Forums

Contact Form 7
[resolved] Contact Form 7 being used to send spam, despite Akismet (1 post)

  1. gillespieza
    Member
    Posted 1 year ago #

    My system emails on my linux server have been getting "message undelivered" emails which appear to be sent from the Contact Form 7 widget I had on my website (I have removed the widget, for now).

    The odd thing is, there is no "to:" field in the widget - just "from" and "message". And yet the "undelivered messages" include random to:addresses.

    I have Akismet set up, and I have tested that it works successfully (I get the spam failure message when I test with their test-spam-email address).

    Clearly, something somewhere is being highjacked. Perhaps some sort of php mailer (don't know what contact form 7 uses - built in wp_mail?). How do I stop it?

    I've contacted my host but they are unable to help me, other than to say "Disable Contact Form 7", which I don't want to do.

    Email message below. The bottom bits were bits I added to my contact form in my WordPress installation, which is the only reason I figured out it was coming from my Contact Form 7 widget:

    From: Mail Delivery System
    To: mysystemusername@constantine.dreamhost.com
    Subject: Undelivered Mail Returned to Sender
    Date: Sun, 16 Jan 2011 02:13:01 -0800 (PST)
    Message-Id: <deleted>
    
    [-- Attachment #1: Notification --]
    [-- Type: text/plain, Encoding: 7bit, Size: 0.6K --]
    
    This is the Postfix program at host pants.dreamhost.com.
    
    I'm sorry to have to inform you that your message could not be
    be delivered to one or more recipients. It's attached below.
    
    For further assistance, please send mail to <postmaster>
    
    If you do so, please include this problem report. You can
    delete your own text from the attached returned message.
    
                            The Postfix program
    
    <esysdsq3614@yahoo.com>: host e.mx.mail.yahoo.com[67.195.168.230] said: 554
        delivery error: dd This user doesn't have a yahoo.com account
        (esysdsq3614@yahoo.com) [-5] - mta1038.mail.ac4.yahoo.com (in reply to end
        of DATA command)
    
    [-- Attachment #2: Delivery report --]
    [-- Type: message/delivery-status, Encoding: 7bit, Size: 0.5K --]
    
    Reporting-MTA: dns; pants.dreamhost.com
    X-Postfix-Queue-ID: DBA1514C005
    X-Postfix-Sender: rfc822; mysystemusername@constantine.dreamhost.com
    Arrival-Date: Sun, 16 Jan 2011 02:12:56 -0800 (PST)
    
    Final-Recipient: rfc822; esysdsq3614@yahoo.com
    Action: failed
    Status: 5.0.0
    Diagnostic-Code: X-Postfix; host e.mx.mail.yahoo.com[67.195.168.230] said: 554
        delivery error: dd This user doesn't have a yahoo.com account
        (esysdsq3614@yahoo.com) [-5] - mta1038.mail.ac4.yahoo.com (in reply to end
        of DATA command)
    
    [-- Attachment #3: Undelivered Message --]
    [-- Type: message/rfc822, Encoding: 8bit, Size: 1.5K --]
    
    From: floppyk2011 <esysdsq3614@yahoo.com>
    To: esysdsq3614@yahoo.com
    Subject: [Out In Africa]
    Date: Sun, 16 Jan 2011 10:12:57 +0000
    X-Mailer: PHPMailer (phpmailer.sourceforge.net) [version 2.0.4]
    
    Message body:
    �èñòåìà àêòèâíîé ðåêëàìû.  �àðàáîòàòü â ñåòè. �ïëàòà çà ÷òåíèå ïèñåì è êëèêè. �àñêðóòêà ñàéòîâ - óâåëè÷åíèå ïîñåùàåìîñòè, íèçêèå öåíû äëÿ ðåêëàìîäàòåëåé!he system of active advertising. Earn online. Payment
    +for reading emails and clicks. Site promotion - increase attendance, lower prices for advertisers!<a href=http://somespamlinkhere.com>ôëóïèê.ðô</a>
    
    --
    This mail is sent via contact form on Out In Africa (www.oia.co.za), from IP address: 80.58.205.99
    </pre>

    http://wordpress.org/extend/plugins/contact-form-7/

Topic Closed

This topic has been closed to new replies.

About this Plugin

About this Topic