Web Hosting Forum | Lunarpages


*
Welcome, Guest. Please login or register.
Did you miss your activation email?



Login with username, password and session length
March 19, 2010, 06:53:10 AM

Pages: [1]   Go Down
  Print  
Author Topic: I just got an email about secure scripts - what do I do???  (Read 6180 times)
Ed
Berserker Poster
*****
Offline Offline

Posts: 5208



WWW
« on: March 01, 2004, 04:16:18 PM »

Chances are your reading this because you just got an email (or a few) about insecure scripts from hostmaster@lunarpages.com or you got an email stating that your script has been renamed.

Due to some recent exploits on some of the formmail installations lunarpages is actively disabling exploited/able scripts following the emails being sent out.

You are highly recommended to switch any formmailing scripts over to the nms-cgi script which can be found at:

http://nms-cgi.sourceforge.net/tfmail.zip

When you configure it there are a few things to consider:
1) Upload the file in ASCII format - this is a primary cause of 500 server errors
2) CHmod it to 755 (unless directions specify otherwise
3) The path to sendmail on the system can be found in the main CPanel screen (usually located in the left bar near the bottom.
4) Same with the path to perl on your server.
5) do not name it with a name that contains "mail" or "formmail". This is not a security issue as much as the fact that there are spammer robots that crawl the web looking for files with names that contain "mail" and are a script - which they then bomb with exploit techniques, hoping to get through. This puts an unneccessary load on the server, so choosing a different name is wise.


At this time, there have been no listing of php based scripts with exploits. I will update this if I hear of any such announcements.

The current list of banned form mailing scripts are as follows:
Matt Wright?s FormMail
EZ Formmail
Jack?s FormMail
Big Nose Bird
Twebman?s Mail script (The perl version)

If you are wondering how the exploits work on some fo these scripts, search the forums and you will see several examples of possible exploitable lines of code.

Please refrain from posting in this thread unless it is to update this list etc. If you need help installing a script, please start a new thread, or join in a current one.

Hope this helps!

- Ed (Kata)
Security/C++ Perl Moderator
Logged

Ed
Berserker Poster
*****
Offline Offline

Posts: 5208



WWW
« Reply #1 on: March 01, 2004, 05:13:08 PM »

Just an update - looks like jacks formmail is php based. If you do not feel comfortable determining the security of the code, it will be wisest to go with the suggested script.

Also, with regards to some user questions about the chmod instructions. You only want to chmod the .pl file (Read any directions for more specific instructions).

- Ed
Logged

Johnny
MR-Disabled
Über Jedi
*
Offline Offline

Posts: 1914



« Reply #2 on: March 01, 2004, 07:12:42 PM »

I don't use form mail, but I received 3 emails from LP. I was spammed... lol
Logged

Ed
Berserker Poster
*****
Offline Offline

Posts: 5208



WWW
« Reply #3 on: March 01, 2004, 07:16:13 PM »

They sent out a few extra copies by mistake to some users.

- Ed
Logged

Ed
Berserker Poster
*****
Offline Offline

Posts: 5208



WWW
« Reply #4 on: March 04, 2004, 10:13:45 AM »

http://www.lunarforums.com/forum/viewtopic.php?t=12593

Is a wonderful tutorial written up by a lunarforums member to help everyone out! Take a look at it if you need step by step instructions.
Logged

Troy L
Support
Galactic Royalty
*****
Offline Offline

Posts: 405


Darkwolf


« Reply #5 on: May 21, 2008, 05:38:48 PM »

Above URL is no longer active.

Heres a tutorial put together by Priest.

http://www.lunarforums.com/lunarpages_how_tos/setting_up_the_tfmail_script-t12593.0.html;msg73952#msg73952
Logged

mslink
Newbie
*
Offline Offline

Posts: 3


« Reply #6 on: January 21, 2009, 07:19:31 PM »

Hello, I tried setting up TFMail (followed the instructions at http://www.lunarforums.com/lunarpages_how_tos/setting_up_the_tfmail_script-t12593.0.html) - I've tried setting it up 3 times now, and each time the email address I enter on the form I've created gets the copy of the information but the email address I setup to receive the information doesn't get a copy.... Any suggestions or tips? Is there another script other than TFMail that would work or am I the only one having the problem? Thanks for your help, this is driving me nuts!
Logged
Troy L
Support
Galactic Royalty
*****
Offline Offline

Posts: 405


Darkwolf


« Reply #7 on: January 21, 2009, 09:05:08 PM »

Do you experience any other issues with email?

Is the email that should be receiving the email one on your account?
Logged

caree19
Newbie
*
Offline Offline

Posts: 4


« Reply #8 on: February 03, 2009, 08:40:51 PM »

I uploaded twice the recommended script in my cgi directory, and still it does not work. When I call to technical support they tell me that this is a webpage development issue and that they cannot help me. I am reading some articles advising to use php instead of perl (public_html instead of cgi directory) because there are a lot of problems with perl to upload it. I am a little bit confuse. I am getting help from other colleague in this forum, but still if Lunarpages encourages the use of perl...
Anyway, I hope anyone can help me. I uploaded the script correctly, but the webpage is badly created. I would need some support. Thanks

I checked all these points
1) Uploading in ASCII format
2) CHmod it to 755
3) Path to sendmail and to perl on the system
5) name other than "mail" or "formmail"
Logged
Meilena
Galactic Royalty
*****
Offline Offline

Posts: 206


« Reply #9 on: February 21, 2009, 01:05:51 PM »

Hi,

Did you ever resolve this issue?  I normally use php scripts and install Captcha or akismet to secure the form and prevent bots from using my forms to send out spam under my domain.
Logged

Kind Regards,
Meilena Hauslendale
Customer Service Representative
 
Support and Assistance:
Help Desk - http://support.lunarpages.com/
FAQ - http://support.lunarpages.com/faq.php
Membership Forum - http://www.lunarforums.com/
Tutorials - http://www.lunarpages.com/tutorials/

Lunarpages Web Hosting

Lunarpages Forums

Lunarpapages Affiliate Program


support@lunarpages.com

Telephone: 1-714-521-8150
Fax: 1-714-521-8195
Troy L
Support
Galactic Royalty
*****
Offline Offline

Posts: 405


Darkwolf


« Reply #10 on: February 23, 2009, 10:17:06 AM »

Note to anyone who uses the TFMAIL script. 

If you use a 3rd party for your email services (such as google or other 3rd party email providers), you need to contact support, have your MX records setup on the server, and your domain removed from "local domains".

Failure to do this will result in emails not being delivered from the form to your domain.

 Happy Happy Joy Joy Happy Happy Joy Joy Happy Happy Joy Joy  Clapping Clapping
Logged

garymeek
Newbie
*
Offline Offline

Posts: 5


WWW
« Reply #11 on: April 27, 2009, 06:39:55 PM »

I have followed the instructions in the link specified in #5:




Darkwolf


View Profile
   
   
Re: I just got an email about secure scripts - what do I do???
« Reply #5 on: May 21, 2008, 05:38:48 PM »
   Reply with quoteQuote
Above URL is no longer active.

Heres a tutorial put together by Priest.

http://www.lunarforums.com/lunarpages_how_tos/setting_up_the_tfmail_script-t12593.0.html;msg73952#msg73952

However am having no success.  When I save the configuration, I get an Applications Error message.  I am new to this and could use some assistance.  Can anyone take a look at what i have and let me know what is wrong?

Other suggestions?


Logged

Gary W. Meek
Pages: [1]   Go Up
  Print  
 
Jump to: