Kryptronic Software Support Forum

You are viewing this forum as a guest. Login to an existing account, or create a new account, to reply to topics and to create new topics.

#1 08-09-2006 15:59:56

a2zoutletstore.com
Member
Registered: 08-09-2006
Posts: 4

Trying To Hack Site Through Contact Us Form

I need some help. I think someone is trying to hack my site or CCP through the contact us form.  I am getting about 20 emails a day like the one listed below. All are being returned and appear to have the same numbers on them. Anyone have any idea what this is and if indeed someone is trying to get in and how to stop them.

Here is a copy of what I get in the email.

The following information was just submitted on the A2Z Outlet Store web site.
Below are the details for the form submission.

First Name:
80000002

Last Name:
80000002

Email Address:
80000002

Telephone Number:
80000002

Have you placed an order already?:
Yes; No

If so, what is your order number?:
80000002

Where did you hear about us?:
80000002

May we contact you?:
Yes; No

Please enter your comments below.:
80000002

---------------------------------------------------

Here is a copy of the returned error email.

The original message was received at Wed, 9 Aug 2006 06:54:45 -0400
from localhost.localdomain [127.0.0.1]

----- The following addresses had permanent fatal errors -----
<forms@yourdomainname.com>
(reason: 554 <forms@yourdomainname.com>: Relay access denied)

----- Transcript of session follows -----
... while talking to yourdomainname.com.:
>>> DATA
<<< 554 <forms@yourdomainname.com>: Relay access denied
554 5.0.0 Service unavailable
<<< 554 Error: no valid recipients

Open Attachment 2
--- Forwarded Message ---
Date: [Wed, 9 Aug 2006 06:54 -0400]
From: jdevenney@a2zoutletstore.com
To: forms@yourdomainname.com

Subject: A2Z Outlet Store - Customer Feedback Form Confirmation

The following information was just submitted on the A2Z Outlet Store web site.
Below are the details for the form submission.

First Name:
80000002

Last Name:
80000002

Email Address:
80000002

Telephone Number:
80000002

Have you placed an order already?:
Yes; No

If so, what is your order number?:
80000002

Where did you hear about us?:
80000002

May we contact you?:
Yes; No

Please enter your comments below.:
80000002


Any help would be great.

Offline

 

#2 08-13-2006 14:36:10

Blitzen
Member
From: USA
Registered: 01-01-2005
Posts: 936

Re: Trying To Hack Site Through Contact Us Form

We had some novice hackers trying a similar feat - they had an auto script to input many email addresses and kept coming back. Fortunately, the CCP form doesn't allow enough chars to send many emails out.

We deactivated the CCP email contact form and instead use . Quite good for free.

Offline

 

#3 09-04-2006 18:22:42

cybermed
Member
From: Burke Va - US
Registered: 09-06-2001
Posts: 54
Website

Re: Trying To Hack Site Through Contact Us Form

We have the same problem in addition we are getting 100 emails from tell a friend feature.  I think there is a security hole here.  Any help?   

Offline

 

#4 09-04-2006 18:28:14

a2zoutletstore.com
Member
Registered: 08-09-2006
Posts: 4

Re: Trying To Hack Site Through Contact Us Form

I was told by kryptronic that it is actually a search engine bot searching our site and not a hacker trying to get through the system. The told me to block the IP address.

Offline

 

Board footer