note 59883 added to ref.mail
| From: | omgs at osu1 dot php dot net | Date: | Mon, 19 Dec 2005 10:47:34 +0000 |
| Subject: | note 59883 added to ref.mail | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-100400@lists.php.net to get a copy of this message | ||
Whoever puts a form in a page to send mail, is forced to make extra efforts to prevent the form to
be used for extra tasks not supposed to be done. The described techniques by setting some kind of
filters are good, but IMHO, can't prevent DoS by scripting, since the work is all done on the
server side. To raise the server protection level, the only way I've found is by some basic
javascript check on the "sender_name", "sender_email" and "subject"
fields (where headers can go). To prevent javascript is disabled, the first step is let javascript
draw the button. Instead of
echo "<input type=\"submit\" name=\"button\" value=\"send
mail\">";
you can do:
echo "<script type=\"text/javascript\">";
echo "document.write('<input type=\"submit\" name=\"button\"
value=\"send mail\">')";
echo "</script>";
Then, force check in the form declaration:
echo "<form method=\"POST\" action=\"myurl\" onsubmit=\"return
check(this)\">";
Then, the javascript code, that can be in a separate .js file, or included in a <script>
section (I'm not js expert at all, and you may find typos):
// This is a trim function, since there isn't a js native one
function trim(v)
{
if (typeof v != 'string')
{
return '';
}
else
{
return v.replace(/^\s*/, '').replace(/\s*$/, '');
}
}
// The real check function
function check(myform)
{
// Boolean variable to catch error
bForm=false;
if (trim(myform.sender_name.value) == '')
{
alert('Please, enter your name');
myform.sender_name.focus();
}
// Prevent injection characters like '\', ':' or '%'
else if ((myform.sender_name.value.indexOf("\\")!=-1)||
(myform.sender_name.value.indexOf(":")!=-1)||
(myform.sender_name.value.indexOf("%")!=-1))
{
alert('Wrong data');
myform.sender_name.focus();
}
else if ((trim(myform.sender_email.value) ==''))
{
alert('Please enter your email');
myform.sender_email.focus();
}
else if ((myform.sender_email.value.indexOf("@")==-1)||
(myform.sender_email.value.indexOf(".")==-1)||
(myform.sender_email.value.indexOf("\\")!=-1) ||
(myform.sender_email.value.indexOf(":")!=-1) ||
(myform.sender_email.value.indexOf("%")!=-1) )
{
alert('Wrong email address');
myform.sender_email.focus();
}
else if ((trim(myform.subject.value) == '') ||
(myform.subject.value.indexOf("\\")!=-1) ||
(myform.subject.value.indexOf(":")!=-1) ||
(myform.subject.value.indexOf("%")!=-1) )
{
alert('Please, enter a subject');
myform.subject.focus();
}
else
{
alert('Thanks for using our form!');
bForm=true;
}
return bForm;
}
This will raise a popup on the client side when any of the conditions is triggered, or when
successfully completes the form 'cleanly'.
As last resource, you can use the $_SERVER variables to check if the data is posted from the outside
instead of the server itself.
This is not perfect, but I hope it helps.
----
Manual Page -- http://www.php.net/manual/en/ref.mail.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+59883
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+59883&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+59883&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+59883&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+59883&report=yes&reason=useless
Delete: non-english -- http://master.php.net/manage/user-notes.php?action=delete+59883&report=yes&reason=non-english
Delete: already in docs -- http://master.php.net/manage/user-notes.php?action=delete+59883&report=yes&reason=already+in+docs
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+59883&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+59883&report=yes
Search -- http://master.php.net/manage/user-notes.php