This is a classic case of someone not having formmail.pl from Matt's Script
archive locked down.

I found it very interesting that while Matt's Script Archive is setup to
block you from using someone else's form as a referer to yours to prevent
the use of your script from another server, he simply allows you through if
you have no referer at all. And that's how someone used our server several
times about 6 months ago. If you format a perfect querystring and simply hit
enter on the browser, you can successfully send many people e-mail through
formmail.pl if it's not modified to block 'no referer' references.

On 7/26/2001 8:29 PM this was written:

> Below is the result of your feedback form.  It was submitted by
> ([EMAIL PROTECTED]) on Thursday, July 26, 2001 at 20:29:47
> ---------------------------------------------------------------------------
> 
> : Join for free Today.
> Free Memberships. No Credit Cards Needed.
> HUGE Celebrity selection from Jennifer Lopez to Britney Spears.
> Also Specializing Streaming Video, Live sex shows for every desire!
> This isn't one of those crummy scams where you have touse a credit card!
> Take a look and you'll see.
> <a href="aol://2000:http://coverme1.devil.ru";>Enter Here</a>
> 
> 
> <BR><BR><BR><BR><BR><BR><BR>
> 
> You recived this email because you subscribed to a mailing list. If you would
> like to be removed from this mailing list please <a
> href="mailto:[EMAIL PROTECTED]";>Click Here!</a><BR><BR><BR><BR><BR><BR><BR>
> 
> ---------------------------------------------------------------------------
> 
> 
> -- 
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: [EMAIL PROTECTED]
> For additional commands, e-mail: [EMAIL PROTECTED]
> To contact the list administrators, e-mail: [EMAIL PROTECTED]

-- 

Thomas Deliduka
IT Manager
     -------------------------
New Eve Media
The Solution To Your Internet Angst
http://www.neweve.com/



-- 
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]
To contact the list administrators, e-mail: [EMAIL PROTECTED]

Reply via email to