home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Webmastering and Programming
Ask a Tech Support Question (free)!

Spambot is attacking 'Contact Us' forms

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 2694
Discussions: 200,966, Posts: 2,379,635, Members: 246,332
Old May 18th, 2008, 01:47 PM   Digg it!   #1 (permalink)
Senior Member
 
evereddie's Avatar
 
Join Date: Feb 2004
Location: North Carolina
Posts: 603
Spambot is attacking 'Contact Us' forms

I have a "Contact Us" form on a clients site that has started getting hit with a spambot of some kind.

I have set up 'form checking' to require certain fields are filled in correctly (like zip code requiring a number of a certain length) and certain check boxes are checked before it will successfully submit the form. The form then works with a PHP script and sends the info to a list of e-mails. Somehow the Spambot is getting around the 'form checking' and submitting the form even though the required fields are not filled in properly. The actual PHP script is NOT being attacked because it has security features which I can tell is working. The Spambot is working directly with the 'form page'. How is the spambot getting around the form checking?

I might have to switch to a whole different kind of form and have used 'Quask' in the past and think that might help with this issue but would like to know how this can happen and if there are any fixes better than a complete re-do in another type of 'submit form' program.
evereddie is online now   Reply With Quote
Old May 20th, 2008, 07:46 PM     #2 (permalink)
Super F@D Folder
 
Join Date: Jun 2004
Posts: 5,083
Send a message via AIM to sr71000
It sounds to me like they're just submitting the information as opposed going and loading the form and filling it in and then submitting. They aren't using your webpage to submit the form, they just went and looked at what header info needs to be filled in for the script and are hitting your script over and over again. You used some sort of server side scripting to do it, right? (ex. javascript) I'd suggest a simple captcha script and/or require the form checking right at the beginning of your email script and die if the info is incorrect (or reload the form with the old info with a * next to the incorrect fields! Google for more info on captcha scripts

-Kevin

Last edited by sr71000 : May 20th, 2008 at 07:50 PM.
sr71000 is offline   Reply With Quote
Old May 21st, 2008, 03:02 AM     #3 (permalink)
Senior Member
 
evereddie's Avatar
 
Join Date: Feb 2004
Location: North Carolina
Posts: 603
Yes you were right sr71000 and it was because of an ooops on my part. I had accidentally put a copy of the php script for the form in the root directory. I had the active one in the 'cgi-bin' folder where it should be but somehow got a copy of it in the root. It was directly being attacked. It must have been there a while but spam-bot must have just found it. It is deleted and I will know almost immediately if the issues are gone.
Thanx
evereddie is online now   Reply With Quote
Old May 22nd, 2008, 11:05 PM     #4 (permalink)
Super F@D Folder
 
Join Date: Jun 2004
Posts: 5,083
Send a message via AIM to sr71000
good to hear that you found it. Let us know if that fixes it up!
sr71000 is offline   Reply With Quote
Old May 23rd, 2008, 12:23 AM     #5 (permalink)
Senior Member
 
evereddie's Avatar
 
Join Date: Feb 2004
Location: North Carolina
Posts: 603
A couple of days now and no more problems. I hate when I do dumb things like that. At least it's fixed.
Thanx again.
evereddie is online now   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
The Japs are attacking MPLS Cmptr-Gy-Dv IMO Community 14 June 10th, 2007 01:28 AM
Spambot Beware ablang Webmastering and Programming 0 July 7th, 2003 08:17 PM
annoying attacking hlaalu guards ghosty General Gaming Discussion 6 December 30th, 2002 06:14 AM
10/40 forms mdroth IMO Community 8 December 19th, 2002 08:41 PM
Need some help with forms ClubMed Webmastering and Programming 26 July 25th, 2002 04:31 AM


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (3012)
Forty-six years ago today (7)
Laptop with wireless problem. (12)
Wireless Televisions. (12)
CPU fan stops spinning randomly (11)
Regular Build (11)
Internet Lost (5)
windows 7 problem (7)
windows vista security holes (15)
Point and Shoot Camera Suggestions. (6)
Is the PSU I received dead? (13)
radeon x850xt platinum & shader.. (6)
HIS HD5770 graphic card question (15)
Install XP pro and a Vista laptop ?.. (11)
Recent Discussions
windows vista security holes (15)
Help getting around port 80 for camer.. (4)
Laptop with wireless problem. (12)
Open With ..... Win7 (2)
Internet Lost (5)
Skillsoft Network+ Study Software Que.. (9)
virus blocking exe. files (1)
Point and Shoot Camera Suggestions. (6)
CPU fan stops spinning randomly (11)
Nvidia GTX 260 problem (1)
Modern Warfare 2: Who Bought It? (65)
Is the PSU I received dead? (13)
Print spooler problem (16)
Kingston Bluetooth Dongle Driver (1)
Multiple Restarts Required at Boot (3)
webcam (0)
upgrade for hp a6101 (0)
tv not turn on-makes clicking sound (2)
EVGA 9800 gtx help with finding a goo.. (11)
Regular Build (11)
Help with onclick and buttons (0)
Virus advise (8)
My monitor won't turn on after instal.. (1)
Dept. of HS: NSA 'Helped' Develop Vis.. (16)
Ideal cheap graph card for PC-Gaming? (18)


All times are GMT -4. The time now is 02:41 PM.
TechIMO Copyright 2009 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28