Gossamer Forum
Home : General : Chit Chat :

Everyone please take a moment to read....

 
Everyone please take a moment to read....
Just a brief word before I begin the bulk of this post, and that is... I have received permission from Gossamer-Threads before posting this.

Ok here we go....

Well today I received 1100+ spam submissions to one of my contact forms (well actually it ended up being three different forms before I blocked it).

The first thing I did apart from secure the form to prevent anyone being able to spam it was check my access log.

Here's what I saw:

www21.web2010.com - - [19/Apr/2002:00:43:29 -0500] "POST /cgi-bin/contact/index.cgi HTTP/1.0" 302 0 "-" "SecretAgent/1.0 libwww-per$
www21.web2010.com - - [19/Apr/2002:00:43:29 -0500] "POST /cgi-bin/contact/index.cgi HTTP/1.0" 302 0 "-" "SecretAgent/1.0 libwww-per$
www21.web2010.com - - [19/Apr/2002:00:43:29 -0500] "POST /cgi-bin/contact/index.cgi HTTP/1.0" 302 0 "-" "SecretAgent/1.0 libwww-per$
www21.web2010.com - - [19/Apr/2002:00:43:30 -0500] "POST /cgi-bin/contact/index.cgi HTTP/1.0" 302 0 "-" "SecretAgent/1.0 libwww-per$
www21.web2010.com - - [19/Apr/2002:00:43:30 -0500] "POST /cgi-bin/contact/index.cgi HTTP/1.0" 302 0 "-" "SecretAgent/1.0 libwww-per$


....around 1100 entries.

So I went to web2010.com and sent an email to the hostmaster asking him to investigate who had posted 1100 form submissions.

Whilst I was waiting for the reply I also noticed the user-agent was ServerAgent/1.0.....the code used to do this was code I myself had posted at the forum yesterday so I came to the conclusion it had to be a forum member who had used my own code against me.

Well for anyone to spam me they have to know how the contact form works and in order to do this they have to visit the form in person to check it out. So I checked back in my log for the hour or so before the attack.....here's what I found:

bus178s048.colorado.edu - - [19/Apr/2002:00:25:50 -0500] "GET /contact/ HTTP/1.1" 200 2292 "http://www.wiredon.net/" "Mozilla/4.0 ($
bus178s048.colorado.edu - - [19/Apr/2002:00:26:08 -0500] "POST /cgi-bin/contact/index.cgi HTTP/1.1" 302 338 "http://www.wiredon.net$
bus178s048.colorado.edu - - [19/Apr/2002:00:26:08 -0500] "POST /cgi-bin/contact/index.cgi HTTP/1.1" 302 5 "http://www.wiredon.net/c$
bus178s048.colorado.edu - - [19/Apr/2002:00:26:08 -0500] "GET /contact/success.shtml HTTP/1.1" 200 1563 "http://www.wiredon.net/con$
n

...a happy camper testing out my contact form....funny that as just before the spamming I received two test submissions from test@test.tv

So Im getting closer........this gives me an ISP hostname.....but who can it be......

So I go back to the forum and find the ip of the most obvious suspect and do a traceroute....

IP: 128.138.178.48

Traceroute leads me to....

17 bus178s048.Colorado.EDU (128.138.178.48) 42.579 ms 43.683 ms 46.521 ms

Well hang on a minute....thats the same as the hostname for the "tester"

Maybe Im on to something here.....

So who do I know from Colorado?.....hm....a forum member from Colorado is Eliot Lee....hmmm his URL is Anthrotech.com.....

Oh look:

Anthro TECH, L.L.C was established in December 1997. Anthro TECH provides innovative Web resources and services for the anthropological community and general public. Anthro TECH, L.L.C is currently based in Rollinsville, Colorado.

Well well well......

So I tootle off to networksolutions.com to use their handy whois service....

Whois anthrotech.com I wonder?.....well I'll tell you......

http://www.netsol.com/...om&SearchType=do

Would you look at that. Who is the technical contact for the domain anthrotech.com ?......surprise...it is HOSTMASTER@WEB2010.COM...the email address I originally emailed right at the beginning which matched the several thousand hits in my access log.

We have our culprit ladies and genlemen.

Eliot Lee - anthrotech.com aka Heckler, Chewbacca and Anthrorules

I will be notifying Eliot's Internet Service Provider and it goes without saying the whole colorado.edu network has been banned from my server.

I will also be notifying Colorado University too that Eliot has been spamming websites from their network (infact I sent them an email 10 minutes ago).

Thanks for reading.

Edit: Hehe next time I won't publically post that my form mailer was put together in about 10 mins....for any Eliot wannabe's you won't be able to do it again...thats not a challenge :)

Last edited by:

Paul: Apr 18, 2002, 12:12 PM
Subject Author Views Date
Thread; locked thread Everyone please take a moment to read.... Paul 18749 Apr 18, 2002, 11:52 AM
Thread Re: [Paul] Everyone please take a moment to read....
Philip_Clark 18359 Apr 18, 2002, 6:04 PM
Thread Re: [Philip_Clark] Everyone please take a moment to read....
Paul 18275 Apr 19, 2002, 2:49 AM
Thread Re: [Paul] Everyone please take a moment to read....
Paul 18454 Apr 19, 2002, 6:51 AM
Thread Re: [Paul] Everyone please take a moment to read....
Watts 18209 Apr 19, 2002, 10:10 AM
Thread Re: [Watts] Everyone please take a moment to read....
Paul 18145 Apr 19, 2002, 11:55 AM
Thread Re: [Paul] Everyone please take a moment to read....
LoisC 18134 Apr 20, 2002, 12:31 AM
Thread Re: [LoisC] Everyone please take a moment to read....
Paul 18118 Apr 20, 2002, 1:42 AM
Thread Re: [Paul] Everyone please take a moment to read....
Michael_Bray 18119 Apr 20, 2002, 7:11 AM
Thread Re: [Michael_Bray] Everyone please take a moment to read....
Andy 18029 Apr 20, 2002, 7:54 AM
Thread Re: [Andy.] Everyone please take a moment to read....
Wil 18224 Apr 20, 2002, 8:11 AM
Post Re: [Wil] Everyone please take a moment to read....
Andy 17829 Apr 20, 2002, 8:14 AM
Thread Re: [Andy.] Everyone please take a moment to read....
Paul 18163 Apr 20, 2002, 9:37 AM
Thread Re: [Paul] Everyone please take a moment to read....
Andy 18027 Apr 21, 2002, 2:36 AM
Thread Re: Everyone please take a moment to read....
QooQ 18117 Apr 23, 2002, 6:55 AM
Thread Re: [QooQ] Everyone please take a moment to read....
Paul 18047 Apr 23, 2002, 6:58 AM
Post Re: [Paul] Everyone please take a moment to read....
Paul 17905 Apr 23, 2002, 6:59 AM
Thread Re: [Paul] Everyone please take a moment to read....
Andy 18050 Apr 23, 2002, 7:03 AM
Thread Re: [Andy.] Everyone please take a moment to read....
Paul 18001 Apr 23, 2002, 7:08 AM
Post Re: [Paul] Everyone please take a moment to read....
Evoir 5750 Apr 23, 2002, 8:38 AM
Thread Re: [Andy.] Everyone please take a moment to read....
Andy 5812 Apr 23, 2002, 8:54 AM
Thread Re: [Andy.] Everyone please take a moment to read....
Paul 5853 Apr 23, 2002, 9:10 AM
Thread Re: [Paul] Everyone please take a moment to read....
Evoir 6007 Apr 23, 2002, 11:38 AM
Post Re: [Evoir] Everyone please take a moment to read....
Paul 5737 Apr 23, 2002, 11:46 AM
Post Re: [Evoir] Everyone please take a moment to read....
Alex 5760 Apr 23, 2002, 12:55 PM
Thread Re: [Paul] Everyone please take a moment to read....
chmod 18320 Apr 19, 2002, 1:09 AM
Thread Re: [chmod] Everyone please take a moment to read....
Paul 18360 Apr 19, 2002, 1:19 AM
Thread Post deleted by Wil
Wil 18221 Apr 19, 2002, 1:22 AM
Post Re: [Wil] Everyone please take a moment to read....
Paul 18157 Apr 19, 2002, 1:23 AM
Thread Re: [Paul] Everyone please take a moment to read....
chmod 18352 Apr 19, 2002, 1:31 AM
Post Re: [chmod] Everyone please take a moment to read....
Paul 18135 Apr 19, 2002, 1:37 AM
Post Re: [Paul] Everyone please take a moment to read....
Ian 5724 Apr 23, 2002, 11:13 AM
Post Re: [Paul] Everyone please take a moment to read....
Alex 5711 Apr 23, 2002, 12:53 PM