note 66415 modified in function.mail by bobby

From: Date: Tue, 10 Oct 2006 20:46:56 +0000
Subject: note 66415 modified in function.mail by bobby
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-118363@lists.php.net to get a copy of this message
Here's my way of detecting an attempt to hijack my mail form. <?php #requires PHP 5 or greater $request = array_map('trim',($_SERVER['REQUEST_METHOD'] == "POST") ? $_POST : $_GET) ; //check for spam injection $allfields = implode('',$request) ; $nontext = $request ; unset($nontext['message'] ); $nontextfields = implode ('',$nontext) ; if ((strpos ($nontextfields,"\\r")!==false) || (strpos ($nontextfields,"\\n")!==false) || (stripos ($allfields,"Content-Transfer-Encoding")!==false) || (stripos ($allfields,"MIME-Version")!==false) || (stripos ($allfields,"Content-Type")!==false) || ($request['checkfield']!=$check) || (empty($_SERVER['HTTP_USER_AGENT']))) die('Incorrect request') ; //stop spammers ?> First, I put the data into an array $request, then set up two strings: $allfields, which is just all fields concatenated, then $nontext, which excludes those fields in which \r\n is allowed (e.g., the message body). Any form field in which \r\n is allowed should be unset in the $nontext array before the second implode function (my message field is called 'message', so I unset that). I also include a hidden field in the form with a preset value ('checkfield', $check), so I can see if something is trying to alter all fields. This is a combination of a lot of things mentioned in the messages below... --was-- Here's my way of detecting an attempt to hijack my mail form. <?php #requires PHP 5 or greater $request = array_map('trim',($_SERVER['REQUEST_METHOD'] == "POST") ? $_POST : $_GET) ; //check for spam injection $allfields = implode('',$request) ; $nontext = $request ; unset($nontext['message'] ); $nontextfields = implode ('',$nontext) ; if ((strpos ($nontextfields,"\\r")!==false) || (strpos ($nontextfields,"\\n")!==false) || (stripos ($allfields,"Content-Transfer-Encoding")!==false) || (stripos ($allfields,"MIME-Version")!==false) || (stripos ($allfields,"Content-Type")!==false) || ($request['checkfield']!=$check) || (empty($_SERVER['HTTP_USER_AGENT']))) die('Incorrect request') ; //stop spammers ?> First, I put the data into an array $request, then set up two strings: $allfields, which is just all fields concatenated, then $nontext, which excludes those fields in which \\r\\n is allowed (e.g., the message body). Any form field in which \\r\\n is allowed should be unset in the $nontext array before the second implode function (my message field is called 'message', so I unset that). I also include a hidden field in the form with a preset value ('checkfield', $check), so I can see if something is trying to alter all fields. This is a combination of a lot of things mentioned in the messages below... http://php.net/manual/en/function.mail.php

« previous php.notes (#118363) next »