March 4, 201214 yr Hello, so this is my site: Website As you can see under the header i have a suggestions box. However there is nothing to stop people just clicking send etc and ill recieve emails all day long. Whats the best way around this? Im not sure how to not allow empty fields? And what other measures can i take? Heres the code: <?php if(isset($_POST['submit'])) { $to = "myemail"; $subject = "Suggestion"; $email_field = $_POST['email']; $message = $_POST['message']; $body = "From: $name_field\n E-Mail: $email_field\n Message:\n $message"; echo '<div id="submitmessage">', "Suggestion sent! If chosen, you will receieve and email shortly!", '</div>'; mail($to, $subject, $body); } ?> Thanks! Edited March 4, 201214 yr by Lovelock
March 4, 201214 yr Hello, so this is my site: Website As you can see under the header i have a suggestions box. However there is nothing to stop people just clicking send etc and ill recieve emails all day long. Whats the best way around this? Im not sure how to not allow empty fields? And what other measures can i take? Heres the code: <?php if(isset($_POST['submit'])) { $to = "myemail"; $subject = "Suggestion"; $email_field = $_POST['email']; $message = $_POST['message']; $body = "From: $name_field\n E-Mail: $email_field\n Message:\n $message"; echo '<div id="submitmessage">', "Suggestion sent! If chosen, you will receieve and email shortly!", '</div>'; mail($to, $subject, $body); } ?> Thanks! um i'd suggest a professional built form, u can try mine by downloading it here RizoContact i never have had a problem with spam using my form
March 4, 201214 yr If it's people manually sending you're worried about, could you put some sort of session variable which say only allowed them to send a certain number of messages? Or a timer which only allowed them to send a message every 30 seconds or so, similar to the flood control on the search facility on WDF.
March 4, 201214 yr Author I think a session variable may be the best bet... as for checking if fields are empty, is just field validation im guessing?
March 4, 201214 yr I think a session variable may be the best bet... as for checking if fields are empty, is just field validation im guessing? $name = (isset($_POST['name'])) ? $_POST['name'] : false; if(!$name){ //Name field is empty } you also may wanna sanitize your fields, but i still suggest just using a prebuilt form spammers are patient, a session will not stop them from spamming ur inbox 5 or 10 times a day
March 4, 201214 yr Hello, so this is my site: Website As you can see under the header i have a suggestions box. However there is nothing to stop people just clicking send etc and ill recieve emails all day long. Whats the best way around this? Im not sure how to not allow empty fields? And what other measures can i take? Heres the code: <?php if(isset($_POST['submit'])) { $to = "myemail"; $subject = "Suggestion"; $email_field = $_POST['email']; $message = $_POST['message']; $body = "From: $name_field\n E-Mail: $email_field\n Message:\n $message"; echo '<div id="submitmessage">', "Suggestion sent! If chosen, you will receieve and email shortly!", '</div>'; mail($to, $subject, $body); } ?> Thanks! One way as has been mentioned on here is to place a time limit between sending messages which irritates the hell out of idiots trying to send spam via your contact us form. Time yourself filling out the form to see how long it takes you, then use this as a benchmark. Another route used by forum registration forms is to generate a randomly pulled Question/answer field which is unique to your website which will stop the automated spammers in their tracks. On forums you can make up as many questions & answers as you like which are then randomly pulled. Change or edit the questions from time to time. The list of randomly pulled questions and answers is unique to your website or forum, this makes it incredibly difficult to be answered by an automated script, and any cheap foreign labourers employed abroad to break the captcha method may not even be able to read English let alone write down the answer! Examples being: Add up the two numbers 2+7:9 Name a Italian supercar manufacturer beginning with F:Ferrari What is the colour of a UK mobile phone company beginning with O:Orange What's the name of a well known computer company in the US that is also a fruit:Apple What is the christian name of the footballer married to Victoria Beckham:David The questions could be related to your site and don't actually have to be too hard. The problem with the captcha method is that text automated recognition systems are getting very good at reading these methods, sometimes better than mere mortals trying to genuinely fill out the form! Am sure there are some knowledgeable coders on here who could compile the code for you if you ask nicely.
March 5, 201214 yr @OP: if you;re worried at all about conversions, ignore all the advice about the having the user answer questions or other silly anti spam measures. So people cant figure out simple math questions? lol EDIT: also i'd like to point out all those missing conversions could also very well be spammers/spam bots, Edited March 5, 201214 yr by webdesigner93
March 5, 201214 yr So people cant figure out simple math questions? lol So if you were visiting a foreign website with the intention of spamming it and encountered this registration question, would it be simple for you to answer or would you move onto the next easier site to spam. Here's the question: Beantworten Sie folgende Frage. Was ist zwei und sieben addiert The maths question is only an example, but it demonstrates how difficult even the simplest of questions can stop a human spammer who doesn't speak the language of that country. Edited March 5, 201214 yr by richwdf
March 5, 201214 yr Author Thanks for the replys. Ill be looking into santization and validation later. I think the best way for me is to check for a valid email and only allow say 1 suggestion a day or something.
March 5, 201214 yr Thanks for the replys. Ill be looking into santization and validation later. I think the best way for me is to check for a valid email and only allow say 1 suggestion a day or something. yes this is a good way as well
March 5, 201214 yr Thanks for the replys. Ill be looking into santization and validation later. I think the best way for me is to check for a valid email and only allow say 1 suggestion a day or something. But then I could just input something like this "ajnjana@kanan.naa" and that'll validate as a real email.
March 5, 201214 yr ...Ill be looking into santization and validation later... You need to do it ASAP. These things are huge problems. Sanitization needs to be done to prevent people from blowing up your database and validation needs to be done to provide a positive user experience. Then you worry about preventing spam, since that's a problem that only affects the person who receives the e-mail. And, keep in mind, you should never put the burden on the user to prevent spam. Edited March 5, 201214 yr by porkchops
March 5, 201214 yr Author You need to do it ASAP. These things are huge problems. Sanitization needs to be done to prevent people from blowing up your database and validation needs to be done to provide a positive user experience. Then you worry about preventing spam, since that's a problem that only affects the person who receives the e-mail. And, keep in mind, you should never put the burden on the user to prevent spam. Only just started with PHP and didn't even know what sanatization was until this thread. But now i see exactly why its needed. This form doesn't write to a database, although i may do it in the future and just make it store as a simple page that i can check instead of receiving emails. Either way, im all for learning and getting into good habits! The reason i use the email address isn't to stop spam as such, but its so that i can contact the user afterwards. I shall get my thinking cap on!
March 5, 201214 yr Only just started with PHP and didn't even know what sanatization was until this thread. But now i see exactly why its needed. This form doesn't write to a database, although i may do it in the future and just make it store as a simple page that i can check instead of receiving emails. Either way, im all for learning and getting into good habits! The reason i use the email address isn't to stop spam as such, but its so that i can contact the user afterwards. I shall get my thinking cap on! No worries, just make sure you get those two things down. People always forget validation, and there is nothing more frustrating than trying to fill out a form only to get an error without any idea what's wrong or how to resolve it.
March 5, 201214 yr Author No worries, just make sure you get those two things down. People always forget validation, and there is nothing more frustrating than trying to fill out a form only to get an error without any idea what's wrong or how to resolve it. we have all been there a few times before. So in terms of validation, im looking for ideally... - Check if forms are empty. - Check for @ sign in email. Then sanatize illegal chars etc within the fields. And finally make it only allowed once over a certain time. Or possible 3 a day. Think i have my learning schedule for tomorrow worked out!
March 5, 201214 yr But then I could just input something like this "ajnjana@kanan.naa" and that'll validate as a real email. I don't think there is any real way around this. Regex for "Something @ something dot something" is usually the way it is (roughly). No way of really checking whether that email really exists. Well, there might be, but I can imagine it'd be quite intrusive and maybe not that reliable. Fact is, if someone wants to manually spam you, there's not really much you can do about it, apart from making it as frustrating as possible for them.
March 5, 201214 yr Regex for "Something @ something dot something" is usually the way it is (roughly). No way of really checking whether that email really exists. Well, there might be, but I can imagine it'd be quite intrusive and maybe not that reliable. You can look up the mx record with getmxrr() - that'll confirm the domain. To confirm the address itself: handshake, identify and send "rcpt to: ajnjana@kanan.naa" to the MX server's Telnet port. Response 250 indicates valid address, 550 and it doesn't exist. All hinges on how important your email address data is. Probably wise to exclude the major free webmail providers though, as it's a spam signal. Edited March 5, 201214 yr by Renaissance-Design
March 6, 201214 yr Author That doesn't matter It's possible to inject headers into an email. For example, I could inject additional emails into the message to spam to as many emails as I wanted. This could bring your mail server down and worse case scenario, get your server blacklisted. Christ, so much malicious stuff out there! Well, i have just started working on the new suggestions method now. Have sorted writing to the database / reading from it. Am now making sure i can truncate it with a button. Then ill start sorting out all the validation and santization. Am rather enjoying PHP actually. HTML and CSS is all good and fun, but with php you really get the feeling your 'creating' .
March 6, 201214 yr You can look up the mx record with getmxrr()... Dude, how do you know SO MUCH and still have time to post here o_O
March 6, 201214 yr Author Right, need a bit of direction... Bare with me! If searched across the web but struggling to find what i need. So, this is my basic code for writing to the database: <?php $con = mysql_connect("localhost","username","password"); if (!$con) { die('Could not connect: ' . mysql_error()); } mysql_select_db("dbname", $con); $sql="INSERT INTO suggestions (Suggestion, Email) VALUES ('$_POST[suggestion]','$_POST[Email]')"; if (!mysql_query($sql,$con)) { die('Error: ' . mysql_error()); } echo "Suggestion Added!"; mysql_close($con) ?> Right, so what i now want to do. Is if either field is blank, or contains illegal chars etc, then do not post to database but im just a bit confused with how things work. So heres my attempt (if statements written in plain english) <?php $con = mysql_connect("localhost","username","password"); if (!$con) { die('Could not connect: ' . mysql_error()); } mysql_select_db("dbname", $con); //IF STATEMENTS HERE TO VALIDATE AND SANATIZE THE INPUT... $sql="INSERT INTO suggestions (Suggestion, Email) VALUES ('$_POST[suggestion]','$_POST[Email]')"; if (!mysql_query($sql,$con)) { die('Error: ' . mysql_error()); } echo "Suggestion Added!"; mysql_close($con) ?> Is that the correct place where i have commented? there i put the if statements? Just not sure how i return the insert to database true / false etc.
March 6, 201214 yr Dude, how do you know SO MUCH and still have time to post here o_O I was looking up DNS functions recently for another project.
March 6, 201214 yr Probably wise to exclude the major free webmail providers though, as it's a spam signal. Yeah that's the reason I figured it may be unreliable. However, I guess according to your method, you could write something to say check if it's a major supplier like yahoo or gmail or whatever, then if it isn't then look it up. So - validate the format of the email address. Let it through if it's gmail, yahoo, hotmail, or any of the major suppliers, and if it isn't then use your method to establish whether it really exists. I guess that would filter some stuff out, although spamming using the major supplier names would still kind of be possible. So if someone's going to enter "gjghfk@dksifn.com" it wouldn't get let through. However "gdfhfdjfh@yahoo.com" would.
March 6, 201214 yr Also Lovelock - perhaps you might want to look into using PDO? It might come in useful in making it easier to write securely and sanitise stuff...
Create an account or sign in to comment