944,174 Members | Top Members by Rank

Ad:
  • PHP Discussion Thread
  • Unsolved
  • Views: 1457
  • PHP RSS
Dec 17th, 2006
0

Abuse of a PHP contact script

Expand Post »
Hi -

I have had a message today from my hosting company to tell me that one of the sites on my hosting account is having it's php code abused. Apparently someone is manipulating the php code from the contact form to allow them
to add Bcc addresses.

Any ideas on what I need to do to close this loop hole?

Thanks.
Similar Threads
Reputation Points: 10
Solved Threads: 0
Newbie Poster
Znojmic is offline Offline
3 posts
since Dec 2006
Dec 19th, 2006
0

Re: Abuse of a PHP contact script

Post the content of the file, please. Enclose it in the [code] tags.
Reputation Points: 10
Solved Threads: 0
Newbie Poster
DennisP is offline Offline
23 posts
since Sep 2006
Dec 19th, 2006
0

Re: Abuse of a PHP contact script

First thing you need to do is disable the script that is being comprimised. I have dealt with this issue and you do not want to be blacklisted

The problem is that they inject line feeds and the code for the up and left arrow key to insert for example a bcc. Take a look here, to solve the line feed. http://www.gerd-riesselmann.net/arch...-contact-forms

The up arrow and stuff is a little bit harder to fix. I can't give out the code unfortunatly cause I did not write it.... But with some Googleling you could find something.

I hope you get your forms safe again.
Reputation Points: 10
Solved Threads: 0
Light Poster
remcov is offline Offline
33 posts
since Dec 2006

This thread is more than three months old

No one has posted to this discussion for at least three months. Please let old threads die and do not reply to them unless you feel you have something new and valuable to contribute that absolutely must be added to make the discussion complete. Otherwise, please start a new thread in this forum instead.
Message:
Previous Thread in PHP Forum Timeline: Loop Problem,plz help
Next Thread in PHP Forum Timeline: Who can make files open automatically with PHP?





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC