Engineering Leader · Private Pilot · Dad · PSU Hockey
OAT 72° XPDR 1200 GS 145 18:42Z
10
20
10
20
160150140130120110100
138
32003100300029002800
3,000
306090120150
90
My Life
Bio & background
PROFILE · SET
My Computers
Current rigs
UPTIME · 100%
My Projects
What I'm building
STATUS · ACTIVE
Résumé
Curriculum vitae
FORMAT · HTML

Not ignoring you

11/19/05 @ 2:55 pm · By Steve Hoffman · Comments (1) · Leave one
As sad as this sounds..this is the first free minute I've had to post in a while.  I thought about putting up a post that said nothing more then "This is all I have time to post today", but as it turned out...I didn't have time.  I discovered a hole in our template websites two days ago, this allowed someone to go to a contact us form and "inject" headers that basically sent the email to anyone they wanted...as a Bcc no less.  It's sad we had to deal with this, but it's actually quite clever the way they did it.  We allow a sender to specify a "From" address in the auto generated email, and by adding a %0A (the equivalent of a Line Feed or new line) they could specify an virtually unlimited number of emails.  So we found it, came up with a fix and put it in play...then...a day later, we noticed that we were still getting a ton of bounce messages from our mailserver...this time from an account that I host "pro-bono" for Mingos!  He had been hit too, doh!  This time we didn't make it off so easily...the cracker that hit his site decided to target AOL customers who promptly blacklisted our mailserver...it's only supposed to be for 24 hours...but it's still there...took another look and they hit his site again..this time using the subject line which you can also inject to...I fixed it for him though...
  

Comments

Bugs · 11/21/05 @ 4:02 am · Mingos
weeeeeell... ain't I a stinka?