PDA

View Full Version : Heads up for some Cpanel users


Joe Gronlund
Wed 27th Aug '03, 8:33pm
This issue is not affecting me; but is affecting a couple people i know.


AnnouncementAuthor:adminTime:19-8-2003-1:25 PSubject:FormMail Attempt Messages

Announcement:If you are receiving email messages containing the following text, please ignore
them. The FormMail clone script installed with Cpanel is installed system-wide
and cannot be disabled. These messages are generated when someone attempts to ex
ploit /cgi-sys/formmail.pl via your domain name. Since the FormMail script that
comes with Cpanel is *not* exploitable you can disregard.

--Example--
From: eP2aBq4S6F@yourdomain.com
Date: Tue Aug 19, 2003 4:30:17 AM US/Pacific
To: eP2aBq4S6F@yourdomain.com
Subject: http://www.yourdomain.com.com/cgi-sys/formmail.pl
--/Example--



Source: VenturesOnline Helpdesk

eva2000
Thu 28th Aug '03, 3:30am
i just delete formmail.pl after each cpanel update heh

Joe Gronlund
Thu 28th Aug '03, 8:38am
i just delete formmail.pl after each cpanel update heh
Sounds like a good idea to me, thanks for the tip, didnt know if it was a safe thing to do :)

Thanks george

The Realist
Mon 23rd Aug '04, 4:18pm
Is it safe to delete formmail.pl from the server and does V use it it anyway?

Reason I ask is Im getting a lot of the following and it could be formmail: unrouteable mail domain sending out emails from VB.

Wayne Luke
Mon 23rd Aug '04, 5:08pm
It should be safe to delete it. vBulletin doesn't use any external scripts that are not included in the download package.

Joe Gronlund
Mon 23rd Aug '04, 8:26pm
Is it safe to delete formmail.pl from the server and does V use it it anyway?

Reason I ask is Im getting a lot of the following and it could be formmail: unrouteable mail domain sending out emails from VB.

If your using cpanel and have disabled "user nobody from sending out scripts", uncheck it,,