You are here: Detecting 'person' v 'script' for email page « All PHP « IT news, forums, messages
Detecting 'person' v 'script' for email page

Posted by M on 03/01/06 22:41

OK, I've been hit by the email spammers, and now validate every field,
chop out all the nasty commands and die if anything is suspicious.

I now want to implement a 'send this idea to someone' type page where a
user can put in their own email id, a friends email id and send a short
message.

Obviously I can trap all the usual nasties and die if I detect one, but
there wont be anything to stop a script calling the page and specifying
one email address at a time, and doing this hundreds of times.

So, what options are available to detect a genuine person v script?

1. type what you see in the image - I really don't like these
2. limit number of calls per IP address in X minutes
3. is there any way to only present / allow the form on the result of a
mouse click (i.e. cannot call the form directly), and can scripts
simulate a mouse click

Grateful if people could suggest potential options, would something like
3 above work at all?

Cheers,
M.

 

Navigation:

[Reply to this message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация