educational

You’ve Got Mail…

No, this isn’t a sappy story about finding love in CyberSpace, or have anything to do with AOL and their now famous announcement to newbies the world over that another useless bit of electronic flotsam has settled into their ‘inbox’ – it is a tale of treachery, deceit, and vulnerability that we all can benefit from…

I’ve written before about the evils of SPAM – no, not the Hormel® processed pork product which I dearly love – but the Unsolicited Commercial Email (UCE) that floods my inbox on a daily basis. Today, however, I wish to begin a new rant, chastising the miscreants who impersonate me in an attempt to wreak havoc on others, and lay the blame at my feet. I have posted about this subject on the Cosmic Village Message Board, but with a noticeable increase as of late, I felt that it was time to revisit the subject – and since others of you may be vulnerable to these heathens as well, I am going to share some advice...

Noticing the Symptoms
Being constantly pre-occupied with both the major issues – as well as the trivial minutiae – of operating an e-commerce business, seemingly random and totally inexplicable occurrences tend to go unnoticed until they demand my attention. An increasing number of returned (bounced) e-mails, marked ‘undeliverable’ or some such, have been making their way into my inbox. Given the huge volume of mail I receive, and the filtering mechanisms I employ, anomalous mail sometimes stands out, and the e-letters in question became noticeable due to their similar traits:

A) They were all marked “undeliverable” and “returned” to stephen@xbiz.com

B) They usually contained subject lines or body text that were obviously not written by people who speak English as their primary language.

C) They were all addressed to people I do not know, and worse yet, to seemingly random e-mail addresses like legal_dept@domain.com – which (thankfully) bounced, hence being undeliverable.

D) They all contained viruses as attachments.

The upshot of all this is the realization that some ass-monkey is sending viruses hither and fro, and spoofing me as the sender! I scan all incoming and outgoing mail for viruses, and the addresses that are returned are not in my address book – leading me to believe that my machine is not possessed of some insidious virus that is emailing garbage to all of my friends and associates. Instead, I am one of the victims in an ongoing and confusing campaign which amounts to digital vandalism at best, and a premeditated criminal conspiracy at worst. While I hate to point fingers without having all of the facts, one URL that weaves its way through many of these bounced e-mails is thongn@hcm.vnn.vn – along with several variants thereof.

Since I am being spoofed, I hesitate to refer this e-mail address to younger and less scrupulous, yet far more technically advanced associates of mine, who (so legend says) have the ability to smoke this jamoch’s server, lest he be an innocent bystander as well. So what’s a boy to do? Tighten security as much as possible…

Holding Down the Home Front
While all of these attacks have been exclusively associated with my XBiz e-mail account, I maintain and use dozens of other e-mail addresses – one of the major ‘benefits’ of infinite mail-mapping across all of my own domains. While I have no administrative control over the servers and other technical assets that power XBiz and its sister products, I do have a level of control over my own properties, and have begun to tighten things up as much as possible. One area that I have looked into of late is my use of so-called ‘mail form’ scripts – server scripts which process form input and send the results via e-mail – and which can be ‘hijacked’ to send SPAM (and viruses), often without the knowledge of the site’s owner.

Like many Webmasters, I have long used the MailForm script (also known as formmail.pl, formmail.cgi, FormMail.cgi, FormMail.pl, mailform.pl, or mailform.cgi in its various incarnations), the original of which is typically obtained from Matt's Script Archive. The SPAM vulnerability comes from not limiting access to the script to the domain that it is hosted on. If you have one of these scripts that you have done any significant customization to, or have setup to send e-mail to a domain external to your website (a common practice), then an inherent vulnerability allows others to exploit the script to send SPAM. Minor changes that will deny outside abusers access, and prevent them from sending e-mails inappropriately through this software, can easily be accomplished. Simply ensure that the Web page you use to submit user input to your mailform contains the e-mail address where you are receiving mail from that form. For example, be sure to include <INPUT type=hidden name="recipient" value="webmaster@yourdomain.com">. The e-mail address that you use must be within your domain – it cannot be user@aol.com, etc.

If you would like to have mail delivered to such an address using this form, and not upgrade to a non-exploitable script, simply rename the script to something other than the names on the list above, being careful to change the name of the script in your mail forms to the name of your newly renamed script. While your mailform script may still be vulnerable, at least the spammers are not searching for it by your custom name and thus will probably not find it.

There may be no fool-proof way to totally eliminate unauthorized mailings, but every operation can and should conduct periodic internal revues to uncover, and mitigate, the weaknesses and vulnerabilities that are present in even the best systems. Good luck, and if you happen to receive any unexpected emails from stephen@xbiz.com that have attachments with them, please be sure not to open them! ~ Stephen

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More Articles

profile

LoyalFans' Anastasia Pierce Bridges Creator Education, Empowerment and Ownership

Anastasia Pierce beams when she talks about her 26 years in the industry. Full of passionate energy, she clearly doesn’t just work in adult; she loves it.

Women In Adult ·
opinion

Growing Site Revenue Under Ever-Changing Compliance Rules

Over the past year, many merchants have reported earnings that were flat or even a bit down. This is due to three main factors: age verification regulations, click-to-cancel rules, and banks backing away from cross-sales due to regulatory requirements and the rollout of the Visa Acquiring Monitoring Program (VAMP).

Cathy Beardsley ·
opinion

AI Safeguards for Platform Compliance and Trust

If your platform hosts user-generated content (UGC), then you already know protecting your brand is not merely a matter of good design or strong community guidelines. It requires systems that can verify who your users are, filter what they upload and ensure your business stays on the right side of regulators, payment processors and public opinion.

Christoph Hermes ·
opinion

How to Eliminate User Redirects and Improve Checkout Retention

Running an adult site, you work hard to create traffic and make sure your funnel is optimal, with the end goal of getting users to make a purchase. Then, right at that critical moment, what do you do? You send them somewhere else. Not good.

Jonathan Corona ·
profile

Stripchat's Jessica on Building Creator Success, One Step at a Time

At most industry events, the spotlight naturally falls on the creators whose personalities light up screens and social feeds. Behind the booths, parties and perfectly timed photo ops, however, there is someone else shaping the experience.

Jackie Backman ·
opinion

Inside the OCC's Debanking Review and Its Impact on the Adult Industry

For years, adult performers, creators, producers and adjacent businesses have routinely had their access to basic financial services curtailed — not because they are inherently higher-risk customers, but because a whole category of lawful work has long been treated as unacceptable.

Corey Silverstein ·
opinion

How to Build Operational Resilience Into Your Payment Ecosystem

Over the past year, we’ve watched adult merchants weather a variety of disruptions and speedbumps. Some even lost entire revenue streams overnight — simply because they relied too heavily on a single cloud provider that suffered an outage, lacked sufficient redundancy and failover, or otherwise fell short when it came to making sure their business was protected in case of unwelcome surprises.

Cathy Beardsley ·
opinion

Building a Stronger Strategy Against Card-Testing Bots

It’s a scenario every high-risk merchant dreads. You wake up one morning, check your dashboard and see a massive spike in transaction volume. For a fleeting moment, you’re excited at the premise that something went viral — but then reality sets in. You find thousands of transactions, all for $0.50 and all declined.

Jonathan Corona ·
opinion

A Creator's Guide to Starting the Year With Strong Financial Habits

Every January brings that familiar rush of new ideas and big goals. Creators feel ready to overhaul their content, commit to new posting schedules and jump on fresh opportunities.

Megan Stokes ·
profile

Pornnhub's Jade Talks Trust and Community

If you’ve ever interacted with Jade at Pornhub, you already know one thing to be true: Whether you’re coordinating an event, confirming deliverables or simply trying to get an answer quickly, things move more smoothly when she’s involved. Emails get answered. Details are confirmed. Deadlines don’t drift. And through it all, her tone remains warm, friendly and grounded.

Women In Adult ·
Show More