Greetings and possible spam attack

Hi,

I cannot think of a solid usecase but I think that sending greetings is a probable spam-prone area. I noticed to send a greeting you just need to login to your account and type this in the browser:

http://demozzz.com/dolphin7b/greet.php?sendto=<user_id>&from=<the_spammer_id>&ConfCode=

No authorization or captcha code is required.

So a spammer can create an account, login  and just use a script and have this url in it:

http://demozzz.com/dolphin7b/greet.php?sendto=<user_id>&from=<the_spammer_id>&ConfCode=

And then all he needs to do is to increment the user_id count and fire the request again to send greetings to a different user. So imagine how easy it would be to SPAM the whole community forget about server load issues.

What do you say guys???

Mick

Quote · 4 Nov 2009

Ticket for 7.1 was added: http://www.boonex.com/trac/dolphin/ticket/1428

Rules → http://www.boonex.com/terms
Quote · 5 Nov 2009
 
 
Below is the legacy version of the Boonex site, maintained for Dolphin.Pro 7.x support.
The new Dolphin solution is powered by UNA Community Management System.