Educause Security Discussion mailing list archives

Re: Form SPAM?


From: Kevin Wilcox <wilcoxkm () APPSTATE EDU>
Date: Tue, 8 Dec 2009 11:41:14 -0500

2009/12/8 Pete Hickey <pete () shadows uottawa ca>:

It's the old take advantage of the bug in the web-feedback software.  Just include
it in your site, and users can give feedback to the webmaster.  Manipulating the
parms lets one send to any address through this.

Indeed. And if it's sufficiently automated, it's just a script that
trolls for some type of "submit" and hopes that the content makes its
way into a public site at your .edu so that their ranking goes up when
someone searches for nudes of Jennifer Aniston, Lindsay Lohan, Miley
Cyrus, Angelina Jolie, etc.

We have had a few incidents where site admins would leave anonymous
forum posts available and stuff like this shows up.

kmw

-- 
Kevin Wilcox
Network Infrastructure and Control Systems
Appalachian State University
Email: wilcoxkm () appstate edu
Office: 828.262.6259

Current thread: