Receiving Spam Emails

2 replies
Joined: 10/09/2007
User offline. Last seen 6 weeks 3 hours ago.

Hi Andrew,

I have installed phpformmail on two websites and I am receiving spam messages through both sites. One in particular is www.kazed.com.au, now someone has been on the site and made some updates and the form on the index page doesn't work. Yet the spam emails are coming through as if they have been through the site. I have renamed the original file, so perhaps the spammers are picking up on something else. I use the senders email in the reply field - would this have a bearing on the code being spammed?

I have an example email:

Below is the result of your feedback form. It was submitted by
Smith (clingo44@ya.ru) on October 30th, 2008 at 02:09PM (GMT +11).

realname: Smith
Phone: sAwmnziEoxWXudqXI
email: clingo44@ya.ru
Description: Really, cool: [list of links to same website - removed]

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.
Joined: 06/04/2007
User offline. Last seen 21 hours 38 min ago.

Could you post the full headers of the email. As far as I know, there are currently no exploits but I've got to hand it to the spammers, they're dedicated to finding them.

Joined: 10/09/2007
User offline. Last seen 6 weeks 3 hours ago.

Here is the header info. Unfortunately this is another email I received, as the previous one was forwarded to me from my client, but came through the same way - oustide of the website!

Received: from apache by bq010.easily.co.uk with local (NetBenefit 2.0)
id 1KqrQA-0005WK-Lo ; Fri, 17 Oct 2008 16:39:22 +0100
To: design@sv2.co.uk
Subject: SV2: Website Contact Form
From: lalefxnqw
Reply-to: lalefxnqw
X-Priority: 0
X-Mailer: PHPFormMail Classic v1.07.2 (http://www.boaddrink.com)
X-Sender-IP: 94.102.49.85
X-Referer: http://www.sv2.co.uk/contact.htm
Content-Type: text/plain; charset=utf-8
Message-Id:
Sender: Apache
Date: Fri, 17 Oct 2008 16:39:22 +0100
X-NB-Virus-Scan: virus-free
X-Originally-To: design@sv2.co.uk

User login