Re: php 'mail()' security
| From: | Justin French | Date: | Sun, 28 Jul 2002 08:13:58 +0000 |
| Subject: | Re: php 'mail()' security | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-110036@lists.php.net to get a copy of this message | ||
- strip_tags() will remove HTML and PHP code from a string
- there is a great function set which validates email address' to ensure the
email address is in the correct format available from killersoft:
http://killersoft.com/modules.php?op=modload&name=News&file=article&sid=2
- ensuring there are no newlines (\n) in the email address, subject, etc etc
will ensure that they aren't sneaking another email header into an existing
header.
Justin French
on 28/07/02 1:54 PM, Dennis Gearon (gearond@cvc.net) wrote:
> What I meant was, how to sanitize the input on the forms so that
> malicious stuff cannot be put as commands, etc. in the email address, or
> body, or 'extra' field of the 'mail()' function in PHP.