Re: Help - PHP Security problems

From: Date: Tue, 06 Nov 2001 11:44:14 +0000
Subject: Re: Help - PHP Security problems
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-73574@lists.php.net to get a copy of this message
Also, you might want to consider an email validation. In other words, you send an email to the email address provided at the time of setup. This email would have a code!! or any other information which must be entered before an account is ACTIVATED - I don't think he will go to each email and start replying!! Also, to make it even worse, use an image that displays that code/number/etc... for ACTIVATION - This way he can't pretty much parse the image to extract the embedded text, I guess. Kal "Chris Ross" <asip@theross.com> wrote in message news:B80CBA52.7097%asip@theross.com... > Okay I have a huge problem... I need some help. > > I have a free lotto site (www.iwinweekly.com). I could go on to explain how > the site works but the best way to see is just to go there and play a ticket > or two (just enter any email address) > > Here is my problem. Some person from China has wrote a program to play our > tickets automatically. His program creates free email addresses from yahoo > and other free email sites. the the program uses these email addresses to > play our game. Then each email goes on and plays all the tickets and starts > over. The program does multiple threads at once. We have tried everything to > stop him.... he is using open relays from all over the world so we can't ban > his IP.... We can't even trace his IP. We have tried all kinds of PHP > security steps but every time we put one in place he finds away around it. > > Here's our security: > The user must enter any email address - we have basic pattern validation. > The user must have an IP address. > The user must follow our process - they're tracked with session variables. > > He is entering over 10,000 tickets per day and is screwing up stats. Does > anyone have any suggestions from a php standpoint or any on how to stop him? > > Thanks > Chris >

« previous php.general (#73574) next »