or not?
Why don't I get any response?
Is my post off topic? Is the feedback.module not vulnarable to the above mentioned cracking method?
Please, is there anybody here to guide me out into the light? Let me know if I'm wrong or if I'm right.
Thanks.
I cant help you, but I would
I cant help you, but I would post this as an support issue on the specific module project page.
--
my httpclient for uploading whole directories to drupal image galleries (image.module)
They tried on my site too.
I had read about this vulnerability on php.net while learning about the mail functions, and tried to emulate the attack using the feedback module. It didn't work. I don't know if the crackers were successful in using my feedback module to send spam (I hope not), but I agree that we should audit for this vulnerability.
Have you contacted Károly Négyesi about this? He's the leader of the security team.
http://drupal.org/user/9446/contact
- Robert Douglass
-----
Rate the value of this post: http://rate.affero.net/robertDouglass/
I recommend CivicSpace: www.civicspacelabs.org
My sites: www.hornroller.com, www.robshouse.net
Thank you both ...
... I opened an issue and contacted Károly Négyesi.
I hope we all will be wiser in the near future.
Thanks again.
Replied in the issue
I tried to crack it, but could not.
See details here
http://drupal.org/node/29927#comment-41621
If any one else is able to crack it, let me know.
--
Drupal development and customization: 2bits.com
Personal: Baheyeldin.com
--
Drupal performance tuning and optimization, hosting, development, and consulting: 2bits.com, Inc. and Twitter at: @2bits
Personal blog: Ba