P.Z. Low Cost CPanel Web Hosting  

Go Back   P.Z. Low Cost CPanel Web Hosting > Page-Zone Web Hosting Main Forum > General FAQ > General Questions and Comments

General Questions and Comments Post your question or grace us with your knowledge. Posting limited to registered members.

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Formmail secure?
Old
  (#1 (permalink))
Eric Schreiber
Registered User
Eric Schreiber is on a distinguished road
 
Status: Offline
Posts: 30
Join Date: Mar 2003
Location: Plainfield IL
Rep Power: 37
Formmail secure? - 08-23-2003, 12:07 PM

Just a paranoia check, really. I noticed some attempts to access formmail at my domain, and wanted to be sure it was safe...


Host: 210.0.179.146 Url: /cgi-sys/formmail.pl Http Code : 200
Date: Aug 23 04:37:21 Http Version: HTTP/1.0" Size in Bytes: 250
Referer: http://www.ericschreiber.com/ Agent: -

Host: 210.242.69.243 Url: /cgi-sys/formmail.pl Http Code : 200
Date: Aug 23 04:35:33 Http Version: HTTP/1.0" Size in Bytes: 253
Referer: http://www.ericschreiber.com/ Agent: -

Host: 200.171.213.234 Url: /cgi-sys/formmail.pl Http Code : 200
Date: Aug 23 04:35:32 Http Version: HTTP/1.0" Size in Bytes: 250
Referer: http://www.ericschreiber.com/ Agent: -

Host: 202.184.1.40 Url: /cgi-sys/formmail.pl Http Code : 200
Date: Aug 23 04:35:19 Http Version: HTTP/1.0" Size in Bytes: 233
Referer: http://www.ericschreiber.com/ Agent: -

Host: 80.55.20.78 Url: /cgi-sys/formmail.pl Http Code : 200
Date: Aug 23 04:35:17 Http Version: HTTP/1.0" Size in Bytes: 227
Referer: http://www.ericschreiber.com/
   
Reply With Quote
yeah, me too...
Old
  (#2 (permalink))
stratplan
Registered User
stratplan will become famous soon enough
 
stratplan's Avatar
 
Status: Offline
Posts: 706
Join Date: Sep 2002
Location: Texas, USA
Rep Power: 74
Question yeah, me too... - 08-23-2003, 01:09 PM

I was sitting here looking at the latest 'formmail' script (NMS v. 3.09cl) that is supposed to be secure, wondering if I should install it.

I really need a formmail type program, and am familiar with cgi, but not php so I prefer not to go that (php) route to shorten the time and learning curve.

I received no reply on my previous query here,
http://www.page-zone.com/forums/show...light=formmail
and was thinking about opening a help ticket:



You can see Jim says it is a no-no like that, and I am surprised that renaming it would work, but if he says so, it must be.

Thanks for regenerating this puzzle. I'm looking forward to the response. Seems like the cgi-sys route would be secure.


stratplan
Click Here to Visit Page-Zone's Help Desk
Help find disease cures: FoldForCures
   
Reply With Quote
Old
  (#3 (permalink))
aaa
Registered User
aaa is on a distinguished road
 
Status: Offline
Posts: 2
Join Date: Aug 2003
Rep Power: 0
08-24-2003, 02:04 AM

The cgi-sys route is NOT safe to use.
   
Reply With Quote
Old
  (#4 (permalink))
Jim
of Page-Zone
Jim will become famous soon enoughJim will become famous soon enough
 
Status: Offline
Posts: 1,131
Join Date: Jun 2002
Location: Wauseon, Ohio
Rep Power: 98
My location
08-24-2003, 10:20 AM

Renaming it doesn't make it secure but it will stop the script kiddies from finding it. What they do is set a script loose crawling the internet looking for /cgi-bin/formail.pl (or a variation of that) on thousands of domain names.

Odds are EVERY site will eventually get crawled and if the script is sitting there it will be exploited. If the script is still there but called something else like /cgi-bin/send.pl it severely cuts down the chances of getting found by a bot, but it still isn't the best way. A script which can't be exploited is the best way but Matt Wright's formmail scripts always get cracked, and it looks like CPanel's version is a heavy target as well.


--
Thank You,
Jim Snape
Page-Zone
--
   
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Formmail not working bwit General Chat 3 12-28-2006 05:33 PM
Sendmail Formmail CGImail... neumannu47 General Questions and Comments 5 07-04-2004 09:00 PM
formmail redux...and rename... stratplan General Chat 14 09-26-2003 06:22 PM
formmail question paulj General Questions and Comments 4 07-04-2003 09:04 PM
Formmail Clone, cgiemail... Katrina General Questions and Comments 6 02-10-2003 05:32 AM


Live Help



Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0 RC6
vBulletin Skin developed by: vBStyles.com
Copyright © 2002 Page-Zone Web Hosting. All rights reserved.
Smilies provided by Crack's Smilies http://www.mysmilies.com