<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html" />
  <link rel="self" type="application/atom+xml" href="http://ask-leo.com/atom.xml" />
  <id>tag:ask-leo.com,2009://3/tag:ask-leo.com,2003://3.1850-</id>
  <updated>2009-11-19T14:02:17Z</updated>
  <title>Comments for A spammer is using my cgiemail, what do I do?</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.25</generator>

  <entry>
    <id>tag:ask-leo.com,2003://3.1850-comment:977</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2003://3.1850" type="text/html" href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html#c977" />
    <title>Comment from Brian on 2009-01-03</title>
    <author>
      <name>Brian</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>For a real solution that introduces an optical security feature bundled in a PHP program that is easily implemented and thoroughly documented FOR FREE, go to:<br />
<a href="http://www.dagondesign.com/articles/secure-php-form-mailer-script"><a href="http://www.dagondesign.com/articles/secure-php-form-mailer-script"><a href="http://www.dagondesign.com/articles/secure-php-form-mailer-script">http://www.dagondesign.com/articles/secure-php-form-mailer-script</a></a></a></p>

<p>Regarding question: Is there a way to find all pages that use cgiemail?</p>

<p>Well, the simple way would be to remove all permissions from the cgi-script...then they will come to you when it no longer works!</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html">A spammer is using my cgiemail, what do I do?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-01-03T15:16:03Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2003://3.1850-comment:976</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2003://3.1850" type="text/html" href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html#c976" />
    <title>Comment from Rick on 2008-07-06</title>
    <author>
      <name>Rick</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>Thanks for this script, Leo. The only problem that I am having is getting the prefix "required-" to work. I must be missing something, but if the form has a field input name "required-firstName" and the template has [required-firstName] one can still send the form without filing in the first name field.</p>

<p>Other than that, it works great and I love the new parameter prefixes. Thanks.</p>

<p>Rick</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html">A spammer is using my cgiemail, what do I do?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2008</a>.</p>
    </content>
    <published>2008-07-06T16:12:54Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2003://3.1850-comment:975</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2003://3.1850" type="text/html" href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html#c975" />
    <title>Comment from Maryann on 2006-11-28</title>
    <author>
      <name>Maryann</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>Hello,</p>

<p>I would like to use tmail.pl but my hosting service does not support it.  They say to use the NET::SMTP component, as opposed to Sendmail.</p>

<p>Do you know what that means and how I get around it?</p>

<p>Thanks<br />
Maryann</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html">A spammer is using my cgiemail, what do I do?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2006</a>.</p>
    </content>
    <published>2006-11-28T22:44:52Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2003://3.1850-comment:974</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2003://3.1850" type="text/html" href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html#c974" />
    <title>Comment from Leo on 2004-11-02</title>
    <author>
      <name>Leo</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>Don't know if there is one, but this would be the place to start looking: <a href="http://web.mit.edu/wwwdev/cgiemail/"><a href="http://web.mit.edu/wwwdev/cgiemail/"><a href="http://web.mit.edu/wwwdev/cgiemail/">http://web.mit.edu/wwwdev/cgiemail/</a></a></a></p>]]>
      <p>A comment on: <a href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html">A spammer is using my cgiemail, what do I do?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2004</a>.</p>
    </content>
    <published>2004-11-02T21:32:14Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2003://3.1850-comment:973</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2003://3.1850" type="text/html" href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html#c973" />
    <title>Comment from Larry on 2004-11-02</title>
    <author>
      <name>Larry</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>Does anyone have a "patched" copy of cgiemail that I can simply ftp upload to my server to overwrite my existing one? I am not a "c" programmer and don't have a compiler either.</p>

<p>Any help is appreciated.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html">A spammer is using my cgiemail, what do I do?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2004</a>.</p>
    </content>
    <published>2004-11-02T13:27:28Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2003://3.1850-comment:972</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2003://3.1850" type="text/html" href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html#c972" />
    <title>Comment from Leo on 2004-07-20</title>
    <author>
      <name>Leo</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>A poorly designed template can still be exploited. Do let me know if you find out something more.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html">A spammer is using my cgiemail, what do I do?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2004</a>.</p>
    </content>
    <published>2004-07-20T21:34:03Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2003://3.1850-comment:971</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2003://3.1850" type="text/html" href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html#c971" />
    <title>Comment from Jef Spelman on 2004-07-20</title>
    <author>
      <name>Jef Spelman</name>
      <uri>http://hostcentric.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://hostcentric.com">
      <![CDATA[<p>Hello,<br />
  It has been brought to my attention that tmail is exploitable. I am in the process of working out with my SA where the problem lies, please feel free to contact me via telephone at 407.445.3033x2167. I am available from 4PM-12AM tuesday through saturday.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html">A spammer is using my cgiemail, what do I do?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2004</a>.</p>
    </content>
    <published>2004-07-20T21:26:16Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2003://3.1850-comment:970</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2003://3.1850" type="text/html" href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html#c970" />
    <title>Comment from LeoN on 2003-10-18</title>
    <author>
      <name>LeoN</name>
      <uri>http://ask-leo.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://ask-leo.com">
      <![CDATA[<p>For the record: tmail.pl is in Perl, and once you download it it's easy to modify and you can do so to your heart's content.</p>

<p>Leo</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html">A spammer is using my cgiemail, what do I do?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2003</a>.</p>
    </content>
    <published>2003-10-19T05:39:02Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2003://3.1850-comment:969</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2003://3.1850" type="text/html" href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html#c969" />
    <title>Comment from Kit Peters on 2003-10-18</title>
    <author>
      <name>Kit Peters</name>
      <uri>http://www.clownswilleatyou.com/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.clownswilleatyou.com/">
      <![CDATA[<p>Well, by default there's a header field enabled:</p>

<p>"X-Mailer: cgiemail "</p>

<p>If one personally doesn't expect to recieve mail generated by a web form (which, if one doesn't have a website with such a form, is a pretty safe bet) one can add a filter to block mails coming with that particular header.</p>

<p>That's an individual, and not systematic, solution, however.  I myself prefer FormMail because the source is more easily modifiable, and you don't have to compile it.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html">A spammer is using my cgiemail, what do I do?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2003</a>.</p>
    </content>
    <published>2003-10-18T15:16:21Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2003://3.1850-comment:968</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2003://3.1850" type="text/html" href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html#c968" />
    <title>Comment from Leo on 2003-10-17</title>
    <author>
      <name>Leo</name>
      <uri>http://pugetsoundsoftware.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://pugetsoundsoftware.com">
      <![CDATA[<p>"Is there a way to find all pages that use cgiemail?" Not that I'm aware of offhand. Search engine cataloging of the usage of cgiemail is spotty at best, since most of the search engines avoid a lot of dynamic content and/or cgi scripts. Most ISPs are (or should be) on various security mailing lists that have discussed this issue. It's quite common to find cgiemail on ISP provided web hosts, and if they're on top of things, they'll be aware of the problem. Certainly they will be if they get hijacked.</p>

<p>Leo</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html">A spammer is using my cgiemail, what do I do?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2003</a>.</p>
    </content>
    <published>2003-10-18T05:46:07Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2003://3.1850-comment:967</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2003://3.1850" type="text/html" href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html#c967" />
    <title>Comment from Carl Manaster on 2003-10-17</title>
    <author>
      <name>Carl Manaster</name>
      <uri>http://www.fotolog.net/cmanaster</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.fotolog.net/cmanaster">
      <![CDATA[<p>Is there a way to find all pages that use cgiemail?  It would be a great service to all of us if someone could find them all and email the webmasters to inform them of the spammer hijacking risk and possible fixes.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/a_spammer_is_using_my_cgiemail_what_do_i_do.html">A spammer is using my cgiemail, what do I do?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2003</a>.</p>
    </content>
    <published>2003-10-18T05:23:12Z</published>
  </entry>

</feed>
