note 59883 deleted from ref.mail by mazzanet
| From: | mazzanet@php.net | Date: | Sun, 25 Dec 2005 23:03:28 +0000 |
| Subject: | note 59883 deleted from ref.mail by mazzanet | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-100692@lists.php.net to get a copy of this message | ||
Note Submitter: omgs
----
Whoever puts a form in a page to send mail, is forced to make extra efforts to prevent the form to
be used for extra tasks not supposed to be done. The described techniques by setting some kind of
filters are good, but IMHO, can't prevent DoS by scripting, since the work is all done on the
server side. To raise the server protection level, the only way I've found is by some basic
javascript check on the "sender_name", "sender_email" and "subject"
fields (where headers can go). To prevent javascript is disabled, the first step is let javascript
draw the button. Instead of
echo "<input type=\"submit\" name=\"button\" value=\"send
mail\">";
you can do:
echo "<script type=\"text/javascript\">";
echo "document.write('<input type=\"submit\" name=\"button\"
value=\"send mail\">')";
echo "</script>";
Then, force check in the form declaration:
echo "<form method=\"POST\" action=\"myurl\" onsubmit=\"return
check(this)\">";
Then, the javascript code, that can be in a separate .js file, or included in a <script>
section (I'm not js expert at all, and you may find typos):
// This is a trim function, since there isn't a js native one
function trim(v)
{
if (typeof v != 'string')
{
return '';
}
else
{
return v.replace(/^\s*/, '').replace(/\s*$/, '');
}
}
// The real check function
function check(myform)
{
// Boolean variable to catch error
bForm=false;
if (trim(myform.sender_name.value) == '')
{
alert('Please, enter your name');
myform.sender_name.focus();
}
// Prevent injection characters like '\', ':' or '%'
else if ((myform.sender_name.value.indexOf("\\")!=-1)||
(myform.sender_name.value.indexOf(":")!=-1)||
(myform.sender_name.value.indexOf("%")!=-1))
{
alert('Wrong data');
myform.sender_name.focus();
}
else if ((trim(myform.sender_email.value) ==''))
{
alert('Please enter your email');
myform.sender_email.focus();
}
else if ((myform.sender_email.value.indexOf("@")==-1)||
(myform.sender_email.value.indexOf(".")==-1)||
(myform.sender_email.value.indexOf("\\")!=-1) ||
(myform.sender_email.value.indexOf(":")!=-1) ||
(myform.sender_email.value.indexOf("%")!=-1) )
{
alert('Wrong email address');
myform.sender_email.focus();
}
else if ((trim(myform.subject.value) == '') ||
(myform.subject.value.indexOf("\\")!=-1) ||
(myform.subject.value.indexOf(":")!=-1) ||
(myform.subject.value.indexOf("%")!=-1) )
{
alert('Please, enter a subject');
myform.subject.focus();
}
else
{
alert('Thanks for using our form!');
bForm=true;
}
return bForm;
}
This will raise a popup on the client side when any of the conditions is triggered, or when
successfully completes the form 'cleanly'.
As last resource, you can use the $_SERVER variables to check if the data is posted from the outside
instead of the server itself.
This is not perfect, but I hope it helps.