Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

PHP Forum


You are currently viewing our PHP Forum as a guest. Please register to participate.
Login



Freelance Jobs

Reply
Bogus contact us submits
Old 09-05-2005, 11:02 AM Bogus contact us submits
nixies78@yahoo.'s Avatar
Extreme Talker

Posts: 222
Trades: 0
This is strange for some reason we keep getting bogus submission on the contact us form on the website. Using a email address of our website and it keeps happening about two or three a day.

Does anyone know why?
__________________
Beware Dyslexic!
Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE
-
Please login or register to view this content. Registration is FREE
nixies78@yahoo. is offline
Reply With Quote
View Public Profile Visit nixies78@yahoo.'s homepage!
 
 
Register now for full access!
Old 09-05-2005, 12:45 PM
security's Avatar
Experienced Talker

Posts: 45
Trades: 0
....are there any strange/unusual characters being used? Sounds like someone is "testing" your forms, possibly looking for weaknesses to exploit.
__________________

Please login or register to view this content. Registration is FREE
security is offline
Reply With Quote
View Public Profile
 
Old 09-05-2005, 07:11 PM
Skilled Talker

Posts: 62
Trades: 0
One of my clients noticed something similar happening with his contact form - I would recommend temporarily saving a copy of all contact form submissions in a .txt file on your server, along with a copy of the IP address of the user submitting the form so you can check to see whether this is a hacker attempting to execute code or a spammer attempting to manipulate the headers on the outgoing mail (a common vulnerability if your contact page uses the mail() function) - sounds like there's definite cause to ban 'em.
__________________

Please login or register to view this content. Registration is FREE
danlefree is offline
Reply With Quote
View Public Profile Visit danlefree's homepage!
 
Old 09-06-2005, 08:29 AM
leavethisplace's Avatar
Ultra Talker

Posts: 297
Trades: 0
do you mean someone is emailing other people from your website using your sites email addresses (so it seems as though you are writing it) or do you mean you're getting emails sent through to yourself?

If the latter, simply stop people from sending in emails from the Contact form, using your email address - that should stop them using your email addresses. There isn't much you can do about it, other than blocking their IP and Host Mask.
__________________
A lie gets halfway around the world before the truth has a chance to get its pants on. - Sir Winston Churchill

Please visit my sites:
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
leavethisplace is offline
Reply With Quote
View Public Profile
 
Old 09-06-2005, 01:41 PM
Kyrnt's Avatar
The Post-Mod Years

Posts: 2,536
Location: Western Maryland
Trades: 0
A client of mine was also getting this behavior just this past weekend. I augmented the code to reject any attempt to use the client's domain in the form verification code.
__________________
—Kyrnt
Kyrnt is offline
Reply With Quote
View Public Profile Visit Kyrnt's homepage!
 
Reply     « Reply to Bogus contact us submits
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.19322 seconds with 12 queries