![]() Topic awaiting preservation: SecurePHP : Email Injection (Page 1 of 1) |
|
---|---|
Paranoid (IV) Inmate From: France |
![]() The SecurePHP wiki has an interresting page about Email Injection. |
Paranoid (IV) Inmate From: A graveyard of dreams |
![]() Was a thread about this recently at the Gurusnetwork for those interrested. |
Maniac (V) Inmate From: Cell 53, East Wing |
![]() Yeah some simple checking of the email address should do it. Check out kuckus' contact page tutorial which also appears to be secure against this: |
Maniac (V) Mad Scientist From: New California |
![]() I've placed a hidden field in my form and if it is filled out then I know an automated submission was used. That's been working for me pretty well. |
Paranoid (IV) Inmate From: France |
![]() |
Paranoid (IV) Inmate From: Madison, Indiana, USA |
![]() Bugimus said quote:
|
Paranoid (IV) Inmate From: France |
![]() hyperbole: Spam bots analyzes the HTML code and try to fill all the fields and submit the form ( by doing the HTTP request ). Therefore if a hidden field is not empty, there's all the chances that it's a spam bot. |
Maniac (V) Mad Scientist From: New California |
![]() Precisely, poi. I was surprised they were that dumb too. It probably won't take long for them to learn this trick... especially with threads like this |
Paranoid (IV) Inmate From: France |
![]() |
Maniac (V) Mad Scientist From: New California |
![]()
|
Paranoid (IV) Mad Scientist with Finglongers From: Germany |
![]() Just on a side note, the past serveral days I've gotten such emails from the webmail form I'm using on smarttab.org ... quote:
|
Paranoid (IV) Mad Scientist with Finglongers From: Germany |
![]() this is getting worse and worse - we've a customer that regularly get's batches of about 30 of these emails. |
Paranoid (IV) Mad Scientist with Finglongers From: Germany |
![]() ok... how about a hidden field with an md5 or such of the current date. (so that it changes regularly) |
Paranoid (IV) Mad Scientist with Finglongers From: Germany |
![]() ok... hidden field changed || if newline in one of the single line field - reject. |
Paranoid (IV) Mad Scientist From: Omicron Persei 8 |
![]() TP, that is exactly the same kind of email i got. see: |