How Can I Prevent A Scan From Causing An Email Flood? - Acunetix
Maybe your like
Apart from being an annoyance, if the problem of mass mailing has impacted your site then it could be a web application vulnerability in itself. A hacker or malicious user can perform the same steps to flood the mail system, for example by using automated bots. This issue is dependent on how the custom website actually works at the server-side, with certain types of requests. This mass mailing can be caused by more than one thing: forms, links, and multiple requests.
As a black box scanner, Acunetix cannot predict if a website contains such entry points, since emails are actually sent at the server side.
It is important to be aware that this can be exploited like a vulnerability to cripple a server, therefore such mass mailing entry points should be made more secure. When using forms for sending emails (e.g. registration forms), techniques such as CAPTCHA (http://en.wikipedia.org/wiki/Captcha) should be implemented to validate the input and protect such forms against bots.
Resolution
To avoid from receiving such emails while scanning your website with Acunetix, follow the following steps:
- Add a filter in the Directory and File Filters node to exclude the mailing script from being scanned. For example, if contact_us.html posts details to /cgi-bin/mailer.php, add the URL of mailer.php to the exclusion list
- Control the request by denying any requests which try to access the script that generates emails directly, or from any other invalid referrers; this will also protect your mail server when a malicious user tries to abuse the script’s functionality
You can read more about this issue and other ways to tackle it from the following blog post: Ways to avoid email floods when running Web vulnerability scans.
Tag » How To Flood A Email
-
Flooding Someone's Email. How? - Subaru Enthusiast Forum
-
The Return Of Email Flooding - Dark Reading
-
How To Send Bulk Emails (flood The Inbox Not Spam) - YouTube
-
Managing “Email Flood” In Service Management Solutions
-
Email Flooding | Fluid Attacks Documentation
-
SPAM That Special Jerk In Your Life With Enough Email To Close Their ...
-
How To Overcome Your Daily Email Flood - FocusMe
-
How To Get Rid Of Spam Emails - Norton
-
3 Easy Steps To Avoid The Flood Of Email After A Vacation
-
Email Flood Free Download - SourceForge
-
5 Easy Steps To Stanch The E-Mail Flood - The New York Times
-
Flood Of Emails Definition | English Dictionary For Learners | Reverso
-
How To Survive The Email Flood - Cavalletti Communications
-
Sudden Flood Of Emails - Microsoft Community