Tag: infosec

  • Registration Form Used To Send Spam Via Welcome Email

    Registration Form Used To Send Spam Via Welcome Email

    While reviewing a client site, I recently noticed a small number of accounts had registered with spurious firstName and lastName values such as: firstName:You have 5 new messages from Patty: lastName: http://www.nsbe.org/impakredirect.aspx?url=http://project1200995.tilda.ws After some digging, it appeared these customers had legitimate email addresses, however had placed no orders, nor had they interacted with our site.…

    Continue reading