I have contacted the hosting support people around 300 times over the past two years, this week that trend started a reversal and they contacted me.
One of the websites in the hosting was being used by spammers to send messages out. It was detected that an abnormal volume of dodgy emails were being sent from one particular domain. I am not sure about what the motivation is, but it has happened a couple of times before, but in those cases the clients contacted me rather than the hosting company.
The pattern is that the spammers/ hackers/ ne’er-do-wells target a website and try to use the form in the website to send out messages. It generally fails for a number of reasons, but it does generate a lot of emails, and many of those with some of the more recent forms send messages back to one of your monitoring accounts and fills the inbox up.
We know that it is computers filling in forms, and I speculate that what is really happening is they are testing some automated process with a network of computers targeting a few sites. It tends to come in bursts, the content is invariably a promotion or link within the message.
The reason it comes out in bursts is probably someone is monitoring what is happening and then tweaks the script and starts it off again.
In this case around 500 emails were sent over the course of 6 hours before it was eventually shut down.
Why do they do it?
Usually because they are advertising something, probably of dubious value. In this case the person or computer that was causing the problem was based in the Philippines and it was advertising in Chinese, possibly a gambling site in China nr Shenzen. If there is some sort of scam operating the perpetrators do not want it associated with their domain, so they try to use someone else’s.
How to stop it?
The best way to stop it is to have some form of Captcha or Honey Trap built into the form. Captcha can be a problem, particularly for those with visual impairments, and even those that can see perfectly well. I have stopped using ReCaptcha by asking questions particularly when Google switched to the latest version of ReCaptcha which is a pain where you are looking at 9 panels of images and identifying which one is a car or a shop. You just cannot tell. I also suspect that Google Recaptcha favours Chrome users because I don’t see the questions very often with Chrome, but I do see it a lot with other browsers.
The Honey Trap
This is preferred method, it hides a special field in the form that computers can see, but humans cannot see. Computers tend to fill in all of the form fields. So if they are all filled, and one of them should be empty, it is easy to detect.
Am I affected?
If you see a sudden increase in spam mail originating from forms in your website, please let me know. Currently there are several form handlers in the installed base. If you get the problem, I can look at upgrading your forms to a new more recent standard than when the site was built. If you do see a problem, it is best to let me know ASAP because the people creating the problem tend to keep attacking the same sites in bursts of activities.