i don’t know how long the
formmail exploit

has been around, but it seems like it could get ugly, given the popularity of the script:

“Formmail exploit is getting worse day by day. The real horror is that you may not even know if your server is exploited or not. A spammer can exploit your formmail script to flood thousands of Internet users with junk mail. The mail header will show your domain name and not even the spammer’s IP address. Unfortunately, The recipient of spam will yell at you and not at the spammer. Such incidents have already been reported.”

if you have formmail on your site, get the

before people start yelling at you. [ via


