Kayako logo
SupportSuite, eSupport and LiveResponse Discussion, troubleshooting and feedback related to Kayako's flagship support desk products SupportSuite, eSupport and LiveResponse.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  (#1) Old
nibb Offline
Member
 
Posts: 89
Join Date: Feb 2007
Spam delivered directly to Kayako - 16-06-2007, 07:56 PM

I have a email set to registered users only. I worked perfect, now suddenly after 2 days im receiving spam on that box. The spam seems to be delivered directly to kayako, since i dont receive a copy of the Ticket like i do normally. Also when i click on the headers it says:
Invalid Parser Log entry. Make sure that the Parser Log entry exists in the database and has not been deleted.

Im getting now 50 a day and they are delivered to the registered mail that is suppose to reject. I also have a very good filter of spam and its not getting to the server, it seems someone is delivering the mails directly to kayako bypassing the mail. This is so strange.
   
Reply With Quote
  (#2) Old
Jamie Edwards Online
Operations Manager
 
Jamie Edwards's Avatar
 
Posts: 5,272
Join Date: Jan 2006
Location: United Kingdom
16-06-2007, 10:34 PM

Hi nibb,

Are you saying this is a form-submitted ticket or an e-mail submitted ticket?


Jamie Edwards (jamie.edwards ]at[ kayako.com)
----------------------------------------------------------------
---
  • Submit bug reports here.
  • Submit support tickets via the members area.
  • Submit sales queries either via live chat or via e-mail.
  • There is no official ETA on Version 4.
  • This is not an official support forum - submit a support ticket.
   
Reply With Quote
  (#3) Old
nibb Offline
Member
 
Posts: 89
Join Date: Feb 2007
16-06-2007, 10:55 PM

I dont know how they deliver it.

It was working for 3 months no spam at all. Since you cannot deliver it. I dont think via forma since you have to log in for that.

All the same comes from Sales

And the user is not even created. Also i have an alert to receive copy and the SMS alert, for the spam i dont receive the SMS alerts and no email copy so i suppose this is not send via mail but forced directly to kayako someway.
For other tickets or normal emails i get the SMS and email but not for this spam.

The weard thig is that on the log parser it shows it delivers it but when you clic on it to see the info it shows that errror that is doesnt exist, and on the spam emails it also shows it doesnt exist. Im scared that the spammer hacked my kayako someway and it putting the same directly. I do see tons of MSN bots sessions as client not as visitor, so this could maybe has something to do with it. But i checked the IP and they are from MSN and Microsoft so i discarded that.
   
Reply With Quote
  (#4) Old
Jamie Edwards Online
Operations Manager
 
Jamie Edwards's Avatar
 
Posts: 5,272
Join Date: Jan 2006
Location: United Kingdom
17-06-2007, 12:15 PM

Hi nibb,

Have you checked the parser log in the administrator control panel? Are there entries for the spam you are receiving? This is a very strange issue.


Jamie Edwards (jamie.edwards ]at[ kayako.com)
----------------------------------------------------------------
---
  • Submit bug reports here.
  • Submit support tickets via the members area.
  • Submit sales queries either via live chat or via e-mail.
  • There is no official ETA on Version 4.
  • This is not an official support forum - submit a support ticket.
   
Reply With Quote
  (#5) Old
nibb Offline
Member
 
Posts: 89
Join Date: Feb 2007
17-06-2007, 05:30 PM

yes, they are, they are marked as OK in green delivered. More strange is when you clic on the log to see it it says it doesnt exist.
   
Reply With Quote
  (#6) Old
nibb Offline
Member
 
Posts: 89
Join Date: Feb 2007
19-06-2007, 03:52 AM

This is getting worse now. It seems somone is using Kayako to spam as a relay. I have the latest kayako and the piping is done via the cli/index.php
   
Reply With Quote
  (#7) Old
Jamie Edwards Online
Operations Manager
 
Jamie Edwards's Avatar
 
Posts: 5,272
Join Date: Jan 2006
Location: United Kingdom
19-06-2007, 12:48 PM

Hi Nibb,

My assumption is that someone must have access your server and/or Kayako installation as a result of an XSS attack on the insecure version you were running previously.

I would suggest you go through each area of your hosting account checking for anything suspicious. I would change all of your administrator passwords, as well as remove your SupportSuite installation directory entirely, reuploading all of the files to ensure they are 'clean'.

You could also submit a ticket to Support; our Services department may be able to better determine (as opposed to my guess work) where the unauthorized access is taking place.


Jamie Edwards (jamie.edwards ]at[ kayako.com)
----------------------------------------------------------------
---
  • Submit bug reports here.
  • Submit support tickets via the members area.
  • Submit sales queries either via live chat or via e-mail.
  • There is no official ETA on Version 4.
  • This is not an official support forum - submit a support ticket.
   
Reply With Quote
  (#8) Old
Jamie Edwards Online
Operations Manager
 
Jamie Edwards's Avatar
 
Posts: 5,272
Join Date: Jan 2006
Location: United Kingdom
19-06-2007, 12:52 PM

I have consulted with a developer - if you do choose to send a ticket to Support to see if we can help trace the offended scripts, please provide mail logs or if available administrator access to your web server.


Jamie Edwards (jamie.edwards ]at[ kayako.com)
----------------------------------------------------------------
---
  • Submit bug reports here.
  • Submit support tickets via the members area.
  • Submit sales queries either via live chat or via e-mail.
  • There is no official ETA on Version 4.
  • This is not an official support forum - submit a support ticket.
   
Reply With Quote
  (#9) Old
nibb Offline
Member
 
Posts: 89
Join Date: Feb 2007
19-06-2007, 04:41 PM

Well i always had Kayako on the latest version. So if it was hacked it was on the latest version.
   
Reply With Quote
  (#10) Old
nibb Offline
Member
 
Posts: 89
Join Date: Feb 2007
19-06-2007, 04:46 PM

I dont think its spamming via the server. The mails are delivered to port 110 to to Kayako itself.

In message id they have something like jjqdmo.gbep5k@mydomain.com
   
Reply With Quote
  (#11) Old
Jamie Edwards Online
Operations Manager
 
Jamie Edwards's Avatar
 
Posts: 5,272
Join Date: Jan 2006
Location: United Kingdom
19-06-2007, 05:38 PM

Hi Nibb,

Please submit a support ticket detailing this problem / link to this thread.


Jamie Edwards (jamie.edwards ]at[ kayako.com)
----------------------------------------------------------------
---
  • Submit bug reports here.
  • Submit support tickets via the members area.
  • Submit sales queries either via live chat or via e-mail.
  • There is no official ETA on Version 4.
  • This is not an official support forum - submit a support ticket.
   
Reply With Quote
Reply

Tags
delivered, directly, spam

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
vBulletin Skin developed by: vBStyles.com


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46