Welcome, Guest. Please login or register.
Did you miss your activation email?


Login with username, password and session length

Search

 
Advanced search

8043 Posts in 1856 Topics- by 2099 Members - Latest Member: roi
Calendar Script CommunitySetup and InstallationProblems and Solutionsmassive spammail distributed from cs-directory
Pages: [1]   Go Down
Print
Author Topic: massive spammail distributed from cs-directory  (Read 688 times)
0 Members and 1 Guest are viewing this topic.
DJBAP
New Member
*

Karma: 0
Offline Offline

Posts: 2


WWW
« on: August 15, 2008, 10:16:06 AM »

Dear members,

  :o horror!
since some weeks i experience during european nighttimes massive spammail distribution through php-scripts (usually named help. php) placed in my CS-directory.  Provider already twice closed down my space. 

Log-files show logs like:
2008-04-18 05:30:02 yx xy|< REMOTE=189. 82. 98. 190 SCRIPT=/help. php -- /usr/sbin/sendmail -t -i
2008-04-18 05:30:02 xy xy <= S=rox@tim. com SZ=1992 D=0 SID=28972760
2008-04-18 05:31:03 xy xy => draconico_666@hotmail. com msmtp. kundenserver. de[172. 19. 35. 7] 250 Message 0ML25U-1JmhIZ0vVf-0001P6 accepted by mrelayeu5. kundenserver. de
and so on. 

who can i protect my space?
running CS 3. 2. 1 with a lot of selfmade templates

please help !!

greetings

Logged
DanO
Full Member
***

Karma: 13
Offline Offline

Posts: 230

Please don't PM me. Post in the open forum.


WWW
« Reply #1 on: August 15, 2008, 12:24:03 PM »

** placed in my CS-directory. **

Placed in your CS-directory how exactly??  Huh?

What permissions are the /calendarscript/ directory set to. It shouldn't need to be any more than 666 but setting it to 600 should prevent any scrips or files in it from being executed or even read from a browser but shouldn't affect the script's ability to use them.

If you're on a Unix based host, it should be possible to curtail the running of all PHP scripts in a particular directory using an .htaccess file.

** running CS 3.21 **

You're absolutely certain? You actually looked at the .pl files for their version number listed at the top? Is so, it may not be responsible for the file upload. Someone will need to investigate how those file(s) are being uploaded.

JMO

Dan O.
Logged
DJBAP
New Member
*

Karma: 0
Offline Offline

Posts: 2


WWW
« Reply #2 on: August 16, 2008, 12:48:52 AM »

thanks for the lesson.  

I changed permissions and discovered that i was running CS 3.  2 , not 3.  21
sorry
 Grin
Logged
Pages: [1]   Go Up
Print
Jump to: