North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: - What hack is this?

  • From: Jeff Wasilko
  • Date: Sun Jan 27 22:09:10 2002

On Sun, Jan 27, 2002 at 08:54:42PM -0600, John Palmer (NANOG Acct) wrote:
> Anyone hear of some sort of a cracking method that uses cgi-bin/formmail?
> I've seen alot of these in my httpd/access_log files
> lately. I don't have anywhere on my system - I flushed all of
> the cgi-bin stuff that came with apache a long time ago.

Spammers use it for sending spam. Early versions of FormMail
didn't do any input checking and could be used to send mail to
any recipient.