note 55111 added to function.mail
| From: | jfonseca at matarese dot com | Date: | Tue, 26 Jul 2005 00:33:01 +0000 |
| Subject: | note 55111 added to function.mail | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-92437@lists.php.net to get a copy of this message | ||
This is NOT PHP-specific but worth mentioning on the mail() page.
Watch out for sendmail command injection on your pages which call the mail() function.
How it works: the attacker will inject SMTP into your form unless you make it real clear where the
header ends. Most people simply don't add a header or a \r\n\r\n sequence to their mail header
forms.
Example : a new BCC: field can be injected so that your form can be used to deliver mail to any
valid address the attacker chooses.
Since the httpd server host is a trusted host your MX will probably relay without asking any
questions.
Be careful with any function that accepts user input.
Hope this helps.
----
Manual Page -- http://www.php.net/manual/en/function.mail.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+55111
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+55111&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+55111&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+55111&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+55111&report=yes&reason=useless
Delete: non-english -- http://master.php.net/manage/user-notes.php?action=delete+55111&report=yes&reason=non-english
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+55111&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+55111&report=yes
Search -- http://master.php.net/manage/user-notes.php