Submit Your Article Forum Rules

Page 5 of 5 FirstFirst ... 345
Results 41 to 44 of 44

Thread: HELP! PHP Form being exploited

  1. #41
    Member
    Join Date
    Nov 2006
    Posts
    64

    Re: HELP! PHP Form being exploited

    I see.. Sorry about that... The form is still very exposed to other exploits other than this problem...
    Web Designer and Custom Spider Creator
    eCommerce and shopping cart information

  2. #42
    WebProWorld MVP deepsand's Avatar
    Join Date
    May 2004
    Location
    State College, PA
    Posts
    16,443

    Re: HELP! PHP Form being exploited

    Quote Originally Posted by shannonlp View Post
    I see.. Sorry about that... The form is still very exposed to other exploits other than this problem...

    The originator of this thread seems to be satisfied with the host's statement that there is no problem with the script.

    You might consider sending a private message to Deb, so as to make sure that it comes to her attention, by using the link at http://www.webproworld.com/web-progr...xploited.html# , detailing your findings.

    Just because her present problem is not owing to such vulnerabilty, does not mean that such will never be the case.

  3. #43
    Junior Member cPages's Avatar
    Join Date
    Aug 2007
    Posts
    2

    Re: HELP! PHP Form being exploited

    Deb,

    A couple of things we can recommend without giving away too many tricks.

    You can add The Official CAPTCHA Siteimage verification and it will help a bit, per the other posts.

    You should ensure your host has mod_security enabled with BCC and other form attack rules in their list.

    You should set bounced email to fail [in case you have a default email address setup, change it to fail]. Ask your host if they are "verifying existance of mail senders". this is recommended.

    Rename your form to something other than "contact" or "form" and more importantly rename your processing script to something completely different. [We believe bots are actually looking for words "form" etc].

    Even if you are not experiencing these attacks from your form, what ever is causing these issues should be addressed with your web host in more depth. They can review logs to see why/how this is happenening and should be able to offer the best advice depending on what security scripts and policies they have in place.

    Regards.

  4. #44
    WebProWorld MVP ctabuk's Avatar
    Join Date
    Jul 2003
    Posts
    3,925

    Re: HELP! PHP Form being exploited

    cPages - Desist from posting please - I know what you are attempting and I have removed your sig.

Page 5 of 5 FirstFirst ... 345

Similar Threads

  1. Good Form and Form to Email Script
    By Burty in forum Graphics & Design Discussion Forum
    Replies: 9
    Last Post: 03-13-2009, 07:40 PM
  2. IE7 Exploited by Hackers
    By crankydave in forum Internet Security Discussion Forum
    Replies: 4
    Last Post: 12-23-2008, 01:06 PM
  3. Passing form data to remote form on another site
    By webace in forum Graphics & Design Discussion Forum
    Replies: 8
    Last Post: 08-31-2007, 03:21 AM
  4. Form Post Redirect to Form Get
    By GiftsForYouBiz in forum Web Programming Discussion Forum
    Replies: 0
    Last Post: 09-26-2006, 04:51 PM
  5. Form problems using Visual Form Mail
    By whatever in forum Graphics & Design Discussion Forum
    Replies: 7
    Last Post: 01-04-2006, 03:14 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •