101sitehosting.com, we supply bannerless free web hosting, free email, free webmail, free site builder, free php scripts and free support for individuals and small business.
Home
Thursday, 28 August 2008
 
 
Translations
Translate This Website
Main Menu
Home
Hosting Tech
Installatron
TLD Overview
FAQs - Support
News
Useful Links
Reciprocal Links
Our Guarantee
About Us
New Webmail system
Free Web Design Software
Testimonials
Entrepreneurs Club
DirectAdmin Tutorials
Client Login
Email Address:
Password:
Click here to register with us
Live Help
A Note to Visitors Using Browser Pop-up Controls - 
If you are using browser pop-up controls or blockers, you might experience problems opening our live help chat window. To avoid problems, we recommend that you temporarily disable pop-up controls before you try to open a live chat window.
Bookmark Us
 
 
Reseller Deals
Reseller Accounts
Reseller Domains
Dedicated Server
Certified Registrar
LoadGraph
(2.8 %)
sem
Preventing hackers sending spam using my domain Print E-mail
I have been notified that hackers are sending spam using the php mail() function on my domain. 101sitehosting.com administrators tell me: "Your scripts should not be able to send unsolicited emails from third persons. For example one of the SPAM emails is send by your feedback form."

Any suggestions how to prevent my scripts from sending spam?

You should check if the form fields, used to input feedback data are well escaped. For example one can "inject" additional fields( e.g. CC:, BCC:) in your "From:" field. Also if you are acquiring email "To:" field from a form it can be easily used to send SPAM.

It is best to filter all user data, you include in your message using regular expressions.
Follow the instructions on the following link and note that all of the fields you include in your mail function are vulnerable.
Email Injection

 

The forms that you can install from installatron aren't secure enough to keep these dudes out. The only real way that is safe without a lot of custom coding is to remove all forms and simply create hyperlinks that will launch their favorite email program and pre-fill in the fields.
 
Links  work very well.
 
You can also stuff the subject and the initial content into the url as well.Copy this html into your contact page and remove the x from the xhref to make it work. I added the x to allow you to see the code without it actually working in this example page.

 
some examples of how to do this even better with SPAM blockers are as follows

 

< Prev   Next >
 
 
Top! Top!
Welcome to 101sitehosting.com. If you are visually impaired and would like to check the availability of a domain, make a purchase, or just have questions please call us at (800) 861-1888. You may also email us at sales@101sitehosting.com to request a website service callback.  We are currently in the process of implementing more accessibility for our visitors so feel free to check back in the near future. Thank you for your interest in our company.