Menu

Header injection? Exploit...

Help
j1010
2007-12-25
2013-06-03
  • j1010

    j1010 - 2007-12-25

    Just found this info:
    "A newer and lesser known vulnerability is header injection, a cunning exploit whereby a spammer hijacks a website’s contact form and uses it to send bulk unsolicited email"

    Are we protected against this?

     
    • TNTEverett

      TNTEverett - 2007-12-26

      Not specifically.  First your form must allow header injection. If you are not allowing variables to populate any header fields then there is nothing to worry about.  If you allow header variables then you need to check to make sure the form's email is only sent to specific addresses and not unintended recipients as it would if the header was injected by some hacker of hacker script. 
      There is alot to know and I can not cover everything in this post.  The best thing to do is identify a specific type of abuse and implement some protection against it. 

       

Log in to post a comment.

Want the latest updates on software, tech news, and AI?
Get latest updates about software, tech news, and AI from SourceForge directly in your inbox once a month.