Forum Home
Press F1
 
Thread ID: 61435 2005-09-04 23:30:00 website enquiry form problem, spam? virus? Morgenmuffel (187) Press F1
Post ID Timestamp Content User
386018 2005-09-04 23:30:00 Hi all

The business websites enquiry form is suddenly getting a lot of traffic and the messages are in this form it almost seems someone is putting a message header into the email address

(thecompany = our company name)




Customers Name:
Customers Email: omnkgpzbkl@thecompany.com Customers Phone:
Page Information requested: omnkgpzbkl@thecompany.com
Content-Type: multipart/mixed; boundary="===============1767040462=="
MIME-Version: 1.0
Subject: 292e0db
To: omnkgpzbkl@thecompany.com
bcc: mhkoch321@aol.com
From: omnkgpzbkl@thecompany.com

This is a multi-part message in MIME format.

--===============1767040462==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit

kprkx
--===============1767040462==--
Information requested:
Customers Address:


//What a correct enquiry should look like

Customers Name: Nigel
Customers Email: nigel@myemail.nz
Customers Phone: 1234567
Page Information requested:
Information requested: I want to test this site
Customers Address:179 some Street
Morgenmuffel (187)
386019 2005-09-05 07:39:00 my site has been getting the same thing.....
i think i recived two over the weekend, i might look more in to it....

do you have IP address of who did the submit??
robsonde (120)
386020 2005-09-05 07:45:00 both my hits where from 210.0.200.2
first at Fri 10:44:20 GMT
and again at Fri 10:44:26 GMT

i think it might be looking for a web to mail type thing.
if the AOL address gets the email then it must be a web to mail gateway if not then its not good for spaming??
robsonde (120)
386021 2005-09-06 00:33:00 Ours weren't from the same ip address unfortunately,

203.196.250.67

213.249.155.231

195.101.157.172

there were more i think but Can't be bothered looking

I looked up the stats page and for these visits there is

no referrer listed (page they came from)
no agent listed (user agent)

Which makes them stand out from everything else

I really know nothing about this type of thing, so any help would be appreciated Cheers
Morgenmuffel (187)
386022 2005-09-06 00:42:00 I just realised the aol address is the same between the emails did a search on it and came up with this (tech.communityarchitect.com 8558) Morgenmuffel (187)
1