Help - Search - Members - Calendar
Full Version: MT Comment Forms Used for Spam?
Movable Type Community Forum > Other Product Discussion > Bugs and Odd Behavior
orty
I glanced through the MT Support Forums and didn't see anything in regards to this, but I didn't have a whole lot of time to look.

Here's what's happening: Every couple weeks, I'll get a few comments that do this type of thing:

In the author field: "angelrrsmr@aol.comTo: angelrrsmr@aol.comFrom: angelrrsmr@aol.comSubject: kvlP(C87BA01E,author)ZOl"
In the e-mail address field: "angelrrsmr@aol.comTo: angelrrsmr@aol.comFrom: angelrrsmr@aol.comSubject:"
In the URL Field: "http:// angelrrsmr@aol.comFrom: angelrrsmr@aol.comSubject: aw(C87BA01E,url)OY4QK1FA2lmq5DIVMRq28RS0KB Ed WPJEfnH3l7M06xz9."
In the comment field: "body"

Herein lies the problem: When I get my e-mail notification for comments, I notice that the "To:" field not only has my e-mail address, but "angelrrsmr@aol.com". So I don't know what else they could be using this for, but I could see this getting exploited.

My comment notification e-mails come up looking like this:

QUOTE
A new comment has been posted on your blog UtterlyBoring.com, on entry
#1602 (Want a really long e-mail address?).
http://utterlyboring.com/archives/2004/03/...ddress.php#2531

IP Address: 137.164.143.111
Name: angelrrsmr@aol.com
To: angelrrsmr@aol.com
From: angelrrsmr@aol.com
Subject: kvlP(C87BA01E,author)ZOlL2KUa

bebrrG5sr6xaIp3ejB Ik


Anybody else run into this? I've posted an entry on my blog as well.
srijith
Other than that it is a comment spam, I wonder how it can be exploited in other ways?

The comment notification email you received could only have been received by you. I don't think the codes can be exploited to send the same email to any arbitary person.

Even though the text portion after the "IP Address: 137.164.143.111" line in your notification email looks like an email, it is not a email by itself.

To be sure, can you check your mail logs to see if the email was sent to anyone else?
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2008 Invision Power Services, Inc.