Phishing site hxxp://www.jotform.com/form/11941952563?

  • Profile Image
    upc-cablecom abusedesk
    Asked on July 15, 2011 at 04:04 AM

    Dear JotForm,

    please close these offending Phishing sites.

    URL: hxxp://www.jotform.com/form/11941952563?
    IP: 174.34.48.212
    status: Alive

    Please remove this site immediately.

    If your review this site, please do this carefully, pay attention for redirects also!
    Also, please consider this particular machines may have a root kit installed !
    So simply deleting some files or dirs or disabling cgi may not really solve the issue !

    Advice: The appearance of a Phishing Site on a server means that
    someone intruded into the system. The server\'s owner should
    disconnect and not return the system into service until an
    audit is performed to ensure no data was lost, that all OS and
    internet software is up to date with the latest security fixes,
    and that any backdoors and other exploits left by the intruders
    are closed. Logs should be preserved and analyzed and, perhaps,
    the appropriate law enforcement agencies notified.

    DO NOT JUST DELETE THE FILES. IF YOU DO NOT FIX THE SECURITY
    PROBLEM, THEY WILL BE BACK!

    If you closed this incident please give us a feedback

    We thank you for your cooperation.

    Kind regards,
       
    upc cablecom
    abuse desk
    abuse@upc-cablecom.ch

  • Profile Image
    allanftd
    Answered on July 15, 2011 at 04:38 AM

    Hi there,

    Thank you for bringing this to our attention. We have already suspended this form as well as the JotForm account associated with it.

    Please let us know if we can be of further assistance.

    JOTFORM SUPPORT

  • Profile Image
    upc-cablecom abusedesk
    Answered on July 15, 2011 at 04:53 AM

    Thank you for your fast reaction.

    Kind regards,

    upc cablecom
    abuse desk
    abuse@upc-cablecom.ch