how could you tell if your site was hacked & sending emails

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • djjeffa
    Senior Member
    • Jul 2004
    • 241
    • 3.6.x

    how could you tell if your site was hacked & sending emails

    I just got an auto responce from an email i didnt send and there are over 100 recipants on it. The subject was work at home and it had some my host info and said sent via vbulletin. And ideals?
    www.djjeffa.com
  • djjeffa
    Senior Member
    • Jul 2004
    • 241
    • 3.6.x

    #2
    this is the email I got
    Code:
    The message you sent requires that you verify that you 
    are a real live human being and not a spam source.
     
    To complete this verification, simply reply to this message and leave
    the subject line intact.
     
    The headers of the message sent from your address are shown below:
     
    From [email protected] Wed Feb 01 13:38:31 2012
    Received: from smarty.dreamhost.com ([208.113.175.8]:39524)
    	by gator156.hostgator.com with esmtp (Exim 4.69)
    	(envelope-from <[email protected]>)
    	id 1Rsg0k-0005QK-Vw
    	for [email protected]; Wed, 01 Feb 2012 13:38:31 -0600
    Received: from raptors.dreamhost.com (raptors.dreamhost.com [69.163.171.157])
    	by smarty.dreamhost.com (Postfix) with ESMTP id 22F85760056;
    	Wed,  1 Feb 2012 11:38:29 -0800 (PST)
    Received: by raptors.dreamhost.com (Postfix, from userid 584256)
    	id 9B415286678; Wed,  1 Feb 2012 11:38:28 -0800 (PST)
    To [COLOR=#FF0000] Email addresses removed but there were about 100
    [/COLOR]Subject: This Work At Home Position is Perfect for You
    From: "djjeffa.com" <[COLOR=#FF0000]my email address I removed it for this post>[/COLOR]
    Auto-Submitted: auto-generated
    Message-ID: <20120201193828.508bf7593020@[COLOR=#FF0000]www.djjeffa.com[/COLOR]>
    MIME-Version: 1.0
    Content-Type: text/plain; charset="UTF-8"
    X-Priority: 3
    X-Mailer: [COLOR=#FF0000]vBulletin Mail via PHP
    [/COLOR]Date: Wed,  1 Feb 2012 11:38:28 -0800 (PST)
    Content-Transfer-Encoding: quoted-printable
    X-Spam-Status: No, score=2.8
    X-Spam-Score: 28
    X-Spam-Bar: ++
    X-Spam-Flag: NO
    www.djjeffa.com

    Comment

    • oldengine
      Senior Member
      • Oct 2004
      • 342
      • 3.7.x

      #3
      This is a new exploit. See: https://www.vbulletin.com/forum/show...mail-log/page2

      Comment

      • Wayne Luke
        vBulletin Technical Support Lead
        • Aug 2000
        • 74132

        #4
        Originally posted by oldengine
        Can you show us the proof of this?
        Translations provided by Google.

        Wayne Luke
        The Rabid Badger - a vBulletin Cloud demonstration site.
        vBulletin 5 API

        Comment

        • Wayne Luke
          vBulletin Technical Support Lead
          • Aug 2000
          • 74132

          #5
          Originally posted by djjeffa
          I just got an auto responce from an email i didnt send and there are over 100 recipants on it. The subject was work at home and it had some my host info and said sent via vbulletin. And ideals?
          Attach your mail server logs please.
          Translations provided by Google.

          Wayne Luke
          The Rabid Badger - a vBulletin Cloud demonstration site.
          vBulletin 5 API

          Comment

          • oldengine
            Senior Member
            • Oct 2004
            • 342
            • 3.7.x

            #6
            Problem located to Photopost Gallery misc.php emailimage

            Exploiter
            124.107.69.88 - check your server log.

            Comment

            • Wayne Luke
              vBulletin Technical Support Lead
              • Aug 2000
              • 74132

              #7
              Originally posted by oldengine
              Problem located to Photopost Gallery misc.php emailimage

              Exploiter
              124.107.69.88 - check your server log.

              So not a vBulletin issue. Thanks for clarifying.
              Translations provided by Google.

              Wayne Luke
              The Rabid Badger - a vBulletin Cloud demonstration site.
              vBulletin 5 API

              Comment

              widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
              Working...