RE: [PHP] Follow up - PHP Security problems

From: Date: Wed, 07 Nov 2001 02:30:08 +0000
Subject: RE: [PHP] Follow up - PHP Security problems
Groups: php.general 
Request: Send a blank email to php-general+get-73668@lists.php.net to get a copy of this message
look at the image section of the manual. My local pdf copy has it as section XXVII -----Original Message----- From: Chris Ross [mailto:asip@theross.com] Sent: Wednesday, November 07, 2001 1:28 PM To: php-general@lists.php.net Subject: [PHP] Follow up - PHP Security problems Thank you all for your posts.... we have stopped them temporarily by suspending all the free email domains he was using. In the meantime we are going to create something simular to altavista and yahoo verification check. Basically an image with different letters and they have to put the correct letters in. They only have to do this once and then the account is activated and can submit tickets. If any one know where I can get info on creating this process or one simular with PHP that would be great. Thanks you all for your responses. Chris http://www.iwinweekly.com Original Question bellow: <<Okay I have a huge problem... I need some help. I have a free lotto site (www.iwinweekly.com). I could go on to explain how the site works but the best way to see is just to go there and play a ticket or two (just enter any email address) Here is my problem. Some person from China has wrote a program to play our tickets automatically. His program creates free email addresses from yahoo and other free email sites. the the program uses these email addresses to play our game. Then each email goes on and plays all the tickets and starts over. The program does multiple threads at once. We have tried everything to stop him.... he is using open relays from all over the world so we can't ban his IP.... We can't even trace his IP. We have tried all kinds of PHP security steps but every time we put one in place he finds away around it. Here's our security: The user must enter any email address - we have basic pattern validation. The user must have an IP address. The user must follow our process - they're tracked with session variables. He is entering over 10,000 tickets per day and is screwing up stats. Does anyone have any suggestions from a php standpoint or any on how to stop him? Thanks Chris >> -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#73668) next »