osCommerce and osCMax shopping cart software forums

Shopping Cart Software

osCommerce with teeth!

 
 

Someone is spamming through my osCMax

This is a discussion on Someone is spamming through my osCMax within the osCMax v1.7 Discussion forums, part of the osCMax v1.7 Forums category; Hi, I recently discovered that someone is using the scripts in my osCMax installation to send spam. I'm not sure ...


Go Back   osCommerce and osCMax shopping cart software forums > osCMax v1.7 Forums > osCMax v1.7 Discussion

Register FAQ Members List Calendar Mark Forums Read


Free community membership! Fast easy FREE membership
Closed Thread

 

LinkBack Thread Tools
  #1  
Old 03-27-2007, 02:01 PM
New Member
 
Join Date: Dec 2006
Posts: 5
Thanks: 0
Thanked 1 Time in 1 Post
Rep Power: 0
shazam-fu is on a distinguished road
Default Someone is spamming through my osCMax

Hi,
I recently discovered that someone is using the scripts in my osCMax installation to send spam.

I'm not sure which script is being used but it could be any that use the following functions:
catalog_server2/includes/languages/english/contact_us.php
html/catalog/includes/languages/espanol/gv_send.php
html/catalog/includes/languages/english/gv_send.php
html/catalog/includes/languages/english/contact_us.php
html/catalog/includes/languages/german/gv_send.php

It's got to be one of these because the first subject in the spam header is "Enquiry from Southworth Company" and that text is used in the emails generated from those functions. There's a 2nd subject that replaces the first that just says "Hi."

Another part of the header is: X-Mailer: osCommerce Mailer

Is there any way to tighten up the functions to stop this? Has anyone else had this problem?

Thanks!

Last edited by shazam-fu; 03-27-2007 at 02:04 PM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Sponsored Links
Advertisement
  #2  
Old 03-27-2007, 02:39 PM
michael_s's Avatar
osCMax Developer

 
Join Date: Jul 2002
Location: Phoenix, AZ
Posts: 11,074
Thanks: 81
Thanked 348 Times in 327 Posts
Rep Power: 10
michael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond repute
Default Re: Someone is spamming through my osCMax

this is most likely the culprit:
catalog_server2/includes/languages/english/contact_us.php

And it was fixed in oscmax over a year ago. You need to patch your store:
osCommerce Documentation by OSCdox :: osCommerce and osCMax installation and users manual, discussion forums (Downloads)
__________________
Michael Sasek
osCMax Developer


  • osCMax Templates - Hundreds of premium quality templates designed for osCMax 2. Loyalty discounts up to 30% off!
    Each purchase supports the osCMax project with much needed funds!

  • xShop for osCMax - Windows Based osCMax administration. Improved workflow, security, speed and convenience.

  • osCMax Hosting - From basic hosting to High Availability, Load Balanced arrays, the most experienced osCMax host. Default multi server configuration for exceptional performance!

  • osCMax Template Tutorial - Learn how to make your own custom templates and how to use the powerful features of the osCMax template system.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #3  
Old 03-28-2007, 05:43 AM
New Member
 
Join Date: Dec 2006
Posts: 5
Thanks: 0
Thanked 1 Time in 1 Post
Rep Power: 0
shazam-fu is on a distinguished road
Default Re: Someone is spamming through my osCMax

Ahh, looks like I'll have to upgrade in order to fix the problem. Or will the patch work w/ v1.7?

I wouldn't mind upgrading except I'm nervous about it because there's a huge amount of data in the database. I've looked for an upgrade download but it looks like there are only full installs. Is that right? I haven't been able to find instructions for upgrading, either. But maybe I just haven't been able to find them. Are there any?

Thanks for your help!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #4  
Old 03-28-2007, 08:19 AM
michael_s's Avatar
osCMax Developer

 
Join Date: Jul 2002
Location: Phoenix, AZ
Posts: 11,074
Thanks: 81
Thanked 348 Times in 327 Posts
Rep Power: 10
michael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond repute
Default Re: Someone is spamming through my osCMax

The patch will work with 1.7, but you need to manually merge in the changes, and there are some changes you need to skip (they are pretty obvious, as the modified code that needs to be skipped is completely absent from osCMax v1.7).

I have done several manual patches of v1.7 and it works well. I suggest doing the patch on an off line copy of your store to work out any kinks before attempting on your live site.

There are no instructions for upgrading, as it is not something that anyone that needs instructions should be doing at this time. osCMax 2 is still being worked on, and the upgrade path is fraught danger for the average user of osCMax
__________________
Michael Sasek
osCMax Developer


  • osCMax Templates - Hundreds of premium quality templates designed for osCMax 2. Loyalty discounts up to 30% off!
    Each purchase supports the osCMax project with much needed funds!

  • xShop for osCMax - Windows Based osCMax administration. Improved workflow, security, speed and convenience.

  • osCMax Hosting - From basic hosting to High Availability, Load Balanced arrays, the most experienced osCMax host. Default multi server configuration for exceptional performance!

  • osCMax Template Tutorial - Learn how to make your own custom templates and how to use the powerful features of the osCMax template system.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #5  
Old 03-28-2007, 08:56 AM
New Member
 
Join Date: Dec 2006
Posts: 5
Thanks: 0
Thanked 1 Time in 1 Post
Rep Power: 0
shazam-fu is on a distinguished road
Default Re: Someone is spamming through my osCMax

Got it. Thanks very much!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Sponsored Links
Advertisement
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -8. The time now is 11:57 PM.


Powered by vBulletin®
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO
http://www.oscmax.com/forums/
Copyright 2008 osCMax