note 69754 deleted from function.mail by cmb
| From: | cmb@php.net | Date: | Sun, 21 Jul 2019 08:26:24 +0000 |
| Subject: | note 69754 deleted from function.mail by cmb | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-211631@lists.php.net to get a copy of this message | ||
Note Submitter: johniskew2
----
An important rule of thumb, because it seems few really follow it and it can alleviate so many
headaches: When filtering your email headers for injection characters use a regular expression to
judge whether the user's input is valid. For example to see if the user entered a valid e-mail
address use something like [a-zA-Z0-9._%-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,4}. Dont try to filter out
bad characters (like searching for LF or CR), because you will ALWAYS miss something. You can be
sure your application is more secure going this route....provided the regular expression is valid!
This same point goes for any sort of form input not just for sending out emails.