Archive for the ‘Finesse’ Category

PixelPost and spam relaying

Wednesday, November 16th, 2005

I’m seeing an interesting new attack on my website where the attacker is hoping to exploit unchecked fields in a “web to email” form. The attack works by assuming a field used in an email header (such as the “From:” address or the “Subject:”) is passed unchecked to the mail subsystem. Appending a newline character and a few more carefully crafted header lines with a BCC list and a spam message body might trick the underlying mail system into relaying spam for the attacker. An initial test sending a BCC copy to killerhamster@punkass.com has been used on most forms on my site to phish for vulnerable scripts. I had an old perl script which didn’t check for new lines in the “email” field which alerted me to the problem and allowed me to quickly fix it. If you run a site, you should check and strip fields for carriage return and newline characters used directly in email headers.

Interesting Crack Attempt to Relay Spam

This morning my hosting provider pulled down my websites all of a sudden. When asked the reason was that some one is using my PixelPost installation at http://www.navakrish.com/photoblog to relay spam messages and that they have received numerous complaints from AOL within the last 24 hours.

Most of these messages were BCCd to ‘battsl1005@aol.com’ . A quick search on Google and I found the reference in this article – “Interesting Crack Attempt to Relay Spam”.

Thought it could help others and so I am sharing this here. I do not have much time to dig further into this problem and so I am temporarily disabling the comment feature in my photoblog.

technorati tags: , , , ,

The “Dirty Dozen”

Tuesday, February 1st, 2005

Dirty Dozen

The top twelve spam producing according to the latest report from Sophos.

1. United States – 42.11%
2. South Korea – 13.43%
3. China (incl Hong Kong) – 8.44%
4. Canada – 5.71%
5. Brazil – 3.34%
6. Japan – 2.57%
7. France – 1.37%
8. Spain – 1.18%
9. United Kingdom – 1.13%
10. Germany – 1.03%
11. Taiwan – 1.00%
12. Mexico – 0.89%
Others - 17.8%

Source: Sophos articles about spam: The “Dirty Dozen” 2004: Sophos reveals the top spamming countries

I hate these invitations

Wednesday, January 26th, 2005

Frustrated with the growing number of of invites I get every day to join hi5.com, I decided to google a bit to find why these people are spamming me.

Any one who thinks of joining hi5.com please read the following two pages before you come to a hasty decision.

(more…)

Telephone Spams

Sunday, August 22nd, 2004

When I got my new BT number I made sure to exclude my number from the telephone directory. And I have never disclosed the number to any one. But I still get annoying spam messages on my answerphone.

I am getting frustrated with the number of spams I receive in my voice mailbox. This is the latest spam I received yesterday.

(more…)

New scam

Thursday, July 15th, 2004

This one is a real beauty. Found this in a Yahoo Group for which I am a moderator. Whoever thought about this idea is an evil idot. (more…)

Desperate IT Consultant

Friday, July 9th, 2004

Had an interesting task yesterday. One of our new customers had a very serious problem. They have a PHP based website, which uses MySQL database for displaying the latest currency exchange rates. They update the exchange rates every day.

Their website was designed and maintained by another one-man company, whose owner/technical consultant has complete admin privileges to their webserver. Recently this customer gave us an order which involves completely rewriting their software and moving the hosting from the existing servers to their inhouse own servers. (Thanks to ADSL/SDSL everyone now thinks that they can do hosting internally.) Their existing software solution is very poorly written and does not serve any purpose.

The consultant who maintains their servers came to know this yesterday and this morning and decided to react in the worst possible manner. (more…)