Spam Attack Vulnerability
-
Hi. I’ve been running subscribe2 for several years. Last week spammers were able to use the executable to spew 25,000 junk mails from our server using the exim mail utility. Here is an entry from the /var/log/exim_mainlog:
2015-08-06 07:41:00 cwd=/home/gowhn/public_html/blog-subdir/wp-content/plugins/subscribe2 4 args: /usr/sbin/sendmail -t -i -fsnamechanged@me.com
2015-08-06 07:41:00 1ZNLPo-0002rw-6Q <= NameAlsoChanged@me.com U=gowhn P=local S=1415 id=c01e8363ee09ecf26a3e8bdd097a7bff@domainchanged.com T=”Re:Adorable blonde strips spreads” from <AlsoNameChanged@me.com> for AnotherNameChanged@yahoo.comPlease evaluate the security vulnerability by assuring that it is wordpress that is calling the script, or preventing the script from activation from the mail via naked SMTP with a cmd= parameter.
Presentation of the arguments to the script enabled the script to run, and then stuffed my mail server with messages at the whim of the calling program. All the hacker had to do was “guess” the directory where subscribe2 was installed. Subscribe2 was disabled at the time the exploit occurred.
The topic ‘Spam Attack Vulnerability’ is closed to new replies.