"Cpt. Zeep" <zeep@nemame.com> wrote in message
news:btbbrl$i89$2@bagan.srce.hr...[color=blue]
> I'm writing small script for sending mail from my web pages. I have heard
> about security hole in FormMail.pl script which can be used by spammers. I
> would like to prevent that in my script. Can you give me some suggestions
> regarding that.
> Thanx!
>
> --
> Relaxen und watch das blinkenlights...
>[/color]
number one thing, DONT PUT THE RECIPIENT ADDRESS IN THE FORM!
sorry, didn't mean to yell, I have hated marks script since day 1, to big,
to insecure, to complicated.
(and mark, if your reading this, why not put the recipient in the
formmail.pl script with the other freaking things you made everyone
configure?)
sending mail via a script is so freakin easy, but everyone tries to make it
look hard, then they try to wrap it up in some class file, and thats even
harder to use than writing one yourself.
Ok, I know I am venting, I havent vented in a while.
I have two snippets for sending mail if you need them (see my site below)
to keep spammers or others from using your form, hard code the recipient
email address in the script, not the form that the user fills out.
thats about it, thanx for letting me vent, it felt good.
--
Mike Bradley
http://www.gzentools.com -- free online php tools