You are here: Re: Block email inject spammers « PHP Programming Language « IT news, forums, messages
Re: Block email inject spammers

Posted by Franηois on 02/06/06 19:28

"Gordon Burditt" <gordonb.eiwt9@burditt.org> wrote in message
news:11uf04s9ocmvc08@corp.supernews.com...

> >if (ereg(":", $Name)) || (ereg(":", $From))
> >
> >If I validate my mail() headers thus, will this stop spammers being
> >able to abuse my mail form? If there is somebody who has a colon in
> >their name or email address, I have yet to meet them.
>
> Do not permit any variable used in constructing the arguments
> to the mail() function to contain line ending characters (\r or \n)
> except for the message body, and that only after you have provided
> a blank line to separate the headers from the body. You check
> this with PHP, *not* javascript (which can be removed from the
> spammer's copy of the form).
>
> Do not allow the form to specify any part of the to: or cc: address.

Hi Gordon,

Thanks for your input. I only have three user fields in the form. If I
expand the colon removal to all three fields that'll do the trick
won't it? They need the colon to inject spurious cc: or bcc:
addresses.

Many thanks

Franc

 

Navigation:

[Reply to this message]


УдалСнная Ρ€Π°Π±ΠΎΡ‚Π° для программистов  •  Как Π·Π°Ρ€Π°Π±ΠΎΡ‚Π°Ρ‚ΡŒ Π½Π° Google AdSense  •  England, UK  •  ΡΡ‚Π°Ρ‚ΡŒΠΈ Π½Π° английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Π‘Π°ΠΉΡ‚ ΠΈΠ·Π³ΠΎΡ‚ΠΎΠ²Π»Π΅Π½ Π² Π‘Ρ‚ΡƒΠ΄ΠΈΠΈ Π’Π°Π»Π΅Π½Ρ‚ΠΈΠ½Π° ΠŸΠ΅Ρ‚Ρ€ΡƒΡ‡Π΅ΠΊΠ°
ΠΈΠ·Π³ΠΎΡ‚ΠΎΠ²Π»Π΅Π½ΠΈΠ΅ ΠΈ ΠΏΠΎΠ΄Π΄Π΅Ρ€ΠΆΠΊΠ° Π²Π΅Π±-сайтов, Ρ€Π°Π·Ρ€Π°Π±ΠΎΡ‚ΠΊΠ° ΠΏΡ€ΠΎΠ³Ρ€Π°ΠΌΠΌΠ½ΠΎΠ³ΠΎ обСспСчСния, поисковая оптимизация