This is part of The Pile, a partial archive of some open source mailing lists and newsgroups.
To: Perrin Harkins <perrin@elem.com> From: Matt Sergeant <matt@sergeant.org> Subject: Re: formmail spammers Date: Sat, 12 Jan 2002 07:12:47 +0000 (GMT) On Fri, 11 Jan 2002, Perrin Harkins wrote: > > I assume I'm not the only one seeing a rash of formmail spam lately. > > Is THAT what it is? I have a Yahoo mail account which someone has been > sending literally thousands of messages per day to, CC'ing lots of > people on every one, and they all appear to be from some kind of > compromised form mailer script. I'm open to any suggestions. http://www.spamassassin.org/ Without a doubt, the best anti-spam solution around. === To: "Matt Sergeant" <matt@sergeant.org> From: "Perrin Harkins" <perrin@elem.com> Subject: Re: formmail spammers Date: Sat, 12 Jan 2002 12:44:07 -0500 > http://www.spamassassin.org/ > > Without a doubt, the best anti-spam solution around. That looks great for solving the problem on my own account, but the larger problem is that there are all of these insecure installations of formmail.pl out there that spammers are using to send tons of mail. It's like having an open relay. A program to check for these on Google and then alert the webmaster at each offending site could be a really good thing. === To: Perrin Harkins <perrin@elem.com> From: Ged Haywood <ged@www2.jubileegroup.co.uk> Subject: Re: formmail spammers Date: Sun, 13 Jan 2002 21:20:31 +0000 (GMT) On Sat, 12 Jan 2002, Perrin Harkins wrote: > > http://www.spamassassin.org/ > > > > Without a doubt, the best anti-spam solution around. > > That looks great for solving the problem on my own account, Well it might look great, but the only result I've had from it so far is MORE SPAM! Mail:: SpamAssassin's "make test" failed for me (apparently similar problems have been seen and should have been fixed but aren't), no response from the mailing list (admittedly after only 24 hours:) to a question - but loads of spam through their list server! === To: modperl@apache.org From: "A.T.Z." <verkoop@atz.nl> Subject: Re: formmail spammers Date: Mon, 14 Jan 2002 15:22:03 +0100 >so, we've been having a spam problem lately due to formmail.pl. this >thread prompted me to scan all our user directories and note people >who had formmail.pl sitting around. We hardcoded the TO address in FormMail.pl and tell all our customers to do the same. Spammers trying to use the script will fail. Only the address in the TO field gets one messages.. Perhaps not the best solution around, but it will do until we fix something else. They don't get their spam out to the world. And we send their ISP a nice notification about what that user was trying to do. Complete with logfiles.. Once you're a know target they will come back.. ===