Re: Help - PHP Security problems
| From: | Kal Amry | Date: | Tue, 06 Nov 2001 11:44:14 +0000 |
| Subject: | Re: Help - PHP Security problems | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-73574@lists.php.net to get a copy of this message | ||
Also, you might want to consider an email validation. In other words, you
send an email to the email address provided at the time of setup. This email
would have a code!! or any other information which must be entered before an
account is ACTIVATED -
I don't think he will go to each email and start replying!!
Also, to make it even worse, use an image that displays that
code/number/etc... for ACTIVATION - This way he can't pretty much parse the
image to extract the embedded text, I guess.
Kal
"Chris Ross" <asip@theross.com> wrote in message
news:B80CBA52.7097%asip@theross.com...
> Okay I have a huge problem... I need some help.
>
> I have a free lotto site (www.iwinweekly.com). I could go on to explain
how
> the site works but the best way to see is just to go there and play a
ticket
> or two (just enter any email address)
>
> Here is my problem. Some person from China has wrote a program to play our
> tickets automatically. His program creates free email addresses from yahoo
> and other free email sites. the the program uses these email addresses to
> play our game. Then each email goes on and plays all the tickets and
starts
> over. The program does multiple threads at once. We have tried everything
to
> stop him.... he is using open relays from all over the world so we can't
ban
> his IP.... We can't even trace his IP. We have tried all kinds of PHP
> security steps but every time we put one in place he finds away around it.
>
> Here's our security:
> The user must enter any email address - we have basic pattern validation.
> The user must have an IP address.
> The user must follow our process - they're tracked with session variables.
>
> He is entering over 10,000 tickets per day and is screwing up stats. Does
> anyone have any suggestions from a php standpoint or any on how to stop
him?
>
> Thanks
> Chris
>