#36341 [NEW]: Changes to combat mail form spam
From: paul at xciv dot org
Operating system: FreeBSD
PHP version: 4.4.2
PHP Bug Type: Feature/Change Request
Bug description: Changes to combat mail form spam
Description:
------------
I have two suggestions for modifications to help combat the problem of
mail form spam.
Firstly I would like to see mail.force_extra_parameters back-ported to the
4.x branch - not everyone is ready to upgrade to 5.x in production yet.
Secondly I would like to suggest that environment variables from the PHP
environment are exposed to the sendmail binary.
I will explain why this is useful.
Reproduce code:
---------------
With the mail.force_extra_parameters option, I can set different
parameters per Apache vhost.
This can be very useful because I can set custom parameters like: -xs
my.vhost.domain
How is this useful? Well if I then set a new sendmail_path to my own
custom wrapper script I can pick up these custom parameters and do two
things:
1. Log the originating vhost, number of recipients etc.
2. Add an X-Header: in the mail detailing which vhost the mail originated
from - before passing it to the real sendmail.
This allows me to track which vhost sent mail from the httpd! So I can
now track which vhost may have an insecure mail form if I get spam
reports. With say 100 vhosts this is *invaluable*.
My second suggestion would make this a lot easier and a lot more
expandable. If the PHP environment variables were exposed to sendmail
then I could even pick up such details as the script filename etc and this
would then not require the use of custom mail.force_extra_parameters.
--
Edit bug report at http://bugs.php.net/?id=36341&edit=1
--
Try a CVS snapshot (PHP 4.4): http://bugs.php.net/fix.php?id=36341&r=trysnapshot44
Try a CVS snapshot (PHP 5.1): http://bugs.php.net/fix.php?id=36341&r=trysnapshot51
Try a CVS snapshot (PHP 6.0): http://bugs.php.net/fix.php?id=36341&r=trysnapshot60
Fixed in CVS: http://bugs.php.net/fix.php?id=36341&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=36341&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=36341&r=needtrace
Need Reproduce Script: http://bugs.php.net/fix.php?id=36341&r=needscript
Try newer version: http://bugs.php.net/fix.php?id=36341&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=36341&r=support
Expected behavior: http://bugs.php.net/fix.php?id=36341&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=36341&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=36341&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=36341&r=globals
PHP 3 support discontinued: http://bugs.php.net/fix.php?id=36341&r=php3
Daylight Savings: http://bugs.php.net/fix.php?id=36341&r=dst
IIS Stability: http://bugs.php.net/fix.php?id=36341&r=isapi
Install GNU Sed: http://bugs.php.net/fix.php?id=36341&r=gnused
Floating point limitations: http://bugs.php.net/fix.php?id=36341&r=float
No Zend Extensions: http://bugs.php.net/fix.php?id=36341&r=nozend
MySQL Configuration Error: http://bugs.php.net/fix.php?id=36341&r=mysqlcfg
Thread (10 messages)
- paul at xciv dot org