Web Hosting Forum | Lunarpages
News: October 6, 2008 - Submit Your Site for the October 2008 Site of the Month!
 
*
Welcome, Guest. Please login or register.
Did you miss your activation email?
October 13, 2008, 12:03:37 AM


Login with username, password and session length


Pages: [1]   Go Down
  Print  
Author Topic: Strange form responses - technical bug or prankster???  (Read 231 times)
darng
Space Explorer
***
Offline Offline

Posts: 8


« on: June 20, 2008, 01:29:53 PM »

We have a form on our website that is really the lifeblood of our website - and it's been working perfectly.  Except in the past two days we have received 3 separate responses that are highly strange.  They're all very similar but slightly different.  We're not sure if they're from a technical bug or a prankster, but they make us worried because we need our form to work 100% perfectly.  Has anyone seen anything like this (see below)?  Is it just a weird prank, or is there something wrong with our CGI script or settings.  BTW, whenever we test the form from any computer, it works perfectly for us.

Here are two of the strange responses, so you can get the idea.  The field names all precede the colons:

Below is the result of your feedback form.  It was submitted by
pdbzingrcd (deorjx@nnzjze.com) on Wednesday, June 18, 2008 at 13:14:23
---------------------------------------------------------------------------


PlaceName: pdbzingrcd

DigsLocation: xDqbophooPgLGXRTZ

trip_date_month: 11

trip_date_year: 2003 or Before

Othertext: UvtDbikdVAXVH

Whysodarngood: HGlmob  <a href="http://shhyqwcwrcgu.com/">shhyqwcwrcgu</a>, aeqxueqpxbju, [link=http://xkofslqwzvvx.com/]xkofslqwzvvx[/link], http://ulufnugkywzw.com/

Location: HGlmob  <a href="http://shhyqwcwrcgu.com/">shhyqwcwrcgu</a>, aeqxueqpxbju, [link=http://xkofslqwzvvx.com/]xkofslqwzvvx[/link], http://ulufnugkywzw.com/

Room: HGlmob  <a href="http://shhyqwcwrcgu.com/">shhyqwcwrcgu</a>, aeqxueqpxbju, [link=http://xkofslqwzvvx.com/]xkofslqwzvvx[/link], http://ulufnugkywzw.com/

Food: HGlmob  <a href="http://shhyqwcwrcgu.com/">shhyqwcwrcgu</a>, aeqxueqpxbju, [link=http://xkofslqwzvvx.com/]xkofslqwzvvx[/link], http://ulufnugkywzw.com/

Vibe: HGlmob  <a href="http://shhyqwcwrcgu.com/">shhyqwcwrcgu</a>, aeqxueqpxbju, [link=http://xkofslqwzvvx.com/]xkofslqwzvvx[/link], http://ulufnugkywzw.com/

KeepinMind: HGlmob  <a href="http://shhyqwcwrcgu.com/">shhyqwcwrcgu</a>, aeqxueqpxbju, [link=http://xkofslqwzvvx.com/]xkofslqwzvvx[/link], http://ulufnugkywzw.com/

Home: IgXPjKrmYx

Age: 46-65

---------------------------------------------------------------------------

AND THE SECOND STRANGE RESPONSE:

Below is the result of your feedback form.  It was submitted by
fvdlvfaxntv (jjnenw@lznwqb.com) on Friday, June 20, 2008 at 09:12:55
---------------------------------------------------------------------------


PlaceName: fvdlvfaxntv

DigsLocation: DbzuDZhAkih

trip_date_month: 8

trip_date_year: 2007

Othertext: cnWrTMJnAhV

Whysodarngood: 1ezIoq  <a href="http://gahrzewfvtlj.com/">gahrzewfvtlj</a>, xkyuoeautpfc, [link=http://tzosqswivkva.com/]tzosqswivkva[/link], http://hjulniytthey.com/

Location: 1ezIoq  <a href="http://gahrzewfvtlj.com/">gahrzewfvtlj</a>, xkyuoeautpfc, [link=http://tzosqswivkva.com/]tzosqswivkva[/link], http://hjulniytthey.com/

Room: 1ezIoq  <a href="http://gahrzewfvtlj.com/">gahrzewfvtlj</a>, xkyuoeautpfc, [link=http://tzosqswivkva.com/]tzosqswivkva[/link], http://hjulniytthey.com/

Food: 1ezIoq  <a href="http://gahrzewfvtlj.com/">gahrzewfvtlj</a>, xkyuoeautpfc, [link=http://tzosqswivkva.com/]tzosqswivkva[/link], http://hjulniytthey.com/

Vibe: 1ezIoq  <a href="http://gahrzewfvtlj.com/">gahrzewfvtlj</a>, xkyuoeautpfc, [link=http://tzosqswivkva.com/]tzosqswivkva[/link], http://hjulniytthey.com/

KeepinMind: 1ezIoq  <a href="http://gahrzewfvtlj.com/">gahrzewfvtlj</a>, xkyuoeautpfc, [link=http://tzosqswivkva.com/]tzosqswivkva[/link], http://hjulniytthey.com/

Home: QqBDBtIpFhJnlVqdvR

Age: -25

---------------------------------------------------------------------------

 
Logged
Mitch
Lunarpages Traffic Cop
Senior Moderator
Berserker Poster
*****
Offline Offline

Posts: 7949



WWW
« Reply #1 on: June 20, 2008, 01:31:46 PM »

Looks like spam to me. 
Logged

darng
Space Explorer
***
Offline Offline

Posts: 8


« Reply #2 on: June 20, 2008, 01:38:05 PM »

Could be, but would a spammer come to our website and fill out the form?  Because all the field names are correct - it looks exactly like any other form response we receive in our email inbox, except it's weird - with all those letters, with a fake email address, and weird html script. 
« Last Edit: June 21, 2008, 08:23:20 AM by darng » Logged
scanman20
Master Jedi
*****
Offline Offline

Posts: 1251



WWW
« Reply #3 on: June 20, 2008, 08:48:12 PM »

Doesn't your script put the field names before whatever is entered by the user, or in this case spambot? I agree with Mitch, looks 100% like spam to me. BTW, spammers don't visit sites. They run scripts that either search for, or process lists of existing forms automatically and in large batches.
Logged

Even a broken clock is right twice a day.
NotOneBit.com
MCSE - MCSA - MCP
darng
Space Explorer
***
Offline Offline

Posts: 8


« Reply #4 on: June 21, 2008, 04:41:48 AM »

Great.  That makes total sense.  I didn't realize that spammers could run scripts like that - without actually vistiting our website in person.  Is there a way to block that kind of spam - or is it just something we should expect, and disregard?

Thanks so much!
Logged
katrina1
Support Supervisor
Über Jedi
*****
Offline Offline

Posts: 2040



WWW
« Reply #5 on: June 21, 2008, 05:16:24 AM »

You should add a captcha to the form.
http://www.captcha.net/
http://recaptcha.net/captcha.html
http://captchas.net/
Logged

Hey, Rocky! Look. Nothing up my sleeve... presto a rabbit!

Lunarpages Web Hosting

Lunarpages Forums

Lunarpapages Affiliate Program
scanman20
Master Jedi
*****
Offline Offline

Posts: 1251



WWW
« Reply #6 on: June 21, 2008, 07:41:36 AM »

hey katrina, how about plugging someone who's been an LP customer for five years? Wink

http://www.notonebit.com/projects/killbot/
Logged

Even a broken clock is right twice a day.
NotOneBit.com
MCSE - MCSA - MCP
darng
Space Explorer
***
Offline Offline

Posts: 8


« Reply #7 on: June 21, 2008, 08:25:19 AM »

Again, thanks so much to everyone.  Now it all makes sense.  I do have one more question - just out of curiosity.  I always thought spammers wanted to sell things or drive traffic to their sites.  Why would the spam form responses I received just be complete gibberish - the links don't mean anything? 
Logged
scanman20
Master Jedi
*****
Offline Offline

Posts: 1251



WWW
« Reply #8 on: June 21, 2008, 09:12:36 PM »

Could be a site coming in the future and the spammer planting seeds or an old script being used with a dead site. Spammers aren't the brightest bulb in the chandelier.
Logged

Even a broken clock is right twice a day.
NotOneBit.com
MCSE - MCSA - MCP
MichaelT
Support
Galactic Royalty
*****
Offline Offline

Posts: 285


« Reply #9 on: June 21, 2008, 11:24:47 PM »

Again, thanks so much to everyone.  Now it all makes sense.  I do have one more question - just out of curiosity.  I always thought spammers wanted to sell things or drive traffic to their sites.  Why would the spam form responses I received just be complete gibberish - the links don't mean anything? 
Could also be they are just checking to see if email accounts are valid so they can "harvest" them for future spamming or to sell to others. Basically looking to see those that don't bounce back or get out of office/auto replies, etc.
Logged

Michael Torrance
Customer Service Representative

Lunarpages Web Hosting
Lunarpages Forums
Lunarpapages Affiliate Program

Telephone: 1-714-521-8150
Fax: 1-714-521-8195
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.6 | SMF © 2006-2008, Simple Machines LLC

Valid XHTML 1.0! Valid CSS! Dilber MC Theme by HarzeM