Getting hit hard with spam through the "contact us" form

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • cyburbia
    Senior Member
    • Aug 2001
    • 441
    • 3.7.x

    Getting hit hard with spam through the "contact us" form

    Today, I got hit with tens of drug spam messages throgh the "Contact us" form. All of it is from [email protected],. IP address of 85.255.117.18. Anyone else getting hit today?
    Cyburbia Forums - a third place for urban planners
    http://www.cyburbia.org/forums
  • Wayne Luke
    vBulletin Technical Support Lead
    • Aug 2000
    • 74111

    #2
    Do you have the image verification for this turned on? It was added in 3.5.0.
    Translations provided by Google.

    Wayne Luke
    The Rabid Badger - a vBulletin Cloud demonstration site.
    vBulletin 5 API

    Comment

    • cyburbia
      Senior Member
      • Aug 2001
      • 441
      • 3.7.x

      #3
      Yes, I do. That's why it seems so strange; who would go thorugh the problem of verifying it just to send spam to one person?

      A traceroute for 85.255.117.18 dies somewhere in West Virginia; not India like I'd expect for this type of spam.

      BTW, I just got hit with nine more spams from
      85.255.117.18.
      Cyburbia Forums - a third place for urban planners
      http://www.cyburbia.org/forums

      Comment

      • Reeve of Shinra
        Senior Member
        • Sep 2001
        • 4325
        • 4.0.0

        #4
        ban the ip at the server level and in vb
        Plan, Do, Check, Act!

        Comment

        • simsim
          Senior Member
          • Nov 2005
          • 1625
          • 3.6.x

          #5
          Actually DNSStuff.com records shows that this IP belongs to a hosting company in Ukraine. They have an abuse e-mail which you can complain to.

          See for details:
          You're spending millions of dollars on a website?!

          Comment

          • cyburbia
            Senior Member
            • Aug 2001
            • 441
            • 3.7.x

            #6
            Originally posted by simsim
            Actually DNSStuff.com records shows that this IP belongs to a hosting company in Ukraine. They have an abuse e-mail which you can complain to.
            I just googled, and found that the IP is responsible for a LOT of spam. I doubt the hosting company is going to do anything about it.
            Cyburbia Forums - a third place for urban planners
            http://www.cyburbia.org/forums

            Comment

            • MrNase
              Senior Member
              • Jun 2003
              • 3575
              • 3.8.x

              #7
              I am getting spam through that form from this IP: 84.19.186.155

              I've turned the image verification for guests on so see if that helps.


              The Spam I get uses the URL-BBcode and links to various subpages of http://[REMOVE]beliy.pbwiki.[REMOVE]com
              That's the end of that!

              Comment

              • ManagerJosh
                Senior Member
                • Jun 2002
                • 9922

                #8
                Looks like nLayer is one of the primary backbones for this guy too.
                ManagerJosh, Owner of 4 XenForo Licenses, 1 vBulletin Legacy License, 1 Internet Brands Suite License
                Director, WorldSims.org | Gaming Hosting Administrator, SimGames.net, Urban Online Entertainment

                Comment

                • Reverend
                  Senior Member
                  • Jul 2002
                  • 588
                  • 4.2.x

                  #9
                  Originally posted by cyburbia
                  Today, I got hit with tens of drug spam messages throgh the "Contact us" form. All of it is from [email protected],. IP address of 85.255.117.18. Anyone else getting hit today?
                  I was hit by them for a few days.

                  In the
                  "Allow Unregistered Users to use 'Contact Us'" setting, make sure you have selected the "Yes, but verify image" option from the drop down.

                  I only had mine set to "Yes" not realizing there was another option to verify the image as well. Since applying that setting i haven't received any more spam.
                  Techzonez - Tech News
                  Techzonez Forums - Tech Community

                  Comment

                  • cyburbia
                    Senior Member
                    • Aug 2001
                    • 441
                    • 3.7.x

                    #10
                    Originally posted by Reverend
                    I only had mine set to "Yes" not realizing there was another option to verify the image as well. Since applying that setting i haven't received any more spam.
                    That's the thing - I did have image verification turned on for the contact form. Seems like a LOT of trouble to go through just to spam one person.

                    As far as board registration goes, I've got most free Russian email providers and Yahoo.* among the banned addresses. Just blocking registration from Yahoo addresses stopped 95% of the spam that was posted.

                    EDIT: Amazing. My logs are showing a LOT of posts to vBulletin threads and nonexistent forms for other scripts I don't have (Moveable Type seems to be one of them) from 85.255.113.* to 85.255.117.* .
                    Last edited by cyburbia; Sat 10 Jun '06, 10:33am.
                    Cyburbia Forums - a third place for urban planners
                    http://www.cyburbia.org/forums

                    Comment

                    • cyburbia
                      Senior Member
                      • Aug 2001
                      • 441
                      • 3.7.x

                      #11
                      Originally posted by ManagerJosh
                      Looks like nLayer is one of the primary backbones for this guy too.
                      More stock graphics of the corporate-looking guy staring up at "endless opportunity" or something like that, with the usual skyscrapers in the background, along with liberal use of the word solutions. I don't trust companies like that, for some reason.
                      Cyburbia Forums - a third place for urban planners
                      http://www.cyburbia.org/forums

                      Comment

                      • Bob Isaac
                        Senior Member
                        • Dec 2005
                        • 771
                        • 3.8.x

                        #12
                        Does the 'contact us' form use the servers sendmail system?

                        Bob

                        Comment

                        • Quillz
                          Senior Member
                          • Nov 2004
                          • 2787
                          • 5.0.X

                          #13
                          Originally posted by Bob Isaac
                          Does the 'contact us' form use the servers sendmail system?

                          Bob
                          I think it uses sendmessage.php.
                          Forums

                          Comment

                          • Colin F
                            Senior Member
                            • May 2004
                            • 17689

                            #14
                            It uses sendmessage.php, which in turn uses the function you selected in your vBulletin Options, either mail() or SMTP.
                            Best Regards
                            Colin Frei

                            Please don't contact me per PM.

                            Comment

                            • Bob Isaac
                              Senior Member
                              • Dec 2005
                              • 771
                              • 3.8.x

                              #15
                              Oh well, I had hoped I could use sendmail's blocking systems to deal with this.

                              Bob

                              Comment

                              widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                              Working...