"
But couldn't find any links that were any help.
So next I investigated the content of the emails for common factors and found the following Javascript snippet began every message body:
"var defDoor"... before launching into other Javascript elements, followed by the keywords and links.
I wonder...
A quick search on Google and two factors astonished me...
1) Google showed up 92,600 pages with this code on, of which every one I checked matched the exact spam posts I was seeing in style and content. So we were dealing with a professional of some magnitude.
2) They were all on forums, but not the one I used, but WWWBoard as available from http://www.scriptarchive.com/wwwboard.html
A quick search with my FTP software through the bowels of my admittedly large site that has been online for 5 years or so and has seen more reworkings than Pamela Anderson showed I *had* got WWWBoard installed on my site but had stopped using it years ago in place of my current forum software.
I had completely forgotten about it, and there were the hundreds of spam posts sitting there on my server!
Obviously I don't use the script so instantly deleted it and the spamming stopped dead overnight but if I'm one of over 90,000 victims this guy has duped then a little advice is necessary:
1) Appreciate that there are security flaws to WWWBoard and you either need to watch your forum very carefully or consider switching to another script.
2) Don't leave old scripts sitting around on your server waiting for spammers to abuse them. Use them, or delete them.
3) Try to avoid using obvious folders for scripts. Whilst I didn't link to my old forum from anywhere on the site, it was in an obvious folder so a spammer (or a script) could easily have guessed it.
4) Realise that security threats are very real if you get reasonable traffic and take steps *in advance* to minimize the risk to your own site.
------
=======================================================
Richard Adams is the founder of http://www.merchantaccountforum.com , one of the net's most popular merchant account advice sites.
=======================================================
This article is free for republishing
Printed From: http://www.articlealley.com/article_45086_3.html
Back to the original article
Tags: google, hyperlinks, email addresses, ips, magnitude, spammer, common factors, discussion forum, generation software, paris