HostNed.comHostNed Forums
Welcome, Guest. Please login or register.
Did you miss your activation email?
September 07, 2008, 04:46:33 AM
248 Posts in 90 Topics by 65 Members
Latest Member: apurvis
Home Help Search Login Register
HostNed Forums  |  WEB DESIGN  |  Scripting  |  Topic: web forms being hijacked by spammers 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Print
Author Topic: web forms being hijacked by spammers  (Read 2335 times)
twilitestudios
Newbie
*
Posts: 1


View Profile
web forms being hijacked by spammers
« on: April 20, 2006, 09:55:36 PM »

Please Help!!!!

I have lots of accounts here at hostned and one of them was suspended due to spam bots hijacking my form or script or however it works.
I have tried about 5 different php scripts, jmail, and some other supposedly "secure" scripts...
When I change the form script, it helps for a little while and then BAM!  it happens again.

Can someone please get me a SECURE script for my web forms or help me in finding one?
I can't afford to have my client's accounts shut down...
I have linux accounts as well as windows!

Cheers
Logged
Dynaweb
Yep
Administrator
Full Member
*****
Gender: Male
Posts: 107


HostNed Admin


View Profile WWW
Re: web forms being hijacked by spammers
« Reply #1 on: April 24, 2006, 09:17:06 AM »

This is a big concern lately.  Security on websites is very similar to other forms of security -- there are no absolutes.  The game is to stay ahead of the bad guys.  In order to do that you must identify your vulnerabilities and secure them.  I believe a big loophole lately is with Email Injection where a spammer inserts potentially thousands of BCC lines into the form via an external script.  If your web form does not prevent against this then you will need to modify it for sure.  Other common vulnerabilities include:
- Naming your web forms "formtoemail" or "mailform" or like that.  That is just inviting for spammers looking for a new exploitable.
- Leaving email addresses "out in the open" where spambots can easily scoop them up.
- Leaving "testing" versions of form-to-email scripts up by mistake.  While you have forgotten they are there, spammers use google to find and exploit them!
- Forgetting to exclude your contact-me pages from search engine listings using either robots.txt or meta tag exclusion methods.

HostNed has a web dev team so they can evaluate and secure your forms for you if it is something that is too technical for you to do yourself.
Logged
Dynaweb
Yep
Administrator
Full Member
*****
Gender: Male
Posts: 107


HostNed Admin


View Profile WWW
Re: web forms being hijacked by spammers
« Reply #2 on: September 20, 2006, 04:45:25 PM »

Our affiliate DynaWeb Designs has released their SFEPS Form to Email Script.  It is very secure and easy to set up.  Give it a try and let us know how you like it.
Logged
Pages: [1] Print 
HostNed Forums  |  WEB DESIGN  |  Scripting  |  Topic: web forms being hijacked by spammers « previous next »
Jump to: