Spam "Outgoing"?? instead of incoming??

I am getting emails similar to the one below on daily basis. I have included RFC-822 Headers below. Is it possible to detect the point of origination from the header data? I am beginning to wonder if one of my mailform.cgi’s has been hijacked!? With that thought in mind…I deactivated all my mail cgi’s in all cgi folders on my site. Or is the e-mail below incoming Spam to me? I am totally without a clue on the one below and the other 35 like it I have received in the past week. ?(

Is there a program we can use to search the root and/or our public_html folders of our websites to check for security issues of this nature?

All feed back welcomed! thanks, nti. :slight_smile:

The suspected spam is on self reply below. <Not able to submit suspect e-mail due to unknown cause within this forum posting restrictions!?

It sounds like what I have been seeing a lot of recently, botnets hitting formmails of all sorts, from CGI, ASP, CF, PHP, etc.

It has become quite a chore and we are sending some 5-10 notices every 24 hours of form mails that do are allowing header injections and some even making spam complaints because they are vulnerable to them.

I’d recommend using image verification on the form mails to prevent such from happening.