Reply
Exploit free mailform?
Old 06-30-2003, 10:00 AM Exploit free mailform?
Guerrilla's Avatar
Ultra Talker

Posts: 387
Hello,

Just in the process of changing mail forms from the bnb form (which i discovered has loads of exploits easily available on the net) to formmail.php

Just wondering really how secure this is as i have heard mention of formmail exploits and notice that even though i do not have formmail on my site i still clock about 20 access attempts for it a month.

Thanks again,

G
Guerrilla is offline
Reply With Quote
View Public Profile
 
When You Register, These Ads Go Away!
Old 07-03-2003, 11:06 PM
Experienced Talker

Posts: 31
Best suggestion I can make for you - no matter what formmail program you use - would be to rename the file to anything other than "formmail.xxx".

The thieves who would abuse your formmail seem to have automated programs running, searching for files by that specific name. If you change the name, it'll make your program much harder (if not totally impossible) to locate and abuse.

I'd also suggest not including the words "form" or "mail" anywhere in the new file name. Try "Henry" or "Esmeralda" or even "go-away-you-spamming-moron". Anything that they're not likely to run a search for should (hopefully) resolve the problem.

HTH!
Syren

Last edited by SyrenSong : 07-03-2003 at 11:08 PM.
SyrenSong is offline
Reply With Quote
View Public Profile
 
Reply     « Reply to Exploit free mailform?
 

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML

 


Page generated in 0.11795 seconds with 12 queries