Exploited Scripts

Exploited Scripts

by Fuad Luque -
Number of replies: 3

I received the following message from my ISP :

In an effort to proactively ensure the stability of our servers, we are regularly running a program to identify exploitable form mail scripts. Form mail scripts that are exploited will result in a deluge of spam being generated from our server, endangering our servers to blacklisting by ISPs. Also, because of the quantity of emails generated by these compromised scripts, it may cause an excessive load on the servers. This may mean services would have to be disabled or even the server rebooted if it got to a critical point.
 
We are asking your assistance with this to check your form codes for **poorly named scripts** or **insecure scripts**
 
Poorly named scripts are scripts with any extension that are named or have in their name mail, formmail or any variation thereof. In the case of poorly named scripts, please rename these to something more obscure. Scripts with these names are targeted for exploits and even scripts written well don't need the undue attention.
 
Insecure scripts are scripts we know to be exploitable and have already caused issues on our servers. If you have any of these, please disable them immediately.
What can i do to solve this?
Are moodle form mail scripts insecure?
Thanks for your help.
Average of ratings: -
In reply to Fuad Luque

Re: Exploited Scripts

by Huib van Wees -
HI,

I think you ISP does some checks on syntax in the scripts.
As moodle can send out a lot of mail (copy of forum posts) the scripts might look like a threat. Maybe the error script (which mails to the webmaster) may look like a threat.

Ask your provider which scripts they think there are a threat to their service and servers.

Hope this helps.

Regards,

Huib
In reply to Huib van Wees

Re: Exploited Scripts

by Fuad Luque -

Hi Huib,

This is the list of insecure scripts they know to be exploited:

Matt Wrights FormMail
EZ Formmail
Jacks FormMail
Big Nose Bird
Twebmans Mail script

In reply to Fuad Luque

Re: Exploited Scripts

by Huib van Wees -
Well, I don't think these scripts are included in Moodle.
But is your ISP able to provide a list of filenames which should be a threat ?

Regards,

Huib