| Home | Register | FAQ | Members List | Search | Today's Posts | Mark Forums Read |
|
|
#1 (permalink) |
|
Registered User
|
Unauthorized access to a web form
Hi Let me see if I can explain this. I manage several sites and on some of them I use a cgi Form for the visitor to send comments, requests, etc. I use the same code on all the sites. I just customize the contents. Never had a problem before. Several months ago I created a site which is a pretty simple 5-page personal html site and posted the form on the Contact Us page. Very soon after, I started to receive spam posts. No biggie. Then I started receiving submissions that were not in the correct format. The form is submitted to me via email and should look like this: The form below was submited by 123@abc.com from Ip address: 00.00.00.00 on June 1, 2008 at 23:04 FormsEditField1: me FormsEditField2: ll FormsMultiLine1: bvnvmnvmnvmnbvn Instead, it looked like this: The form below was submited by from Ip address: 202.166.170.5 on June 2, 2008 at -12:57 --xYzZY Content-Disposition: form-data; name: "subject"<br> Web Comment<br> xYzZY<br> Content-Disposition: form-data; name I couldn't figure out what was happening, so I got rid of the form, but I still noticed many more hits on the contact page than the home page. So I renamed the contact page. I also banned all search engines from spidering anything but the home page, so no references to any of the other pages exist on the web. I looked at the server stats and the log today. It seems that many people are still trying to open the old contact page, because there are several page errors per day in the log. The ip address are from all over the world, mostly in third world countries, which is weird. Does anyone have an idea of what is going on here? I really suspect hackers are trying to use my form for something devious. |
|
|
|
![]() |