note 65319 deleted from ref.mail by bjori

From: Date: Thu, 25 May 2006 12:29:29 +0000
Subject: note 65319 deleted from ref.mail by bjori
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-112171@lists.php.net to get a copy of this message
Note Submitter: mfp ---- The code block posted by anton at basehost dot net will corrupt all your php data if you try to use it. It turns all values in the POST array to nothing due to the fact that there is no $value_orig variable. There are other adjustments, read code to see. <?php // if this code breaks a client's website, you could just add them to this whitelist // Any domain in this whitelist array will not process this antispam script $whitelist = array('white-listed-domain.com'); // Make sure this domain is not in whitelist if (!in_array($_SERVER['HTTP_HOST'], $whitelist)) { # what we do - is we simply check all posted values. # (you may also want to add blocks for $_GET and $_REQUEST foreach($_POST as $f=>$v) { $_POST[$f] = _local_replace_bad($v); } # if register_globals is set to "on", then we should overwrite them once again. if (ini_get("register_globals") == 1) { extract($_POST, EXTR_OVERWRITE); //extract($_GET, EXTR_OVERWRITE); //depends on which array you have enabled above //extract($_REQUEST, EXTR_OVERWRITE); //depends on which array you have enabled above } } function _local_replace_bad($origvalue) { # mail adress(ess) for reports... $report_to = "youremail@yourdomain.com"; # array holding strings to check, we do not trust these strings in $_POST $suspicious_str = array ( "content-type:" ,"charset=" ,"mime-version:" ,"multipart/mixed" ,"bcc:" ); $suspect_found = false; // remove added slashes from $value... $value = stripslashes($origvalue); # checks if $value contains $suspect... foreach($suspicious_str as $suspect) { if(eregi($suspect, strtolower($value))) { # if we found some suspicios string, then we add our string, so it # will be messed a little bit. :) $suspect_found = true; $value = eregi_replace($suspect, "(anti-spam-".$suspect.")", $value); } } if ($suspect_found) { # if at least one suspicios string was found, then do something more # Remember, that POST values were already changed. But we still want to inform our # admin about this suspicios request. if(isset($report_to) && !empty($report_to)) { @mail( $report_to, "[ABUSE] [SUSPECT] @ " . $_SERVER['HTTP_HOST'] . " by " . $ip, "Stopped possible mail-injection @ " . $_SERVER['HTTP_HOST'] . " by " . $ip . " (" . date('d/m/Y H:i:s') . ")\r\n\r\n" . "*** IP/HOST\r\n" . $ip . "\r\n\r\n" . "*** USER AGENT\r\n" . $ua . "\r\n\r\n" . "*** REFERER\r\n" . $rf . "\r\n\r\n" . "*** REQUEST URI\r\n" . $ru . "\r\n\r\n" . "*** REQUEST METHOD\r\n" . $rm . "\r\n\r\n" . "*** SUSPECT\r\n-----\r\n" . $value . "\r\n-----" ); } # if report $ip = (empty($_SERVER['REMOTE_ADDR'])) ? 'empty' : $_SERVER['REMOTE_ADDR']; $rf = (empty($_SERVER['HTTP_REFERER'])) ? 'empty' : $_SERVER['HTTP_REFERER']; $ua = (empty($_SERVER['HTTP_USER_AGENT'])) ? 'empty' : $_SERVER['HTTP_USER_AGENT']; $ru = (empty($_SERVER['REQUEST_URI'])) ? 'empty' : $_SERVER['REQUEST_URI']; $rm = (empty($_SERVER['REQUEST_METHOD'])) ? 'empty' : $_SERVER['REQUEST_METHOD']; # very often HTTP_USER_AGENT is empty. We consider this is 100% spam if ($suspect_found && $ua == "empty") { # exit the called script to stop the spammer. exit(); } } # end if suscpect found else { $value = $origvalue; } return($value); } ?>

« previous php.notes (#112171) next »