Web Hosting Forum | Lunarpages
News: July 14, 2008 - New Contest! - Submit Your WordPress Theme Designs, Win BIG!
June 30, 2008 - Submit Your Site for the July 08 Site of the Month Award!
 
*
Welcome, Guest. Please login or register.
Did you miss your activation email?
July 25, 2008, 06:36:02 PM


Login with username, password and session length


Pages: [1]   Go Down
  Print  
Author Topic: I just got an email about secure scripts - what do I do???  (Read 4289 times)
Ed
Berserker Poster
*****
Offline Offline

Posts: 5206



WWW
« on: March 01, 2004, 04:16:18 PM »

Chances are your reading this because you just got an email (or a few) about insecure scripts from hostmaster@lunarpages.com or you got an email stating that your script has been renamed.

Due to some recent exploits on some of the formmail installations lunarpages is actively disabling exploited/able scripts following the emails being sent out.

You are highly recommended to switch any formmailing scripts over to the nms-cgi script which can be found at:

http://nms-cgi.sourceforge.net/tfmail.zip

When you configure it there are a few things to consider:
1) Upload the file in ASCII format - this is a primary cause of 500 server errors
2) CHmod it to 755 (unless directions specify otherwise
3) The path to sendmail on the system can be found in the main CPanel screen (usually located in the left bar near the bottom.
4) Same with the path to perl on your server.
5) do not name it with a name that contains "mail" or "formmail". This is not a security issue as much as the fact that there are spammer robots that crawl the web looking for files with names that contain "mail" and are a script - which they then bomb with exploit techniques, hoping to get through. This puts an unneccessary load on the server, so choosing a different name is wise.


At this time, there have been no listing of php based scripts with exploits. I will update this if I hear of any such announcements.

The current list of banned form mailing scripts are as follows:
Matt Wright?s FormMail
EZ Formmail
Jack?s FormMail
Big Nose Bird
Twebman?s Mail script (The perl version)

If you are wondering how the exploits work on some fo these scripts, search the forums and you will see several examples of possible exploitable lines of code.

Please refrain from posting in this thread unless it is to update this list etc. If you need help installing a script, please start a new thread, or join in a current one.

Hope this helps!

- Ed (Kata)
Security/C++ Perl Moderator
Logged

Ed
Berserker Poster
*****
Offline Offline

Posts: 5206



WWW
« Reply #1 on: March 01, 2004, 05:13:08 PM »

Just an update - looks like jacks formmail is php based. If you do not feel comfortable determining the security of the code, it will be wisest to go with the suggested script.

Also, with regards to some user questions about the chmod instructions. You only want to chmod the .pl file (Read any directions for more specific instructions).

- Ed
Logged

Johnny
Support
Über Jedi
*****
Offline Offline

Posts: 1915



« Reply #2 on: March 01, 2004, 07:12:42 PM »

I don't use form mail, but I received 3 emails from LP. I was spammed... lol
Logged

Ed
Berserker Poster
*****
Offline Offline

Posts: 5206



WWW
« Reply #3 on: March 01, 2004, 07:16:13 PM »

They sent out a few extra copies by mistake to some users.

- Ed
Logged

Ed
Berserker Poster
*****
Offline Offline

Posts: 5206



WWW
« Reply #4 on: March 04, 2004, 10:13:45 AM »

http://www.lunarforums.com/forum/viewtopic.php?t=12593

Is a wonderful tutorial written up by a lunarforums member to help everyone out! Take a look at it if you need step by step instructions.
Logged

Troy Laclaire
Support
Intergalactic Superstar
*****
Offline Offline

Posts: 156


Darkwolf


« Reply #5 on: May 21, 2008, 05:38:48 PM »

Above URL is no longer active.

Heres a tutorial put together by Priest.

http://www.lunarforums.com/lunarpages_how_tos/setting_up_the_tfmail_script-t12593.0.html;msg73952#msg73952
Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.3 | SMF © 2006-2007, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks


Valid XHTML 1.0! Valid CSS! Dilber MC Theme by HarzeM