Hi there,
We have been running Xenforo v2.2.3 Patch 1 for more than a year now.
Our normal email daily sends are 1000 to 2000 emails. All of them are notifications for subscriptions or for new conversations started.
Yesterday, all of sudden, we noticed that Xenforo had sent 400.000 emails via our email smtp provider (Sendgrid) in just a few hours.
These were all duplicates of the same message. For example, a notification email "You have a new private message" was sent to some users 20.000 times (each).
Horror story, really.
We cleared the SMTP details in Xenforo admin, and also deleted the sendgrid API key, just in case.
After a bit of investigation, we confirmed that all those emails were indeed sent by Xenforo. They were typical Xenforo messages, but sent thousand of times.
We haven't however found the route cause of this.
I cannot think of anything else other than a nasty bug OR a xenforo exploit (hack).
Does this ring a bell to anyone?
Is this a bug fixed on later versions that could explain this?
Thanks!
Nick
We have been running Xenforo v2.2.3 Patch 1 for more than a year now.
Our normal email daily sends are 1000 to 2000 emails. All of them are notifications for subscriptions or for new conversations started.
Yesterday, all of sudden, we noticed that Xenforo had sent 400.000 emails via our email smtp provider (Sendgrid) in just a few hours.
These were all duplicates of the same message. For example, a notification email "You have a new private message" was sent to some users 20.000 times (each).
Horror story, really.
We cleared the SMTP details in Xenforo admin, and also deleted the sendgrid API key, just in case.
After a bit of investigation, we confirmed that all those emails were indeed sent by Xenforo. They were typical Xenforo messages, but sent thousand of times.
We haven't however found the route cause of this.
I cannot think of anything else other than a nasty bug OR a xenforo exploit (hack).
Does this ring a bell to anyone?
Is this a bug fixed on later versions that could explain this?
Thanks!
Nick
Last edited: