security with email data entries
| From: | Chris Hayes | Date: | Wed, 15 Aug 2001 15:20:31 +0000 |
| Subject: | security with email data entries | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-62847@lists.php.net to get a copy of this message | ||
Hi group!
i have this script to read data in POP emails and put them in a database.
I would like to know if anybody knows how people would try to get around the
tests I've build in.
- normal registration by web form (password scrambled), with confirmation
through email response
- the first header starting with 'From:' in the mail is scanned for a the
email addtess and then i check whether the email address is in the database
- the mail contains the non-scrambled username and password, which are also
checked
- there must be a magic word in the email subject (to prevent SPAM mail
confusing my script)
Oh and I intend only to disclose the email address to people i know.
thanks,
Chris
--------------------------------------------------------------------
-- C.Hayes Droevendaal 35 6708 PB Wageningen the Netherlands --
--------------------------------------------------------------------