{"id":1037,"date":"2022-03-30T19:49:34","date_gmt":"2022-03-30T19:49:34","guid":{"rendered":"https:\/\/heathertankersley.com\/emaildelivered\/?p=1037"},"modified":"2022-03-30T19:49:36","modified_gmt":"2022-03-30T19:49:36","slug":"autoresponse-plus-arp-security-problem","status":"publish","type":"post","link":"https:\/\/heathertankersley.com\/emaildelivered\/2022\/03\/30\/autoresponse-plus-arp-security-problem\/","title":{"rendered":"Autoresponse Plus (ARP) Security Problem"},"content":{"rendered":"\n<p>Over the past week, we\u2019ve been made aware of a potential security issue affecting users of autoresponse plus. Currently, the instances we\u2019ve seen have been related to ARP3 and are a serious concern.<\/p>\n\n\n\n<p>In a nutshell, hackers are hacking into autoresponse plus accounts (not the server, but the actual email client itself).<\/p>\n\n\n\n<p><strong>NOTE:<\/strong>&nbsp;This vulnerability is not exclusive to, or in any way related to, the hosting provider or server choice. This is a problem with autoresponse plus (ARP\/ARP3). It has been found on a variety of webhosts running all different applications and across a number of different industries and markets.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">As a result, here is some of what is happening:<\/h2>\n\n\n\n<ol class=\"wp-block-list\"><li><strong>Sending out blatant spam (here\u2019s an example of a message:<\/strong>Hello Friend,Note: This offer will be gone without any notice.Your KINDLE competition will&nbsp;surrender like little crybabies!Get this with 72% DISCOUNT!&nbsp;HURRY!<\/li><li><strong>Changing account information inside of your autoresponse plus installation.<br><\/strong>In other words, they are actually CHANGING the email address set up in your ARP account. This means password resets, notifications, etc. will all be going to the email address they change it to. (So far, these all appear to be Hotmail, gmail, and Yahoo top level domains).<\/li><li><strong>Downloading your email list.<br><\/strong>We have verified that, inside several accounts, the \u201chacker\u201d has downloaded the contact list. For obvious reasons, this is a big issue\u2026<\/li><\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">How Is Autoresponse Plus Getting Hacked?<\/h2>\n\n\n\n<p>While we are not 100% certain of all the ways in which this is happening due to log file expiration on the servers we\u2019ve looked at, it appears that it is due to a \u201cSQL injection\u201d.<\/p>\n\n\n\n<p>To keep things simple, there is a problem with ARP, which exposes elements of the database to attackers. The autoresponse plus (arp)&nbsp;admin password is not encrypted, and a hacker can essentially overwrite the admin user email address and use it to retrieve the password as well as retrieve an export of all email addresses in the system.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to Fix the Problem<\/h2>\n\n\n\n<p>The only sure fire way to solve the problem is to REMOVE autoresponse plus (ARP3 from your server). There are several ways in which the security can be compromised.<\/p>\n\n\n\n<p><strong>Next Steps<\/strong><\/p>\n\n\n\n<p>There\u2019s a good chance your IP reputation has been affected by the hack, so you\u2019ll want to do a few things right away to restore your reputation and improve it overall.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Remove ARP3 (none of our clients or partners have \u201cfixed\u201d. They\u2019ve simply opted for another solution such as Interspire.<\/li><li>Check your IP address at senderscore.org<\/li><li>Verify that your server has all of the necessary authentication on it (DKIM, domainkeys, SPF, etc.)<\/li><li>Verify that your feedback loops are all set up and working<\/li><li>Watch your complaints VERY closely for the next 7-10 days to make sure the problem is resolved (if you\u2019ve not set up a new email client)<\/li><li>Practice impeccable list hygiene (in other words, get the bad subscribers out of your list ASAP). You will want to review all of the bounce data outside of autoresponse plus as autoresponse plus (ARP) is rather inaccurate in the bounce reporting statistics due to the fact that it\u2019s not been updated in some time, the bounce rules in particular.<\/li><li>Watch for irregularity in your mail log (such as mail bound to people not on your list).<\/li><\/ol>\n\n\n\n<p>Until your reputation has rebounded to upper 80s\/lower 90s, you\u2019ll want to clean your list after each broadcast or promotion. After that, you\u2019ll want to practice routine list hygiene on a weekly basis and stay on top of complaints, removing those subscribers from your list ASAP.<\/p>\n\n\n\n<p>Author: Heather Seitz<\/p>\n\n\n\n<p>Attention Readers, Publishers, Editors, Bloggers, and Marketers: You may republish or syndicate this article without any charge. The only thing I ask is that you keep the newsletter article or blog post exactly as it was written and formatted, with no changes. You must also include full publication attribution and back links as indicated.<\/p>\n\n\n\n<p>This information has been provided by<a href=\"http:\/\/emaildelivered.com\/\">&nbsp;http:\/\/www.EmailDelivered.com<\/a>&nbsp;and written by Heather Seitz. Don\u2019t forget to sign up for the EmailDelivered Pulse newsletter for articles, tips, and recommended resources related to email marketing and email deliverability.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Over the past week, we\u2019ve been made aware of a potential security issue affecting users of autoresponse plus. Currently, the instances we\u2019ve seen have been related to ARP3 and are a serious concern. In a nutshell, hackers are hacking into autoresponse plus accounts (not the server, but the actual email client itself). NOTE:&nbsp;This vulnerability is [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1038,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"cybocfi_hide_featured_image":"","footnotes":""},"categories":[6],"tags":[],"class_list":["post-1037","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-email-delivered"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v18.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Autoresponse Plus (ARP) Security Problem - EmailDelivered<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/heathertankersley.com\/emaildelivered\/2022\/03\/30\/autoresponse-plus-arp-security-problem\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Autoresponse Plus (ARP) Security Problem - EmailDelivered\" \/>\n<meta property=\"og:description\" content=\"Over the past week, we\u2019ve been made aware of a potential security issue affecting users of autoresponse plus. Currently, the instances we\u2019ve seen have been related to ARP3 and are a serious concern. In a nutshell, hackers are hacking into autoresponse plus accounts (not the server, but the actual email client itself). NOTE:&nbsp;This vulnerability is [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/heathertankersley.com\/emaildelivered\/2022\/03\/30\/autoresponse-plus-arp-security-problem\/\" \/>\n<meta property=\"og:site_name\" content=\"EmailDelivered\" \/>\n<meta property=\"article:published_time\" content=\"2022-03-30T19:49:34+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-03-30T19:49:36+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/heathertankersley.com\/emaildelivered\/wp-content\/uploads\/2022\/03\/autoresponse-plus.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"300\" \/>\n\t<meta property=\"og:image:height\" content=\"300\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"heathertankersley\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/heathertankersley.com\/emaildelivered\/#website\",\"url\":\"https:\/\/heathertankersley.com\/emaildelivered\/\",\"name\":\"EmailDelivered\",\"description\":\"Just another WordPress site\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/heathertankersley.com\/emaildelivered\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/heathertankersley.com\/emaildelivered\/2022\/03\/30\/autoresponse-plus-arp-security-problem\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/heathertankersley.com\/emaildelivered\/wp-content\/uploads\/2022\/03\/autoresponse-plus.jpg\",\"contentUrl\":\"https:\/\/heathertankersley.com\/emaildelivered\/wp-content\/uploads\/2022\/03\/autoresponse-plus.jpg\",\"width\":300,\"height\":300},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/heathertankersley.com\/emaildelivered\/2022\/03\/30\/autoresponse-plus-arp-security-problem\/#webpage\",\"url\":\"https:\/\/heathertankersley.com\/emaildelivered\/2022\/03\/30\/autoresponse-plus-arp-security-problem\/\",\"name\":\"Autoresponse Plus (ARP) Security Problem - EmailDelivered\",\"isPartOf\":{\"@id\":\"https:\/\/heathertankersley.com\/emaildelivered\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/heathertankersley.com\/emaildelivered\/2022\/03\/30\/autoresponse-plus-arp-security-problem\/#primaryimage\"},\"datePublished\":\"2022-03-30T19:49:34+00:00\",\"dateModified\":\"2022-03-30T19:49:36+00:00\",\"author\":{\"@id\":\"https:\/\/heathertankersley.com\/emaildelivered\/#\/schema\/person\/a17f7a9a229313fa642355cfe9aa7428\"},\"breadcrumb\":{\"@id\":\"https:\/\/heathertankersley.com\/emaildelivered\/2022\/03\/30\/autoresponse-plus-arp-security-problem\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/heathertankersley.com\/emaildelivered\/2022\/03\/30\/autoresponse-plus-arp-security-problem\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/heathertankersley.com\/emaildelivered\/2022\/03\/30\/autoresponse-plus-arp-security-problem\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/heathertankersley.com\/emaildelivered\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Autoresponse Plus (ARP) Security Problem\"}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/heathertankersley.com\/emaildelivered\/#\/schema\/person\/a17f7a9a229313fa642355cfe9aa7428\",\"name\":\"heathertankersley\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/heathertankersley.com\/emaildelivered\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d05b527651547b129bd354c4eb66cbcd0a7ff9e26efaaf664306bdaf4fc19d2b?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d05b527651547b129bd354c4eb66cbcd0a7ff9e26efaaf664306bdaf4fc19d2b?s=96&d=mm&r=g\",\"caption\":\"heathertankersley\"},\"sameAs\":[\"https:\/\/heathertankersley.com\/emaildelivered\"],\"url\":\"https:\/\/heathertankersley.com\/emaildelivered\/author\/heathertankersley\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Autoresponse Plus (ARP) Security Problem - EmailDelivered","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/heathertankersley.com\/emaildelivered\/2022\/03\/30\/autoresponse-plus-arp-security-problem\/","og_locale":"en_US","og_type":"article","og_title":"Autoresponse Plus (ARP) Security Problem - EmailDelivered","og_description":"Over the past week, we\u2019ve been made aware of a potential security issue affecting users of autoresponse plus. Currently, the instances we\u2019ve seen have been related to ARP3 and are a serious concern. In a nutshell, hackers are hacking into autoresponse plus accounts (not the server, but the actual email client itself). NOTE:&nbsp;This vulnerability is [&hellip;]","og_url":"https:\/\/heathertankersley.com\/emaildelivered\/2022\/03\/30\/autoresponse-plus-arp-security-problem\/","og_site_name":"EmailDelivered","article_published_time":"2022-03-30T19:49:34+00:00","article_modified_time":"2022-03-30T19:49:36+00:00","og_image":[{"width":300,"height":300,"url":"https:\/\/heathertankersley.com\/emaildelivered\/wp-content\/uploads\/2022\/03\/autoresponse-plus.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"heathertankersley","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebSite","@id":"https:\/\/heathertankersley.com\/emaildelivered\/#website","url":"https:\/\/heathertankersley.com\/emaildelivered\/","name":"EmailDelivered","description":"Just another WordPress site","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/heathertankersley.com\/emaildelivered\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/heathertankersley.com\/emaildelivered\/2022\/03\/30\/autoresponse-plus-arp-security-problem\/#primaryimage","inLanguage":"en-US","url":"https:\/\/heathertankersley.com\/emaildelivered\/wp-content\/uploads\/2022\/03\/autoresponse-plus.jpg","contentUrl":"https:\/\/heathertankersley.com\/emaildelivered\/wp-content\/uploads\/2022\/03\/autoresponse-plus.jpg","width":300,"height":300},{"@type":"WebPage","@id":"https:\/\/heathertankersley.com\/emaildelivered\/2022\/03\/30\/autoresponse-plus-arp-security-problem\/#webpage","url":"https:\/\/heathertankersley.com\/emaildelivered\/2022\/03\/30\/autoresponse-plus-arp-security-problem\/","name":"Autoresponse Plus (ARP) Security Problem - EmailDelivered","isPartOf":{"@id":"https:\/\/heathertankersley.com\/emaildelivered\/#website"},"primaryImageOfPage":{"@id":"https:\/\/heathertankersley.com\/emaildelivered\/2022\/03\/30\/autoresponse-plus-arp-security-problem\/#primaryimage"},"datePublished":"2022-03-30T19:49:34+00:00","dateModified":"2022-03-30T19:49:36+00:00","author":{"@id":"https:\/\/heathertankersley.com\/emaildelivered\/#\/schema\/person\/a17f7a9a229313fa642355cfe9aa7428"},"breadcrumb":{"@id":"https:\/\/heathertankersley.com\/emaildelivered\/2022\/03\/30\/autoresponse-plus-arp-security-problem\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/heathertankersley.com\/emaildelivered\/2022\/03\/30\/autoresponse-plus-arp-security-problem\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/heathertankersley.com\/emaildelivered\/2022\/03\/30\/autoresponse-plus-arp-security-problem\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/heathertankersley.com\/emaildelivered\/"},{"@type":"ListItem","position":2,"name":"Autoresponse Plus (ARP) Security Problem"}]},{"@type":"Person","@id":"https:\/\/heathertankersley.com\/emaildelivered\/#\/schema\/person\/a17f7a9a229313fa642355cfe9aa7428","name":"heathertankersley","image":{"@type":"ImageObject","@id":"https:\/\/heathertankersley.com\/emaildelivered\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/d05b527651547b129bd354c4eb66cbcd0a7ff9e26efaaf664306bdaf4fc19d2b?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d05b527651547b129bd354c4eb66cbcd0a7ff9e26efaaf664306bdaf4fc19d2b?s=96&d=mm&r=g","caption":"heathertankersley"},"sameAs":["https:\/\/heathertankersley.com\/emaildelivered"],"url":"https:\/\/heathertankersley.com\/emaildelivered\/author\/heathertankersley\/"}]}},"_links":{"self":[{"href":"https:\/\/heathertankersley.com\/emaildelivered\/wp-json\/wp\/v2\/posts\/1037","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/heathertankersley.com\/emaildelivered\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/heathertankersley.com\/emaildelivered\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/heathertankersley.com\/emaildelivered\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/heathertankersley.com\/emaildelivered\/wp-json\/wp\/v2\/comments?post=1037"}],"version-history":[{"count":1,"href":"https:\/\/heathertankersley.com\/emaildelivered\/wp-json\/wp\/v2\/posts\/1037\/revisions"}],"predecessor-version":[{"id":1039,"href":"https:\/\/heathertankersley.com\/emaildelivered\/wp-json\/wp\/v2\/posts\/1037\/revisions\/1039"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/heathertankersley.com\/emaildelivered\/wp-json\/wp\/v2\/media\/1038"}],"wp:attachment":[{"href":"https:\/\/heathertankersley.com\/emaildelivered\/wp-json\/wp\/v2\/media?parent=1037"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/heathertankersley.com\/emaildelivered\/wp-json\/wp\/v2\/categories?post=1037"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/heathertankersley.com\/emaildelivered\/wp-json\/wp\/v2\/tags?post=1037"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}