I've been in touch with my web hosting company, Speakeasy.net, a very good one with great support, who tell me that there have been thousands of spam emails sent throught what they think is a bad security hole in Drupal. Maybe if you have a moment you could weigh in on the claims here.

I have been using the most recent version of 4.7 since it was released. I have no email modules running other than the standard to request an account and such. I am not a professional IT or network manager so I don't even know where to look to try to solve this problem. The threat to our site is that it could be shut down if I can't isolate the abuse.

It is not clear to date whether these spam emails are produced by our Drupal installation or by cloning one of our return email addresses. There are no messages in my admin log that tell me messages have been sent to anyone, so I don't know if their claim is valid. And I don't have logs from them yet to see any technical stats.

Granted that I have nothing to show, what is the actual risk of our Drupal installation being exploited for sending potentially thousands of emails? If there is a risk, can I band together with someone to 1) protect my site from shut down and 2) solve this problem for other users of the newest Drupal version. If you want admin access to help address this then please let me know and I can work out some details for you.

Here is the support ticket conversation I have had with them over the last couple of days:

Them:

Called Sean and let him know about the SPAM issue. I sent him the link to find a vulnerability fix for his Drupal issue. He is currently investigating the issue. I let him know that if the issue is not dealt with the site will be taken down.

http://www.securityfocus.com/bid/17104

Also see:
http://www.drupal.org

Them (auto-emailed abuse report):

Greetings,

We have recently received a report that there has been activity originating from your circuit that is in violation
of the Speakeasy Acceptable Use Policy. The IP address in question is:

69.17.116.124

The following complaint is concerning unsolicited emails being sent from this IP and/or spam being sent,
advertising a site at that IP address. Sending any form of unsolicited or bulk mail or using unsolicited email to
promote a site hosted anywhere on our network is strictly prohibited under Speakeasy's Terms of Service. We
request that you immediately cease and desist this activity.

If you believe that someone may be compromising a machine or other equipment on your network, it is imperative
that you remove the vulnerable machine or equipment from your network and make certain that it is properly
secured, prior to placing it back online.

It is vital for the security of your personal network and the Speakeasy network as a whole that you address this
issue. If we continue to receive similar reports about your circuit, we will be forced to temporarily suspend your
broadband service until this issue is resolved. Please understand that we consider an interruption in your service
only when it is absolutely required to ensure both your security, and the overall security of the entire Speakeasy
network.

PLEASE ALSO NOTE:
There will be an open Service Ticket on your account. To ensure that your service is not interrupted, it is
important that you update us once you have resolved this issue. Please call Speakeasy Support at 800.556.5829 or
login to MySpeakeasy (http://www.speakeasy.net/myspeak) and update the open Service Ticket referencing this issue.

We thank you for taking the time to address these Internet security concerns.

Network Security Department
Speakeasy, Inc.
abuse@speakeasy.net

- Speakeasy AUP/TOS
http://www.speakeasy.net/tos

X-Message-Status: n:0
 X-SID-PRA: ViagrCialisAmbienMeridiawptbqofk <wcrsssqwbqz@placedevelopment.net>
 X-SID-Result: TempError
 X-Message-Info: LsUYwwHHNt27R7oVrWGq1ChctY9086HEn1AvXU4M0e4=
 Received: from berceni.net ([80.96.237.123]) by bay0-mc3-f13.bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.2444);
 Wed, 6 Sep 2006 04:01:49 -0700
 Received: from mail pickup service by hotmail.com with Microsoft SMTPSVC;
 Wed, 06 Sep 2006 06:01:37 -0600
 Received: from 157.105.131.184 by by118fd.bay125.hotmail.msn.com with HTTP;
 Wed, 06 Sep 2006 06:01:37 -0600
 Message-ID: <BAY1_________________2709@phx.gbl>
 From: "ViagrCialisAmbienMeridiawptbqofk" <wcrsssqwbqz@placedevelopment.net>
 Subject: CheapestPriceFor You
 To: x
 Date: Wed, 06 Sep 2006 06:01:37 -0600
 MIME-Version: 1.0
 Content-Type: text/plain; format=flowed
 Return-Path: qpabv75zamc@worthyforce.com
 X-OriginalArrivalTime: 06 Sep 2006 11:01:50.0333 (UTC) FILETIME=[DA8F32D0:01C6D1A3]
 
 <html>
 <head>
 <title>Cambridge Community Television | The Voice and Vision of Cambridge, MA
 <body>
 </div><div class="block block-block" id="block-block-1">
 <h1>Quick Links</h1>
 <div class="hr"><hr></div>
 <div class="content"><p><a href="http://www.cctvcambridge.org/mediareform">Media Reform</a><br />
 <a href="http://www.cctvcambridge.org/lab">computerCENTRAL Vlog</a><br />
 <a href="http://www.cctvcambridge.org/macblog">MAC Blog</a><br />
 <a href="http://www.youareherenews.org/wiki">You Are Here News</a><br />
 <a href="http://www.cctvcambridge.org/bandwidth">Bandwidth Music</a><br />
 <a href="http://www.cctvcambridge.org/classes#orient">Next Orientation</a><br />
 <a href="http://www.cctvcambridge.org/forms">Newsletters &amp; Forms</a><br />
 <a href="http://www.cctvcambridge.org/jobs">Job Openings</a><br />
 <a href="http://www.cctvcambridge.org/auction">BBQ Auction!</a><br />
 <a href="http://www.cctvcambridge.org/product">BBQ Tickets</a><br />
 <a href="http://cctv-smi.blogspot.com/">SMI Videos</a></p>
 </div>

Me:

I am familiar with the Drupal.org website and have contributed to modules, bug reports, comments, etc. We have been using the newest Drupal version (version 4.7.3, as advertised on the front page) for three weeks already, this version is not on your vulnerable list as published here:

http://www.securityfocus.com/bid/17104

I’ve posted on the Drupal support forums about this issue and will wait to hear from some of the 60,000 developers that participate there. Until then, I have disabled the modules that allow users to ‘forward’ pages and articles to their friends, which I believe is the only feature that might leave open exploitations.

Could this issue be coming from our Majordomo/listserv manager that is available to us from Speakeasy via our webhosting account?

Our webmail is down today, your customer support tells us this is a larger issue than our security problem, but I thought I would alert you to it as well.

Them:

Thank you for your prompt response to this issue.

What we are reporting is that we received thousands of spams logged through your site hitting the internet, and Drupal appeared to be involved.

Ultimately, it is possible that with a product such as this with a long security flaw history, that there remain undocumented holes that they have not yet patched.

The bottom line is that we need to see the open holes allowing professional third party spammers to use your site without your knowing to be closed permanently. The internet is not a forgiving environment to IP addresses that are run as open spam holes, our server IP where your content rests can and would be blocked if we did not take immediate action.

Thank you for following up, please let us know if we can assist with specific questions or concerns.

Time Elapses here:

Them:

Called Sean back to let him know that this issue has cropped up again. He believes that his domain email may have had been cloned. I let him know that I would forward this message on to our security engineers to address. He will however, investigate any other reason this would happen.

Comments

Dewi Morgan’s picture

Seems like you need to be asking them some hard questions yourself. They claim "thousands" of emails were "hitting the internet" - ask for a copy of the logs, with timestamps. These must be definitive logs of email traffic sourced from your machine, not just reports of emails being received with your name or IP in the "From:" or "Return-path" lines, which are trivial to fake, as they are the responsibility of the originating host.

Any headers used as evidence must include your IP on the "Received:" lines, as these are added by intermediate routes, and cannot be so easily faked. I note their example does not have your IP on. Is this because their mail routers are broken, or is it because the email was never really received from your machine?

They claim there are "open holes" and "Drupal appeared to be involved": ask them on what they base these assertions, stating that you require copies of any evidence.

They claim that Drupal has "a long security flaw history". Ask for references that Drupal is in any way less secure than comparable products.

On the face of it, they seem to be blindly making unfounded assertions out of an unresearched bias. If they DO have a case, however, then the only way you can help them is if they tell you why they think what they do - and that means getting their logs.

The email headers they gave are pitiful evidence, and appear to be clearly faked, unless your IP is really 157.105.131.184 - unlikely since that IP is registered to Tokyo University! The incompetence of their security department in reading email headers is quite worrying.

I find it far, far more likely that a university machine has been compromised, myself.

--
Yet another Drupal user.
MorganAlley.com web design.

seaneffel’s picture

I have generally had a great experience with Speakeasy, they are not the usual oversell/underprice chop shop that other hosts are. In fact they make their money by providing excellent DSL, T1, T3, VoIP etc, service. I think they are mostly concerned that their own server IP address will be blacklisted as a known spammer or worse, so I can understand their aggressive position.

I'm glad that there are more people in the know and can help arm me with a defense!

sepeck’s picture

They really really need to look at the mailservers log. Your mailservers log to see if you are an open relay or your server itself is hacked. Frankly, a Drupal site would probably fall down and die if it was the vector for that many messages unless you had a really beefy setup. Do you Drupal logs indicate a lot of Traffic?

Long security issue history? Check here: http://drupal.org/security
Drupal fixes and reports security issues in a timely manner and our reputation is pretty good on that front. If an issue is reported, it is dealt with and announced.

Has the site been hacked?
Has THEIR server been hacked?
Is the email server misconfigured.

A spam database lookup shows you on known spam lists that use spam traps.
http://www.dnsstuff.com/tools/ip4r.ch?ip=80.96.237.123
It is unknown if the senders were forging your ip address or if your server itself has been compromised.

-Steven Peck
---------
Test site, always start with a test site.
Drupal Best Practices Guide -|- Black Mountain

-Steven Peck
---------
Test site, always start with a test site.
Drupal Best Practices Guide

bryansd’s picture

Three quick questions/suggestions:

1) Any chance you have any other scripts in your directory besides Drupal? I'm surprised your host provider hasn't ran some type of auditing software to give you a list of potential trojans on your server.
2) Did you by chance install a third party module now found at Drupal.org?
3) I would copy/move all your files off the server and make sure you do a clean install of Drupal. Before you upload the latest Drupal code...don't forget to also check for hidden files. Any third party modules/themes that you install...make sure they come from drupal.org or yourself and are the very latest files. See if you then have a problem. I would not just copy Drupal 4.7 files over your present directories.

Bryan
CMSReport

seaneffel’s picture

Here is the newest communication from the host:

Dear Sean,

Hopefully you're the one dialoging in the ticket, it wasn't signed, so we
can't tell who wrote it.

Anyway, as sent two weeks ago, here is one of the many copies we had of
mail bomb from your site.

As soon as we disabled, the mail bomb stopped, which was also used in
determining it was your site doing it.

Please let me know if any questions.

Kind regards,

--
Dave
Network Security
Speakeasy, Inc.
www.speakeasy.net Broadband Voice & Data Communications

---------
Subject: [SpamCop (htt p://www.cctvcambridge.org/lab)
id:1909829451]CheapestPriceFor You
Date: Wed, 6 Sep 2006 03:51:52 -0700
To: abuse@speakeasy.net
From: "Admin SS427" <1909829451@reports.spamcop.net>

[ SpamCop V1.596 ]
This message is brief for your comfort. Please use links below for
details.

Spamvertised web site: htt p://www.cctvcambridge.org/lab
http://www.spamcop.net/w3m?i=z1909829451zddc43424e2efe779d59bb1d3faf9bf62z
[ Additional links on ww w.cctvcambridge.org: ]
http://www.cctvcambridge.org/auction
http://www.cctvcambridge.org/classes
http://www.cctvcambridge.org/jobs
http://www.cctvcambridge.org/product
http://www.cctvcambridge.org/lab
http://www.cctvcambridge.org/macblog
http://www.cctvcambridge.org/forms
http://www.cctvcambridge.org/bandwidth
http://www.cctvcambridge.org/mediareform
http://www.cctvcambridge.org/lab is 69.17.116.124; Wed, 06 Sep 2006
15:45:19 GMT

[ Offending message ]
X-Message-Status: n:0
X-SID-PRA: ViagrCialisAmbienMeridiaoquzakpm
<xndxewharolj@cousinwindow.net>
X-SID-Result: TempError
X-Message-Info: LsUYwwHHNt29OQQsrulqbNHmr/LDIJwVHctnkTM3i6A=
Received: from host-81-190-186-198.kwidzyn.mm.pl ([81.190.186.198]) by
bay0-mc4-f8.bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.2444);
Wed, 6 Sep 2006 03:51:52 -0700
Received: from mail pickup service by hotmail.com with Microsoft SMTPSVC;
Wed, 06 Sep 2006 03:51:17 -0800
Received: from 176.159.137.206 by by148fd.bay92.hotmail.msn.com with HTTP;
Wed, 06 Sep 2006 03:51:17 -0800
Message-ID: <BAY146-511017209123153977@phx.gbl>
From: "ViagrCialisAmbienMeridiaoquzakpm" <xndxewharolj@cousinwindow.net>
Subject: CheapestPriceFor You
To: ptwoods@hotmail.com
Date: Wed, 06 Sep 2006 03:51:17 -0800
MIME-Version: 1.0
Content-Type: text/plain; format=flowed
Return-Path: hpiqdb9efd@studiedfool.com
X-OriginalArrivalTime: 06 Sep 2006 10:51:53.0426 (UTC)
FILETIME=[76C66B20:01C6D1A2]

<html>
<head>
<title>Cambridge Community Television | The Voice and Vision of Cambridge,
MA
<body>
</div><div class="block block-block" id="block-block-1">
<h1>Quick Links</h1>
<div class="hr"><hr></div>
<div class="content"><p><a
href="http://www.cctvcambridge.org/mediareform">Media Reform</a><br />
<a href="http://www.cctvcambridge.org/lab">computerCENTRAL Vlog</a><br />
<a href="http://www.cctvcambridge.org/macblog">MAC Blog</a><br />
<a href="http://www.youareherenews.org/wiki">You Are Here News</a><br />
<a href="http://www.cctvcambridge.org/bandwidth">Bandwidth Music</a><br />
<a href="http://www.cctvcambridge.org/classes#orient">Next
Orientation</a><br />
<a href="http://www.cctvcambridge.org/forms">Newsletters &amp;
Forms</a><br />
<a href="http://www.cctvcambridge.org/jobs">Job Openings</a><br />
<a href="http://www.cctvcambridge.org/auction">BBQ Auction!</a><br />
<a href="http://www.cctvcambridge.org/product">BBQ Tickets</a><br />
<a href="http://cctv-smi.blogspot.com/">SMI Videos</a></p>
</div>
</div><div class="block block-user" id="block-user-1">

</quote>
sepeck’s picture

That doesn't actually tell anyone anything.

Disabled your site..... Does this mean your email, did they bother to see if the server was hacked? Did they see if your mail server account password was compromised? Was this a reverse NDR spam?

Was a directory audit of the scripts down? Is you Apache patched? Is the file level permissions locked down?

So, any messages in the Drupal logs indicating you've send out email? Notifications? something? If not, then what modules are you using that send email and do they normally log? If they do and you do not have a log event then .......... How is it Drupal?

Perhaps the mailbomb merely ran out? Spammers run through an address list and stop when done. By 'your site' was that also 'your mail server'?

If they say it was a Drupal exploit then they had better be able to actually say what happened. If not, then they didn't really do anything now did they? If it was a Drupal module then we need to know so it can be fixed. At this point we don;t know it was Drupal, we don;t know it was not and they don't seem particularly interested in helping you actually figure it out.

I still think the sending IP Address was in fact forged and you are a victim of the spammer and now your current host provider. I am feeling more and more inclined to think negatively about your host provider. Paticularly in light of the unsupported claims about Drupal. They really need to address these unfounded claims publically. They really do. Especially if this is what they are telling their customers.

(Note: I wrapped the message in code tags and broke the links to the spam site.)

-Steven Peck
---------
Test site, always start with a test site.
Drupal Best Practices Guide -|- Black Mountain

-Steven Peck
---------
Test site, always start with a test site.
Drupal Best Practices Guide

yelvington’s picture

There's no evidence in the mail headers that cctvcambridge is involved and no evidence that Drupal is involved.

Anyone with a brain could figure out that cctvcambridge would have no reason to send spam (of any nature, let alone this junk).

The only reference to cctvcambridge is in the text itself, which appears to be HTML copied from a Drupal page -- probably from the navigation block.

The only thing I can figure is that spammers are now trying to overload Spamcop's services by flooding the net with fake spam containing URLs of legitimate websites. This is known as "poisoning the well."

In fact, I'd bet lunch that's what's happening. If they succeed, Spamcop will no longer be regarded as a trustworthy information source, and the spammers will win.

sepeck’s picture

Not that that actually means anything except they are using Drupal for their site. It could have been a misconfigured mail message. It could have been a number of things. We don't have enough info to say it was Drupal. We also don;t have enough to say it wasn't.

Very frustrating. If it's a problem, then we need to know so it can be fixed. If it's not, then speakeasy needs to educate themselves and stop saying inaccurate things to their customers about large Open Source projects.

-Steven Peck
---------
Test site, always start with a test site.
Drupal Best Practices Guide -|- Black Mountain

-Steven Peck
---------
Test site, always start with a test site.
Drupal Best Practices Guide

seaneffel’s picture

I appreciate all the help, and I appreciate the concern for sniffing out potential exploitations in Drupal and am behind that 100%. So if the webhost responds with more data then I'll post it up here. Its been five days and I've still got no substantial response from them.

brioz’s picture

From the limited information available, I am of the opinion that your email address is being impersonated.
I have a number of gambling websites that are hosted on good data centers with fast servers. Over the last month I am getting five or six bounced emails being "returned" to info@blackjackrat.com which is a non existant email address but is picked up by the catch all feature of the mail server. The displayed originating email address is mostly info@blackjackportal.net (this site is not owned by me and currently has no website) with the return address of info@blackjackrat.com

On the few that show the IP address of the originating server, the addresses are in Moscow, Belsuras, Egypt, Canada, Japan and the Philipines.

Today I got one "back" for brioz@winnersrun.com, a site on page one at Google for the target keywords.

These e-mails are always for online pharmacies and dud penny stocks.

I have contacted my hosting company which is in the Planet Data Centre and they assure me that these emails are not being sent out from my servers some of which have their own dedicated IP addresses. Fortunately none of the "returned" mail shows any of my IP addresses in the header information. So far I have had no problems with my hosting provider over this spam but my main concern is the likely scenario of being blacklisted for spamming.

So far, I cannot find any regulatory authority anywhere in the world that is interested in dealing with these fleas.

I would be asking your ISP for copies of say 100 of these spam emails so I could examine the headers as only a small number of mail servers show where the message was received from when they bounce it because I am sure that you and I have the misfortune to share a common problem.

If anyone knows of any regulatory authority that is prepared to take these germs on, please enlighten me.

Brioz
Slow and persistant