Full Version: Job Offer
From: Cody (BOBTNAILER) [#9]
30 Jan 2007
To: Boz (CHEDDARHEAD) [#8] 30 Jan 2007
A little off the beaten path, but maybe along the same lines....
I've gotten several submissions from our "contact us" web page from this address: baufaufru@mispir.org.
Every one of his submissions has had some sort of html reference to prescription meds.
I used to just get the normal spam from these guys, but now they're actually using my fill-in-the-blanks form to get my own website to send me spam! :/
From: Harvey only (HARVEY-ONLY) [#10]
30 Jan 2007
To: Cody (BOBTNAILER) [#9] 30 Jan 2007
And I am still amazed that people actually respond to those drug ads. They are such obvious spam.
Maybe I should offer a course in how to become an expert engraver in less than ten days.
They send me $100 and I send them a link to EE.
From: Jer (DIAMOND) [#11]
30 Jan 2007
To: Harvey only (HARVEY-ONLY) [#10] 30 Jan 2007
From: Jim (RETAIL74) [#12]
30 Jan 2007
To: ALL
From: UncleSteve [#13]
30 Jan 2007
To: Jim (RETAIL74) [#12] 30 Jan 2007
From: Dave Jones (DAVERJ) [#14]
30 Jan 2007
To: Cody (BOBTNAILER) [#9] 31 Jan 2007
From: Stunt Engraver (DGL) [#15]
30 Jan 2007
To: Dave Jones (DAVERJ) [#14] 30 Jan 2007
What would be the cure for that, if indeed, that's what the spammers are doing?
Another script?
From: Dave Jones (DAVERJ) [#16]
30 Jan 2007
To: Stunt Engraver (DGL) [#15] 30 Jan 2007
I don't know if his has the potential spam problem or not, but for ones that do, yes a different script is the answer.
The problem comes from generic scripts that pass the recipient email address from the web page. The more secure scripts have the recipient email address hard coded into them in a part of the script that can not be reached from the web. FormMail was a popular CGI script that is supplied by a lot of web hosts as a simple way to have a contact form. Similar scripts in other languages abound and work in similar ways, with similar vulnerabilities.
A custom PHP script with the address hard coded is typically the most secure. The next best thing is this PHP script that a friend of mine wrote, with a bit of advice from me, called "NateMail": http://www.mindpalette.com/formprocessing/index.php
It has a hidden list of recipient email addresses stored on the server and forms can only be sent one of the names you enter in that list. The list can not be accessed or overridden from the web.