note 65319 added to ref.mail
| From: | mfp at osu1 dot php dot net | Date: | Fri, 28 Apr 2006 15:55:00 +0000 |
| Subject: | note 65319 added to ref.mail | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-110001@lists.php.net to get a copy of this message | ||
The code block posted by anton at basehost dot net will corrupt all your php data if you try to use
it. It turns all values in the POST array to nothing due to the fact that there is no $value_orig
variable. There are other adjustments, read code to see.
<?php
// if this code breaks a client's website, you could just add them to this whitelist
// Any domain in this whitelist array will not process this antispam script
$whitelist = array('white-listed-domain.com');
// Make sure this domain is not in whitelist
if (!in_array($_SERVER['HTTP_HOST'], $whitelist))
{
# what we do - is we simply check all posted values.
# (you may also want to add blocks for $_GET and $_REQUEST
foreach($_POST as $f=>$v) {
$_POST[$f] = _local_replace_bad($v);
}
# if register_globals is set to "on", then we should overwrite them once again.
if (ini_get("register_globals") == 1)
{
extract($_POST, EXTR_OVERWRITE);
//extract($_GET, EXTR_OVERWRITE); //depends on which array you have enabled above
//extract($_REQUEST, EXTR_OVERWRITE); //depends on which array you have enabled above
}
}
function _local_replace_bad($origvalue) {
# mail adress(ess) for reports...
$report_to = "youremail@yourdomain.com";
# array holding strings to check, we do not trust these strings in $_POST
$suspicious_str = array
(
"content-type:"
,"charset="
,"mime-version:"
,"multipart/mixed"
,"bcc:"
);
$suspect_found = false;
// remove added slashes from $value...
$value = stripslashes($origvalue);
# checks if $value contains $suspect...
foreach($suspicious_str as $suspect) {
if(eregi($suspect, strtolower($value))) {
# if we found some suspicios string, then we add our string, so it
# will be messed a little bit. :)
$suspect_found = true;
$value = eregi_replace($suspect, "(anti-spam-".$suspect.")", $value);
}
}
if ($suspect_found) {
# if at least one suspicios string was found, then do something more
# Remember, that POST values were already changed. But we still want to inform our
# admin about this suspicios request.
if(isset($report_to) && !empty($report_to)) {
@mail(
$report_to,
"[ABUSE] [SUSPECT] @ " . $_SERVER['HTTP_HOST'] . " by "
. $ip,
"Stopped possible mail-injection @ " .
$_SERVER['HTTP_HOST'] . " by " . $ip .
" (" . date('d/m/Y H:i:s') . ")\r\n\r\n" .
"*** IP/HOST\r\n" . $ip . "\r\n\r\n" .
"*** USER AGENT\r\n" . $ua . "\r\n\r\n" .
"*** REFERER\r\n" . $rf . "\r\n\r\n" .
"*** REQUEST URI\r\n" . $ru . "\r\n\r\n" .
"*** REQUEST METHOD\r\n" . $rm . "\r\n\r\n" .
"*** SUSPECT\r\n-----\r\n" . $value . "\r\n-----"
);
} # if report
$ip = (empty($_SERVER['REMOTE_ADDR'])) ? 'empty' :
$_SERVER['REMOTE_ADDR'];
$rf = (empty($_SERVER['HTTP_REFERER'])) ? 'empty' :
$_SERVER['HTTP_REFERER'];
$ua = (empty($_SERVER['HTTP_USER_AGENT'])) ? 'empty' :
$_SERVER['HTTP_USER_AGENT'];
$ru = (empty($_SERVER['REQUEST_URI'])) ? 'empty' :
$_SERVER['REQUEST_URI'];
$rm = (empty($_SERVER['REQUEST_METHOD'])) ? 'empty' :
$_SERVER['REQUEST_METHOD'];
# very often HTTP_USER_AGENT is empty. We consider this is 100% spam
if ($suspect_found && $ua == "empty") {
# exit the called script to stop the spammer.
exit();
}
} # end if suscpect found
else
{ $value = $origvalue; }
return($value);
}
?>
----
Server IP: 196.40.45.72
Probable Submitter: 196.40.32.237 (proxied: 196.40.32.237)
----
X-Spam-Status: No, hits=3.1 required=5.0 tests=DATE_MISSING,FROM_NO_LOWER
autolearn=no version=2.64
----
Manual Page -- http://www.php.net/manual/en/ref.mail.php
Edit -- http://master.php.net/note/edit/65319
Del: integrated -- http://master.php.net/note/delete/65319/integrated
Del: useless -- http://master.php.net/note/delete/65319/useless
Del: bad code -- http://master.php.net/note/delete/65319/bad+code
Del: spam -- http://master.php.net/note/delete/65319/spam
Del: non-english -- http://master.php.net/note/delete/65319/non-english
Del: in docs -- http://master.php.net/note/delete/65319/in+docs
Del: other reasons-- http://master.php.net/note/delete/65319
Reject -- http://master.php.net/note/reject/65319
Search -- http://master.php.net/manage/user-notes.php