Who We Are
bmk
girlie
kristine
Search



Notify List
Let us keep you posted on new entries! Join the notify list!
Blog Status
14 entries
146 comments
12.06.04 11:44 am last update
last 50 referrers

Listed on BlogShares
Syndication
link to us!

virtual venus

virtual venus: MT Wiki
Powered By
because weblogs need love too
Sunday, November 23, 2003
"Mail This Entry" Used For Spam

SEE UPDATE BELOW

If you are using Movable Type's "Mail This Entry" feature on your blog, you are advised to rename your mt-send-entry.cgi file, or remove the feature entirely.

If you are not using the feature on your blog, you still need to either rename the script, disable it by changing the permissions, or remove it from your server altogether.

Spammers have discovered a means of using this script to send messages that will appear to be coming from your server.

Renaming the script won't prevent them from finding it if you continue to use the feature on your site, but it will slow them down a little if everyone chooses a unique name for the script.

Also, if you're using other versions of this feature such as Pop-Up Mail This Entry or MT-Mail-Entry, you may want to take a similar approach to those as well.

If there are any developers out there interested in working on a fix for this vulnerability, please leave a comment and I will contact you with the details of the method being used (if you need them).

Update: Ben posted a fix in the previously-mentioned forum thread:

Before line 40 in mt-send-entry.cgi, add these lines:

die "Invalid from or to value"
if $to =~ /[\r\n]/ || $from =~ /[\r\n]/;

Save mt-send-entry.cgi, upload to your server in ASCII mode, and CHMOD permissions to 755 again (if necessary).

(Cross-posted at The Girlie Matters)


Comments: 4

Hi, do you know if this is still the case if one has installed the blacklist spammer tool?

by Rori at 01:54 AM on 11.24.03

I don't think that Ben's fix is an adequate fix. It would still be relatively simple for a spammer to use the script to send emails from your server. I've just disabled the script completely on my server. I don't use the feature it supplies anyway so it's no great loss.

by richard at 03:38 PM on 11.24.03

Rori, MT-Blacklist has no interaction with mt-send-entry.cgi that I am aware of. It affects comments and trackbacks only as far as I know.

by girlie at 06:38 PM on 11.24.03

new mt-send-entry.cgi file released by MT:

http://www.movabletype.org/news/2003_11.shtml#000873

by demonsurfer at 04:16 PM on 11.27.03
Comments are closed on this entry
More Entries

Copyright © Virtual Venus