Not ignoring you
As sad as this sounds..this is the first free minute I've had to post
in a while. I thought about putting up a post that said nothing
more then "This is all I have time to post today", but as it turned
out...I didn't have time. I discovered a hole in our template
websites two days ago, this allowed someone to go to a contact us form
and "inject" headers that basically sent the email to anyone they
wanted...as a Bcc no less. It's sad we had to deal with this, but
it's actually quite clever the way they did it. We allow a sender
to specify a "From" address in the auto generated email, and by adding
a %0A (the equivalent of a Line Feed or new line) they could specify an
virtually unlimited number of emails. So we found it, came up
with a fix and put it in play...then...a day later, we noticed that we
were still getting a ton of bounce messages from our mailserver...this
time from an account that I host "pro-bono" for Mingos! He had
been hit too, doh! This time we didn't make it off so
easily...the cracker that hit his site decided to target AOL customers
who promptly blacklisted our mailserver...it's only supposed to be for
24 hours...but it's still there...took another look and they hit his
site again..this time using the subject line which you can also inject
to...I fixed it for him though...
Comments