Greetings!

I realize this is a little off topic for this list but hopefully it will
be considered a public warning / general courtesy message.  I know that
there are many on this list who offer domain & website hosting and so
might appreciate a head's up.

In our area recently the abuse of form-mailers as a means for spammers
to send out their messages anonymously has been absolutely rampant!
Local universities and other such entities have had to shut down their
form-mail until further notice while the problem is being addressed.  If
you haven't been hit you're lucky and should take the time to check out
your security on your form-mail.  We had our form-mail set to only allow
domains hosted on our servers to access it but were still exploited.

Once your server(s) get blackholed there is no end of work involved in
getting the issue resolved.  Not the least of which is dealing with all
your client complaints about their emails not getting through to people
they're sending mail to.  Another pain is that the application that the
spammers (usually porn btw) use effectively monopolizes port 80 on your
webserver so nothing else can talk to it and therefore even clients
without forms on their sites are affected by this security breech.

In our case we've moved to an authorized recipient list format for forms
which is a bit of an administrative pain in that every time there's a
new mailbox that forms need to be sent to we need to update the list but
this is far better than doing nothing.  Other people are moving to
CGIEmail which apparently does the job too. (In our case we didn't want
to force our clients to rework their forms so it wasn't an option for
us.)

I won't go into more detail because this isn't really a domain
registration issue but if there are folks on this list that are saved
the many hours of grief that we went through because I took the time to
type this then I'll feel a like it was time well spent.

Cheers.

Jack Broughton
CanTech Solutions

Reply via email to