note 28918 deleted from function.eregi by nlopess

From: Date: Tue, 20 Jan 2004 16:18:13 +0000
Subject: note 28918 deleted from function.eregi by nlopess
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-63888@lists.php.net to get a copy of this message
Note Submitter: I_Hate_Bogus_Email_Addresses ---- FYI, I have experienced a rampant escalation of bogus e-mail address entries into several of my various website forms (especially the Chinese...they are notorious for BOGUS addresses and I get a lot of mail allegedly from abc@abc.com tied to Chinese IP addresses and too <explicative deleted> many other forgeries). In fact, out of an initial test of about 1157 entries well over 300 were bogus e-mail addresses which bounced. This, even after, basic e-mail format rules filtering. And there are also those jerks who enter a FORGERY of my own address. Due to some of the high-profile domains I am working with (which seem to attract net criminals and net leeches), I'm concerned about a barrage of rejected/returned e-mail which will result from bogus Registration entries to the IPB forum boards. I'm a mini-Perl hacker and thanks to one of the gurus on a Perl newsgroup, came up with a more extensive e-mail filtering REGEXP which helped to substantially eliminate unnecessary e-mails being generated only to have them bounce. The classic bogus forgeries (especially from China) seem to take on the following format: 8888888aaaaa@37856666666.com 0@0.com www@#^sxy.com.cn ...etc., etc. Here's the Perl code I'm using to just bounce MANY of these bogus attempts immediately back into their faces and sure would like to see a PHP version 'cuz it works great! Maybe someone can incorporate this with the bounce-back HTML Echo stuff. I decided upon this coding approach in lieu of one "Monster" REGEXP because I can get in and do additional tweakings very easily. I don't know if this will format correctly in the post or not. -------------------------------------------------------------------- #CHECK E-MAIL FORMAT VALIDITY (ROUGH TEST) my $email = $FORM{'email'}; # use this line for live CGI Form processing #my $email = 'user@somedomain.com'; # e-mail entry for testing only - comment out email_check() if length $email >40 # most likely bogus or some malicious code! or $email !~ /[!@]/ # bounce character/word screwaround entries or $email =~ m/\s/ # delete some valid email addresses :-) or $email =~ m/^[^A-Za-z0-9]/ # checks front part of e-mail or $email =~ m/[^A-Za-z0-9]\@/ # checks part just before @ or $email =~ m/\@[^A-Za-z0-9]/ # checks part right after @ or $email =~ m/.*[^A-Za-z0-9]\./ # checks part right before .TLD or $email !~ m/.*\.[A-Za-z]{2,4}$/ # checks for 2-4 character TLD or $email =~ m/www/ # bounce dumbo 'www' format entries or $email =~ m/([A-Za-z0-9]){4,15}/ # bounce aaaaa 88888 etc. types or $email =~ m/^[(\d|\D)]\@[(\d|\D)]\.[A-Za-z]{2,4}$/ # bounce dumbo 0@0.com format entries or $email =~ m/^.*[~!@#%\^&*()[\]{}\|;:"'<,>?\/].*\@/ # check weirdos before @ or $email =~ m/^.*\@.*[~!@#%\^&*()_[\]{}\|;:"'<,>?\/].*\./ # check weirdos before .TLD or $email =~ m/\@mydomain\.com$/; # axes email forgeries of (myowndomain) #### DON'T FORGET TO CHANGE/UNCOMMENT THE FILEWRITING LINES !!!! # subroutine email_check # Print a title and initial heading and reject text sub email_check { print "<Head><Title>Thank You</Title></Head>"; print "<Body><H1>Thank You</H1>"; print "Your e-mail address appears to be invalid and we can not process "; print "your request(s). Please backup and re-enter.\r\n"; print "<HR>"; print "Return to <A HREF=\"http://www.mydomain.com/index.html\">Webpage</A>.<P>"; exit; } ------------------------------------------------------------------- Hope someone else finds interest & can maybe code into PHP language :-) I_Hate_Bogus_Email_Addresses

« previous php.notes (#63888) next »