educational

You’ve Got Mail…

No, this isn’t a sappy story about finding love in CyberSpace, or have anything to do with AOL and their now famous announcement to newbies the world over that another useless bit of electronic flotsam has settled into their ‘inbox’ – it is a tale of treachery, deceit, and vulnerability that we all can benefit from…

I’ve written before about the evils of SPAM – no, not the Hormel® processed pork product which I dearly love – but the Unsolicited Commercial Email (UCE) that floods my inbox on a daily basis. Today, however, I wish to begin a new rant, chastising the miscreants who impersonate me in an attempt to wreak havoc on others, and lay the blame at my feet. I have posted about this subject on the Cosmic Village Message Board, but with a noticeable increase as of late, I felt that it was time to revisit the subject – and since others of you may be vulnerable to these heathens as well, I am going to share some advice...

Noticing the Symptoms
Being constantly pre-occupied with both the major issues – as well as the trivial minutiae – of operating an e-commerce business, seemingly random and totally inexplicable occurrences tend to go unnoticed until they demand my attention. An increasing number of returned (bounced) e-mails, marked ‘undeliverable’ or some such, have been making their way into my inbox. Given the huge volume of mail I receive, and the filtering mechanisms I employ, anomalous mail sometimes stands out, and the e-letters in question became noticeable due to their similar traits:

A) They were all marked “undeliverable” and “returned” to stephen@xbiz.com

B) They usually contained subject lines or body text that were obviously not written by people who speak English as their primary language.

C) They were all addressed to people I do not know, and worse yet, to seemingly random e-mail addresses like legal_dept@domain.com – which (thankfully) bounced, hence being undeliverable.

D) They all contained viruses as attachments.

The upshot of all this is the realization that some ass-monkey is sending viruses hither and fro, and spoofing me as the sender! I scan all incoming and outgoing mail for viruses, and the addresses that are returned are not in my address book – leading me to believe that my machine is not possessed of some insidious virus that is emailing garbage to all of my friends and associates. Instead, I am one of the victims in an ongoing and confusing campaign which amounts to digital vandalism at best, and a premeditated criminal conspiracy at worst. While I hate to point fingers without having all of the facts, one URL that weaves its way through many of these bounced e-mails is thongn@hcm.vnn.vn – along with several variants thereof.

Since I am being spoofed, I hesitate to refer this e-mail address to younger and less scrupulous, yet far more technically advanced associates of mine, who (so legend says) have the ability to smoke this jamoch’s server, lest he be an innocent bystander as well. So what’s a boy to do? Tighten security as much as possible…

Holding Down the Home Front
While all of these attacks have been exclusively associated with my XBiz e-mail account, I maintain and use dozens of other e-mail addresses – one of the major ‘benefits’ of infinite mail-mapping across all of my own domains. While I have no administrative control over the servers and other technical assets that power XBiz and its sister products, I do have a level of control over my own properties, and have begun to tighten things up as much as possible. One area that I have looked into of late is my use of so-called ‘mail form’ scripts – server scripts which process form input and send the results via e-mail – and which can be ‘hijacked’ to send SPAM (and viruses), often without the knowledge of the site’s owner.

Like many Webmasters, I have long used the MailForm script (also known as formmail.pl, formmail.cgi, FormMail.cgi, FormMail.pl, mailform.pl, or mailform.cgi in its various incarnations), the original of which is typically obtained from Matt's Script Archive. The SPAM vulnerability comes from not limiting access to the script to the domain that it is hosted on. If you have one of these scripts that you have done any significant customization to, or have setup to send e-mail to a domain external to your website (a common practice), then an inherent vulnerability allows others to exploit the script to send SPAM. Minor changes that will deny outside abusers access, and prevent them from sending e-mails inappropriately through this software, can easily be accomplished. Simply ensure that the Web page you use to submit user input to your mailform contains the e-mail address where you are receiving mail from that form. For example, be sure to include <INPUT type=hidden name="recipient" value="webmaster@yourdomain.com">. The e-mail address that you use must be within your domain – it cannot be user@aol.com, etc.

If you would like to have mail delivered to such an address using this form, and not upgrade to a non-exploitable script, simply rename the script to something other than the names on the list above, being careful to change the name of the script in your mail forms to the name of your newly renamed script. While your mailform script may still be vulnerable, at least the spammers are not searching for it by your custom name and thus will probably not find it.

There may be no fool-proof way to totally eliminate unauthorized mailings, but every operation can and should conduct periodic internal revues to uncover, and mitigate, the weaknesses and vulnerabilities that are present in even the best systems. Good luck, and if you happen to receive any unexpected emails from stephen@xbiz.com that have attachments with them, please be sure not to open them! ~ Stephen

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More Articles

profile

Stripchat's Jessica on Building Creator Success, One Step at a Time

At most industry events, the spotlight naturally falls on the creators whose personalities light up screens and social feeds. Behind the booths, parties and perfectly timed photo ops, however, there is someone else shaping the experience.

Jackie Backman ·
opinion

Inside the OCC's Debanking Review and Its Impact on the Adult Industry

For years, adult performers, creators, producers and adjacent businesses have routinely had their access to basic financial services curtailed — not because they are inherently higher-risk customers, but because a whole category of lawful work has long been treated as unacceptable.

Corey Silverstein ·
opinion

How to Build Operational Resilience Into Your Payment Ecosystem

Over the past year, we’ve watched adult merchants weather a variety of disruptions and speedbumps. Some even lost entire revenue streams overnight — simply because they relied too heavily on a single cloud provider that suffered an outage, lacked sufficient redundancy and failover, or otherwise fell short when it came to making sure their business was protected in case of unwelcome surprises.

Cathy Beardsley ·
opinion

Building a Stronger Strategy Against Card-Testing Bots

It’s a scenario every high-risk merchant dreads. You wake up one morning, check your dashboard and see a massive spike in transaction volume. For a fleeting moment, you’re excited at the premise that something went viral — but then reality sets in. You find thousands of transactions, all for $0.50 and all declined.

Jonathan Corona ·
opinion

A Creator's Guide to Starting the Year With Strong Financial Habits

Every January brings that familiar rush of new ideas and big goals. Creators feel ready to overhaul their content, commit to new posting schedules and jump on fresh opportunities.

Megan Stokes ·
opinion

Pornnhub's Jade Talks Trust and Community

If you’ve ever interacted with Jade at Pornhub, you already know one thing to be true: Whether you’re coordinating an event, confirming deliverables or simply trying to get an answer quickly, things move more smoothly when she’s involved. Emails get answered. Details are confirmed. Deadlines don’t drift. And through it all, her tone remains warm, friendly and grounded.

Women In Adult ·
opinion

Outlook 2026: Industry Execs Weigh In on Strategy, Monetization and Risk

The adult industry enters 2026 at a moment of concentrated change. Over the past year, the sector’s evolution has accelerated. Creators have become full-scale businesses, managing branding, compliance, distribution and community under intensifying competition. Studios and platforms are refining production and business models in response to pressures ranging from regulatory mandates to shifting consumer preferences.

Jackie Backman ·
opinion

How Platforms Can Tap AI to Moderate Content at Scale

Every day, billions of posts, images and videos are uploaded to platforms like Facebook, Instagram, TikTok and X. As social media has grown, so has the amount of content that must be reviewed — including hate speech, misinformation, deepfakes, violent material and coordinated manipulation campaigns.

Christoph Hermes ·
opinion

What DSA and GDPR Enforcement Means for Adult Platforms

Adult platforms have never been more visible to regulators than they are right now. For years, the industry operated in a gray zone: enormous traffic, massive data volume and minimal oversight. Those days are over.

Corey D. Silverstein ·
opinion

Making the Case for Network Tokens in Recurring Billing

A declined transaction isn’t just a technical error; it’s lost revenue you fought hard to earn. But here’s some good news for adult merchants: The same technology that helps the world’s largest subscription services smoothly process millions of monthly subscriptions is now available to you as well.

Jonathan Corona ·
Show More