View Single Post

  #6 (permalink)  
Old 11-17-2005
Tauno Voipio
 
Posts: n/a
Default Re: mailform hacking

Andy Jacobs wrote:
> In article <KSMef.434$dW1.301@read3.inet.fi>,
> Tauno Voipio <tauno.voipio@INVALIDiki.fi> wrote:
>>
>>Does any of the publicly accessible pages have links to
>>the form?

>
>
> Not links, but it is called from a contact page as the action on a form.
> That's got me thinking though. If I rename the form to something
> obscure, they'll still find it as it will still have to be called. But
> what if I call it using - for want of a better phrase - the numerical
> values? So form2mail.php becomes:
>
> f&#x6f;&#x72;&#x6d;2&#x6d;a&#x69;&#x6c;&#x2e;p&#x6 8;&#x
> 70;
>
> Could this work?


The bots are probably running a de-obfuscator, so they understand
all valid URL/URI forms.

--

Tauno Voipio
tauno voipio (at) iki fi
Reply With Quote