Web Hosting Forum | Lunarpages
News: July 14, 2008 - New Contest! - Submit Your WordPress Theme Designs, Win BIG!
June 30, 2008 - Submit Your Site for the July 08 Site of the Month Award!
 
*
Welcome, Guest. Please login or register.
Did you miss your activation email?
July 25, 2008, 04:54:49 PM


Login with username, password and session length


Pages: [1]   Go Down
  Print  
Author Topic: I just got an email about secure scripts - what do I do???  (Read 3531 times)
Ed
Berserker Poster
*****
Offline Offline

Posts: 5206



WWW
« on: March 01, 2004, 04:37:14 PM »

Chances are your reading this because you just got an email (or a few) about insecure scripts from hostmaster@lunarpages.com or you got an email stating that your script has been renamed.

Due to some recent exploits on some of the formmail installations lunarpages is actively disabling exploited/able scripts following the emails being sent out.

You are highly recommended to switch any formmailing scripts over to the nms-cgi script which can be found at:

http://nms-cgi.sourceforge.net/tfmail.zip

When you configure it there are a few things to consider:
1) Upload the file in ASCII format - this is a primary cause of 500 server errors
2) CHmod it to 755 (unless directions specify otherwise
3) The path to sendmail on the system can be found in the main CPanel screen (usually located in the left bar near the bottom.
4) Same with the path to perl on your server.
5) do not name it with a name that contains "mail" or "formmail". This is not a security issue as much as the fact that there are spammer robots that crawl the web looking for files with names that contain "mail" and are a script - which they then bomb with exploit techniques, hoping to get through. This puts an unneccessary load on the server, so choosing a different name is wise.


At this time, there have been no listing of php based scripts with exploits. I will update this if I hear of any such announcements.

The current list of banned form mailing scripts are as follows:
Matt Wright?s FormMail
EZ Formmail
Jack?s FormMail
Big Nose Bird
Twebman?s Mail script (The perl version)

If you are wondering how the exploits work on some fo these scripts, search the forums and you will see several examples of possible exploitable lines of code.

Please refrain from posting in this thread unless it is to update this list etc. If you need help installing a script, please start a new thread, or join in a current one.

Hope this helps!

- Ed (Kata)
Logged

Ed
Berserker Poster
*****
Offline Offline

Posts: 5206



WWW
« Reply #1 on: March 01, 2004, 05:09:58 PM »

Just an update - looks like jacks formmail is php based. If you do not feel comfortable determining the security of the code, it will be wisest to go with the suggested script.

Also, with regards to some user questions about the chmod instructions. You only want to chmod the .pl file (Read any directions for more specific instructions).

- Ed
Logged

Max
Lunarpages
Über Jedi
*****
Offline Offline

Posts: 2550



WWW
« Reply #2 on: March 03, 2004, 11:50:49 PM »

Excellent tutorial by tfota on how to setup tfmail can be found here http://www.lunarforums.com/viewtopic.php?t=12589  enjoy! Smile
« Last Edit: July 23, 2005, 06:19:03 PM by Pete » Logged
simchippy
Newbie
*
Offline Offline

Posts: 3


« Reply #3 on: November 30, 2005, 02:15:35 PM »

What about the cgi email script in cPanel, CGI Center. Can we use it as long as we rename the file?

Thanks
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.3 | SMF © 2006-2007, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks


Valid XHTML 1.0! Valid CSS! Dilber MC Theme by HarzeM