Sales Training and Social Networking for Sales Professionals
Sales Training (Sales Training and Social Networking for Sales Professionals) : Sales Training Forum / Internet Marketing / Email attack from the website

Email attack from the website

Internet Marketing

  #11
sandiego
Do you have a form on your site that they can fill in and send something to you?
There have recently been several attempts to hack or break these forms to allow spammers to use them, these "bots" go through your site, find the form and try to exploit it...

The best way to stop that part of the spam is to add a server side verification to the email part of the form where your server makes sure the email address that is entered into the form is actually valid...




Quote:
Originally Posted by RainMaker
No, San Diego, I am getting both, at present. Much of it is coming to every variation of address @mydomain.com. I don't even understand why that stuff is being delivered.
 
Join the Sales Training Community!
  #12
RainMaker
Quote:
Originally Posted by sandiego

The best way to stop that part of the spam is to add a server side verification to the email part of the form where your server makes sure the email address that is entered into the form is actually valid...
I do not think (although I am not certain) that this is coming through my form because it is simply coming into variations of addresses @mydomainname.com.

Now I have upted the filters on Outlook Express and changed the setting so it will not download from the server (Verizon's server) questionable emails.

Now I have a new problem. (I have had this problem before only it's much worse now) SOME MAIL IS BEING DIVERTED FOR NO REASON THAT I CAN FIGURE OUT. I have had this problem before with Outlook Express. I don't have many rules set up and the rules are straight forward, but other mail gets dumped into the scrap pile even though it has nothing in it that should snag it.

Now it is worse because instead of going to my deleted items folder, this mail is never getting to me at all.

For example: I no longer get email notification on my own threads from SP. There is nothing in those emails that violated the simple rules I have made. This is so infuriating.
 
  #13
Jeff Blackwell
"Top Sales Expert"
RainMaker, quite possibly what is going on is a php program on your website is being exploited with mail() function. Those jiberish accounts are probably being used for spoofing.

Here is a free tool to encode emails: http://www.wbwip.com/wbw/emailencoder.html
__________________
If you have a website and/or blog please add SalesPractice.com to your list of recommended resources or blogroll because we could use the help getting the word out. We offer a variety of links and logos for use on your website and/or blog.
 
  #14
RainMaker
Quote:
Originally Posted by Jeff Blackwell
RainMaker, quite possibly what is going on is a php program on your website is being exploited with mail() function. Those jiberish accounts are probably being used for spoofing.

Here is a free tool to encode emails: http://www.wbwip.com/wbw/emailencoder.html
Jeff, that is a useful tool. I noticed you mentioned a php program...does it make any difference that my site doesn't use php, but cold fusion?
 
  #15
Jeff Blackwell
"Top Sales Expert"
Quote:
Originally Posted by RainMaker
...does it make any difference that my site doesn't use php, but cold fusion?
Yes, that particular exploit applies to PHP.
 
User Name:  Password:

© 2008 Blackwell & Associates, Inc. All rights reserved.

LinkBacks Enabled by vBSEO 3.0.0 RC6 © 2006, Crawlability, Inc.