note 59883 added to ref.mail

From: Date: Mon, 19 Dec 2005 10:47:34 +0000
Subject: note 59883 added to ref.mail
Groups: php.notes 
Request: Send a blank email to php-notes+get-100400@lists.php.net to get a copy of this message
Whoever puts a form in a page to send mail, is forced to make extra efforts to prevent the form to be used for extra tasks not supposed to be done. The described techniques by setting some kind of filters are good, but IMHO, can't prevent DoS by scripting, since the work is all done on the server side. To raise the server protection level, the only way I've found is by some basic javascript check on the "sender_name", "sender_email" and "subject" fields (where headers can go). To prevent javascript is disabled, the first step is let javascript draw the button. Instead of echo "<input type=\"submit\" name=\"button\" value=\"send mail\">"; you can do: echo "<script type=\"text/javascript\">"; echo "document.write('<input type=\"submit\" name=\"button\" value=\"send mail\">')"; echo "</script>"; Then, force check in the form declaration: echo "<form method=\"POST\" action=\"myurl\" onsubmit=\"return check(this)\">"; Then, the javascript code, that can be in a separate .js file, or included in a <script> section (I'm not js expert at all, and you may find typos): // This is a trim function, since there isn't a js native one function trim(v) { if (typeof v != 'string') { return ''; } else { return v.replace(/^\s*/, '').replace(/\s*$/, ''); } } // The real check function function check(myform) { // Boolean variable to catch error bForm=false; if (trim(myform.sender_name.value) == '') { alert('Please, enter your name'); myform.sender_name.focus(); } // Prevent injection characters like '\', ':' or '%' else if ((myform.sender_name.value.indexOf("\\")!=-1)|| (myform.sender_name.value.indexOf(":")!=-1)|| (myform.sender_name.value.indexOf("%")!=-1)) { alert('Wrong data'); myform.sender_name.focus(); } else if ((trim(myform.sender_email.value) =='')) { alert('Please enter your email'); myform.sender_email.focus(); } else if ((myform.sender_email.value.indexOf("@")==-1)|| (myform.sender_email.value.indexOf(".")==-1)|| (myform.sender_email.value.indexOf("\\")!=-1) || (myform.sender_email.value.indexOf(":")!=-1) || (myform.sender_email.value.indexOf("%")!=-1) ) { alert('Wrong email address'); myform.sender_email.focus(); } else if ((trim(myform.subject.value) == '') || (myform.subject.value.indexOf("\\")!=-1) || (myform.subject.value.indexOf(":")!=-1) || (myform.subject.value.indexOf("%")!=-1) ) { alert('Please, enter a subject'); myform.subject.focus(); } else { alert('Thanks for using our form!'); bForm=true; } return bForm; } This will raise a popup on the client side when any of the conditions is triggered, or when successfully completes the form 'cleanly'. As last resource, you can use the $_SERVER variables to check if the data is posted from the outside instead of the server itself. This is not perfect, but I hope it helps. ---- Manual Page -- http://www.php.net/manual/en/ref.mail.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+59883 Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+59883&report=yes&reason=added+to+the+manual Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+59883&report=yes&reason=bad+code Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+59883&report=yes&reason=spam Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+59883&report=yes&reason=useless Delete: non-english -- http://master.php.net/manage/user-notes.php?action=delete+59883&report=yes&reason=non-english Delete: already in docs -- http://master.php.net/manage/user-notes.php?action=delete+59883&report=yes&reason=already+in+docs Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+59883&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+59883&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#100400) next »