Bizarre Subscribe2 Exploit
-
I don’t know why this is being done to one of my Websites, other than that I may have irritated someone no end. I don’t see any benefit to the other person from this kind of abusive activity. Nonetheless, I think you should be aware of it in case this is happening to other Websites.
Someone is using IP addresses spread across China and Venezuela (and maybe a couple of other countries, but most of this activity comes from China) to submit false Yahoo! email addresses to the subscribe2 plugin.
Between 1 and 200 submissions will be made quickly in bulk. When I see a new batch come in I download the email data in CSV format and block the AS record-level IP address ranges for these overseas submission points. Whoever is doing this keeps finding new Chinese networks to exploit. It could be they are using the Subscribe2 form as a test bed to determine which machines they can use for future DDoS attacks.
The fake email addresses are always in the form of a 5-digit number “at” Yahoo.com. E.g., [email protected].
My server’s email system quickly fills up with bounce messages from Yahoo! I have to delete these fake registrations every 1-2 days and block more Chinese IP address ranges.
If in the future you can add some sort of throttling mechanism (many of the submissions use the same IP addreses, although I suspect they come in semi-random order) that would be helpful.
The topic ‘Bizarre Subscribe2 Exploit’ is closed to new replies.