Reply to Re: Forms getting spammed HELP

Your name:

Reply:


Posted by Dikkie Dik on 12/17/05 19:15

There was a thread about it just one month ago in this newsgroup. Read

http://securephp.damonkohler.com/index.php/Email_Injection

For an explanation of mail injection. Reading this, I suggest that your
first "quick" step is to reject any user supplied mail headers with a
newline character in it. It is best to do that both at the input and the
output side: It is an attack if someone slips a newline in a header (it
is too hard to do with an HTML text input to suggest it was a typo).
But the real error is not wether you accept invalid user data or not,
the real error is that you pass data to the mail function that can have
side effects. So writing a wrapper function for the standard mail()
function, but with extra parameter checks, should prevent a lot of problems.

Best regards

Mike wrote:
> Hello,
> I have a guestbook form that is getting spammed regularly(10 timeds a
> day) by a bot of some kind. I'm in the proccess of picking up PRO PHP
> Security from apress,(Which i need anyway) but I was wondering if anyone has
> a quick fix for this.or point me in the right direction.My client isnt
> happy.
> Thanks
> Mike
>
>

[Back to original message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация