Hello Monroe,
thank you for your answer.
what version are you using?
it is version 2.1.8
Are the PMs coming from the anonymous user or from a logged in user?
The logs show a request using a valid forum user
When you say post messages, are you talking about PM's only?
Yes, the spam affected private messages only.
this is a part of what we found in our logs:
194.8.75.xxx - - [21/Mar/2009:00:26:17 +0100] "GET /projJForum/jforum.page?modu
le=pm&action=sendToUser&subject=Contact%25252520PROJECT.COM&username=X_USERNAME HTTP/1.0
" 200 15732
194.8.75.xxx - - [21/Mar/2009:00:26:17 +0100] "POST /projJForum/jforum.page;jse
ssionid=A72CA67E056FEB95398A121F0241FE67 HTTP/1.0" 200 3648
194.8.75.xxx is the attackers ip, however we assume this might be a poor soul not knowing that he provides some of his bandwidth to contribute to a botnet/spamnet.
thank you in advance for helping us solvings this problem.
kind regards,
user0
[originally posted on jforum.net by user0]