Rob*_*ent 2 php forms validation spam
今天有人联系我说从某个域发送了大量垃圾邮件。这是一个相对简单的 php 网站,带有包含姓名、电子邮件、电话和消息的联系表格。除非整个服务器被黑客入侵,否则我看不到该站点可用于向多个用户发送垃圾邮件的任何其他方式。
电子邮件经过验证,并从邮件正文中删除错误字符。我尝试了多种方法来尝试通过表单修改标题,但似乎无法获得任何工作,因此我开始认为表单是安全的。
这是表单验证:
$to='owner@website.com';
$messageSubject='Enquiry from the website';
$confirmationSubject='Your email to website.com';
$confirmationBody="Thankyou for your recent email enquiry to website.com.\n\nYour email has been sent and we will get back to you as soon as possible.\n\nThe message you sent was:\n";
$email='';
$body='';
$displayForm=true;
if ($_POST){
$email=stripslashes($_POST['email']);
$body=stripslashes($_POST['body']);
$name=stripslashes($_POST['name']);
$phone=stripslashes($_POST['phone']);
// validate e-mail address
$valid=eregi('^([0-9a-z]+[-._+&])*[0-9a-z]+@([-0-9a-z]+[.])+[a-z]{2,6}$',$email);
$crack=eregi("(\r|\n)(to:|from:|cc:|bcc:)",$body);
$spam=eregi("http",$body);
$businessBody = "Enquiry from: $name\nEmail: $email\nPhone: $phone\n\nMessage:\n$body";
if ($email && $body && $phone && $name && $valid && !$crack & !$spam){
if (mail($to,$messageSubject,$businessBody,'From: '.$email."\r\n") && mail($email,$confirmationSubject,$confirmationBody.$body,'From: '.$to."\r\n")){
$displayForm=false;
echo "<div><p>Your message to us was sent successfully, and a confirmation copy has also been sent to your e-mail address.</p><p>Your message was:<br>".htmlspecialchars($body)."</p></div>";
}
else echo '<div class="emailMessage"><p>Something went wrong when the server tried to send your message. This might be due to a server error, and is probably not your fault. We apologise for any inconvenience caused. You are welcome to telephone us on 01383 625110</p></div>'; // the messages could not be sent
}
else if ($crack) echo '<div class="emailMessage"><p>Your message contained e-mail headers within the message body. This seems to be a cracking attempt and the message has not been sent.</p></div>'; // cracking attempt
else if ($spam) echo '<div class="emailMessage"><p>Your message contained characters that our system has flagged as spam email and has not been sent.</p></div>'; // spam mail!
else echo '<div class="emailMessage"><p>Your message could not be sent. You must complete all fields - name, phone number, e-mail address and a message.</p></div>'; // form not complete
}
Run Code Online (Sandbox Code Playgroud)
任何人都可以看到这种形式可以被滥用的方式吗?
原来有人在为群发邮件而构建的服务器上放置了另一个加密文件,所以它实际上并不是来自这个表格。无论如何,感谢您的回答,他们可能会帮助他人!
使用像SwiftMailer这样的合适的邮件类,你会少一些麻烦(而且代码看起来也更漂亮)。通常,通过在“from”或其他标题中添加换行符来滥用这些类型的表单,从而允许他们设置自己的恶意标题。
例如:
if (mail($to,$messageSubject,$businessBody,'From: '.$email."\r\n") && mail($email,$confirmationSubject,$confirmationBody.$body,'From: '.$to."\r\n")){
Run Code Online (Sandbox Code Playgroud)
当你去掉斜杠时,你还没有去掉新行。如果我将电子邮件设置为:
ceejayoz@example.com
Bcc: victim@example.com
Run Code Online (Sandbox Code Playgroud)
victim@example.com 在电子邮件中被密送。通过一些更聪明的东西——把它变成一个多部分的电子邮件并添加一个额外的默认部分——他们可以完全自定义电子邮件。
| 归档时间: |
|
| 查看次数: |
4251 次 |
| 最近记录: |