Create Online Business Learn tips and techniques on how to increase your revenue using Google AdSense Search Engine Optimization Affiliate Marketing Strategic Business Planning  
eg search for: Trade Show Planning
 
 
Generic- Neighborhood Neon Town business logos

 

What to do when you find an Insecure Web page Problem


Please Rate This Page

100%
Total Votes 1
Avg Rating 5
1 2 3 4 5

Featured articles by createonlinebusiness.com
Business Planning and Credit
 
 
 
 
Current Address Labels Easy-to-use templates for address labels including mailing, address, and CD labels

 

Ahhh, HELP my server got hacked from an insecure web form! Part 1

by
Robert Kennedy

 

 

Your worst nightmare…you wake up... get your morning coffee and power up your online empire and it's been deactivated.

The first thing I like to do is download all email. While email is downloading I log into my CMS panel to see how biz is doing! Hmmm, can’t connect to server?

Refresh…another refresh, ctrl key down refresh, NOTHING?!

OK my server must be down, I’m gonna restart it. Before that I toggle back to my downloading email and find an urgent message with the subject reading “3rd level admin DISABLED FOLDER”

Posted on 13 Dec 2005 10:18 AM

Hi,

There seems to be an insecure mail form in the folder “Folder Name”.
I have disabled the folder at this time, you can change the permissions back via ssh or contact me.
Please let me know if you have any questions. You will need to change the type of form that you use.

The spam evidence is below.

Name Removed, Lead Investigator
:: Internet Investigations and Security Services
:: Network Operations Center
:: Orlando, Florida, USA
:: abuse@removed.com
:: http://www.removed.com

 

Great! I'm Busted for Sending Spam I Didn't Even Send, WHAT NEXT?

Seriously bummed out I contact my host to be advised a web form on one of my sites was compromised and used to send out spam originating in China.

Because I have use dedicated, unmanaged servers the cause (blame) is solely mine! How long has this been going on? I had no idea!! Well the truthful answers would soon become blatantly obvious.

Hackers Hacked my Form, WHAT DOES THIS MEAN??

If you are entirely unaware of the potential vulnerabilities of your web forms this can be going on in front of your very eyes for days, weeks or months without your knowledge!! While the recipients of your unwanted spam trash do the right thing and report you to authorities causing your IP address to get blacklisted. The more reports filed the faster this propagates throughout the authorities. Every spam report filed requires evidence. In this case your email IP address is found in the header of every email sent from your server. Once this happens OH OH:

  • Search Rankings disappear
  • Your email addresses become blocked by many ISPs
  • Your name is basically Mud
  • You are labeled as a spammer
  • You are blacklisted

Wait a minute here, I am an entrepreneur with a family and rely entirely on my online business activities to pay the bills. When this happened to me the result was all of the above. My online network that I had worked so hard on developing since 1998 came crumbling down.

Like any online marketer I quickly learned how it happened and what can be done to ensure this doesn’t happen again.

What is the best Solution for web form security?


I asked my tech team to investigate this and come up with the best solution, NOW PLEASE!

OK, so we discover there are many tools used by these evil doers!! Tools (weapons) such as:

  • Form scripts
  • Email hacking
  • Web form generators
  • Hacking programs
  • Web form template hackers
  • Web form processing hackers
  • Html form hacking
  • Script form hacks
  • Hacking mail programs
  • Asp form hacks
  • Form email hackers
  • Hacking credit accounts
  • Form javascript hacks
  • Form database hacking
  • Form submit hacks
  • Hacking tools

OH Ya!! We found the best way to protect ourselves from this garbage!!

A Simple Way to Guard your website that doesn't cost a dime

Firstly, the easy method to combat this is just avoid file naming typically associated with forms. File naming such as “contact.htm” or “email”. Any of your supporting scripts should also avoid typical naming logic. Many of the automatic programs used for this will locate your forms by logical naming then attack. So you may want to start by renaming your current “contactus.htm” form to something like “132-touchbase-321.htm”

An easy, cost free way to protect your email addresses from being harvested

One of the most basic rules is don’t display your email addresses on your site. Display an email address has certain targeted characters such as “mailto” or “@” combined with “.” When these characters are displayed it becomes a feeding frenzy for email spam address harvesting.

How can my Customers Get in touch with me if I don't Publish my Email address?

What Long Term Preventative Action I took Against Insecure Servers!

After my technical team researched the finest, affordable suctions for on-page insecurities one name kept coming up UltimateFormmail (UFM). Here are some of the bells and whistles that I found very useful:

  • Saves contact form information to a mysql database.
  • Option to preserve uploaded digital files to your firm's server or attach them with a business email.
  • Four sample contact forms you have the capability to utilize on your business domain provided that your company is new to html.
  • Straight forward ready made themes you compose from, pages look precisely like your company's web site.
  • HTML emails hold a "backup" text version sent along so your business's announcement is looked through by every possible email viewer.
  • Option to transmit digital file attachments in the response to the visitor using the contact form.
  • You can email html emails to a visitor also/or webmaster.
  • Allows People to upload many files making the most of your company's contact form.
  • Drop down/checkbox selections so users can decide on recipient based on a listing... while your company list of emails remains hidden.
  • A no brainer to apply and configure
  • Super-secure using new technology not available with most other form processors
  • 4 ways to send out emails (sendmail, php mail(), qmail, smtp)
  • Adaptable reply.

 

The script used in its most basic format helps carve hours every week out of manual email sorting. It took only a few minutes to install it and the results were immediately evident.

I have been using this script throughout dozens of well established domains for our use and our clients. It is "bar none" the best, affordable investment you can make to protect your web forms from attack.

I strongly recommend this great, user friendly script for the Ultimate in website form security, Especially when you implement"token sessions".

Stay tuned for part 2 where we'll talk about exactly how to initiate token sessions and how it virtually eliminated ALL web form spam attacks.

Ultimate Form Mail Free Trial

Ultimate Form Mail Free Download

Don't wait until they get you. Take action now!

Wishing you success,

 

Robert Kennedy
Marketeer

Featured articles by createonlinebusiness.com
 
 
 
 
   
 
 

Home Improvements
Home Improvements custom emblem
Search keywords which best describe this web page: business language, business planning, event planning business combined with learn.
Recommended Links
Site Map - Top Web SitesCollectable quotes from Albert Einstein Forex - Household Logos Lots South San Francisco County- - Natural Logos for Business
All rights reserved CreateOnlineBusiness.com ©copyright 2007