Andy,

It's an email injection attack - generally harmless to cf servers - other
than the fact that YOU are receiving emails. Here's a blog post on the
topic:

http://mkruger.cfwebtools.com/index.cfm?mode=alias&alias=email%20injection

-Mark


-----Original Message-----
From: Andy Matthews [mailto:[EMAIL PROTECTED]
Sent: Tuesday, December 06, 2005 8:49 AM
To: CF-Talk
Subject: Spammers getting at my forms and submitting


I've recently had some attacks on a form which was created by a coworker.
Somehow, bots are using a subscription email form to send out spam. They're
using a jibberish email address from the domain I'm working with, but
somehow sending out emails to AOL users. The client is saying that in
addition to their being some crap in the registrations database, they're
also getting bounces from AOL with these addresses.

a) Has anyone else experienced this?
b) What can I do to prevent it?

I'd be happy to post the complete code for review if that would help.

<!----------------//------
andy matthews
web developer
ICGLink, Inc.
[EMAIL PROTECTED]
615.370.1530 x737
--------------//--------->




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~|
Find out how CFTicket can increase your company's customer support 
efficiency by 100%
http://www.houseoffusion.com/banners/view.cfm?bannerid=49

Message: http://www.houseoffusion.com/lists.cfm/link=i:4:226186
Archives: http://www.houseoffusion.com/cf_lists/threads.cfm/4
Subscription: http://www.houseoffusion.com/lists.cfm/link=s:4
Unsubscribe: http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=89.70.4
Donations & Support: http://www.houseoffusion.com/tiny.cfm/54

Reply via email to