note 65319 added to ref.mail

From: Date: Fri, 28 Apr 2006 15:55:00 +0000
Subject: note 65319 added to ref.mail
Groups: php.notes 
Request: Send a blank email to php-notes+get-110001@lists.php.net to get a copy of this message
The code block posted by anton at basehost dot net will corrupt all your php data if you try to use it. It turns all values in the POST array to nothing due to the fact that there is no $value_orig variable. There are other adjustments, read code to see. <?php // if this code breaks a client's website, you could just add them to this whitelist // Any domain in this whitelist array will not process this antispam script $whitelist = array('white-listed-domain.com'); // Make sure this domain is not in whitelist if (!in_array($_SERVER['HTTP_HOST'], $whitelist)) { # what we do - is we simply check all posted values. # (you may also want to add blocks for $_GET and $_REQUEST foreach($_POST as $f=>$v) { $_POST[$f] = _local_replace_bad($v); } # if register_globals is set to "on", then we should overwrite them once again. if (ini_get("register_globals") == 1) { extract($_POST, EXTR_OVERWRITE); //extract($_GET, EXTR_OVERWRITE); //depends on which array you have enabled above //extract($_REQUEST, EXTR_OVERWRITE); //depends on which array you have enabled above } } function _local_replace_bad($origvalue) { # mail adress(ess) for reports... $report_to = "youremail@yourdomain.com"; # array holding strings to check, we do not trust these strings in $_POST $suspicious_str = array ( "content-type:" ,"charset=" ,"mime-version:" ,"multipart/mixed" ,"bcc:" ); $suspect_found = false; // remove added slashes from $value... $value = stripslashes($origvalue); # checks if $value contains $suspect... foreach($suspicious_str as $suspect) { if(eregi($suspect, strtolower($value))) { # if we found some suspicios string, then we add our string, so it # will be messed a little bit. :) $suspect_found = true; $value = eregi_replace($suspect, "(anti-spam-".$suspect.")", $value); } } if ($suspect_found) { # if at least one suspicios string was found, then do something more # Remember, that POST values were already changed. But we still want to inform our # admin about this suspicios request. if(isset($report_to) && !empty($report_to)) { @mail( $report_to, "[ABUSE] [SUSPECT] @ " . $_SERVER['HTTP_HOST'] . " by " . $ip, "Stopped possible mail-injection @ " . $_SERVER['HTTP_HOST'] . " by " . $ip . " (" . date('d/m/Y H:i:s') . ")\r\n\r\n" . "*** IP/HOST\r\n" . $ip . "\r\n\r\n" . "*** USER AGENT\r\n" . $ua . "\r\n\r\n" . "*** REFERER\r\n" . $rf . "\r\n\r\n" . "*** REQUEST URI\r\n" . $ru . "\r\n\r\n" . "*** REQUEST METHOD\r\n" . $rm . "\r\n\r\n" . "*** SUSPECT\r\n-----\r\n" . $value . "\r\n-----" ); } # if report $ip = (empty($_SERVER['REMOTE_ADDR'])) ? 'empty' : $_SERVER['REMOTE_ADDR']; $rf = (empty($_SERVER['HTTP_REFERER'])) ? 'empty' : $_SERVER['HTTP_REFERER']; $ua = (empty($_SERVER['HTTP_USER_AGENT'])) ? 'empty' : $_SERVER['HTTP_USER_AGENT']; $ru = (empty($_SERVER['REQUEST_URI'])) ? 'empty' : $_SERVER['REQUEST_URI']; $rm = (empty($_SERVER['REQUEST_METHOD'])) ? 'empty' : $_SERVER['REQUEST_METHOD']; # very often HTTP_USER_AGENT is empty. We consider this is 100% spam if ($suspect_found && $ua == "empty") { # exit the called script to stop the spammer. exit(); } } # end if suscpect found else { $value = $origvalue; } return($value); } ?> ---- Server IP: 196.40.45.72 Probable Submitter: 196.40.32.237 (proxied: 196.40.32.237) ---- X-Spam-Status: No, hits=3.1 required=5.0 tests=DATE_MISSING,FROM_NO_LOWER autolearn=no version=2.64 ---- Manual Page -- http://www.php.net/manual/en/ref.mail.php Edit -- http://master.php.net/note/edit/65319 Del: integrated -- http://master.php.net/note/delete/65319/integrated Del: useless -- http://master.php.net/note/delete/65319/useless Del: bad code -- http://master.php.net/note/delete/65319/bad+code Del: spam -- http://master.php.net/note/delete/65319/spam Del: non-english -- http://master.php.net/note/delete/65319/non-english Del: in docs -- http://master.php.net/note/delete/65319/in+docs Del: other reasons-- http://master.php.net/note/delete/65319 Reject -- http://master.php.net/note/reject/65319 Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#110001) next »