note 66415 modified in function.mail by bobby
| From: | bobby@php.net | Date: | Tue, 10 Oct 2006 20:46:56 +0000 |
| Subject: | note 66415 modified in function.mail by bobby | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-118363@lists.php.net to get a copy of this message | ||
Here's my way of detecting an attempt to hijack my mail form.
<?php #requires PHP 5 or greater
$request = array_map('trim',($_SERVER['REQUEST_METHOD'] == "POST") ?
$_POST : $_GET) ;
//check for spam injection
$allfields = implode('',$request) ;
$nontext = $request ;
unset($nontext['message'] );
$nontextfields = implode ('',$nontext) ;
if ((strpos ($nontextfields,"\\r")!==false) ||
(strpos ($nontextfields,"\\n")!==false) ||
(stripos ($allfields,"Content-Transfer-Encoding")!==false) ||
(stripos ($allfields,"MIME-Version")!==false) ||
(stripos ($allfields,"Content-Type")!==false) ||
($request['checkfield']!=$check) ||
(empty($_SERVER['HTTP_USER_AGENT']))) die('Incorrect request') ; //stop
spammers ?>
First, I put the data into an array $request, then set up two strings: $allfields, which is just all
fields concatenated, then $nontext, which excludes those fields in which \r\n is allowed (e.g., the
message body). Any form field in which \r\n is allowed should be unset in the $nontext array before
the second implode function (my message field is called 'message', so I unset that). I
also include a hidden field in the form with a preset value ('checkfield', $check), so I
can see if something is trying to alter all fields.
This is a combination of a lot of things mentioned in the messages below...
--was--
Here's my way of detecting an attempt to hijack my mail form.
<?php #requires PHP 5 or greater
$request = array_map('trim',($_SERVER['REQUEST_METHOD'] == "POST") ?
$_POST : $_GET) ;
//check for spam injection
$allfields = implode('',$request) ;
$nontext = $request ;
unset($nontext['message'] );
$nontextfields = implode ('',$nontext) ;
if ((strpos ($nontextfields,"\\r")!==false) ||
(strpos ($nontextfields,"\\n")!==false) ||
(stripos ($allfields,"Content-Transfer-Encoding")!==false) ||
(stripos ($allfields,"MIME-Version")!==false) ||
(stripos ($allfields,"Content-Type")!==false) ||
($request['checkfield']!=$check) ||
(empty($_SERVER['HTTP_USER_AGENT']))) die('Incorrect request') ; //stop
spammers ?>
First, I put the data into an array $request, then set up two strings: $allfields, which is just all
fields concatenated, then $nontext, which excludes those fields in which \\r\\n is allowed (e.g.,
the message body). Any form field in which \\r\\n is allowed should be unset in the $nontext array
before the second implode function (my message field is called 'message', so I unset
that). I also include a hidden field in the form with a preset value ('checkfield',
$check), so I can see if something is trying to alter all fields.
This is a combination of a lot of things mentioned in the messages below...
http://php.net/manual/en/function.mail.php