We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 15001
    • 697 Posts
    Hi,

    One of my clients has a contact form processed by a PHP script.
    The script checks that the fields are not empty and sends an email.
    The form is on a static HTML page.

    My client receives strange emails like this one:

    > #################################
    > ##### REQUEST FROM WEBSITE #####
    > #################################
    > (skip)
    > City : lSHW SwOIYnHwknuXnaNkblf

    The page is static and in iso-8859-1, as specified in the header.
    <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" />

    However, the form itself does not have any valid charset specified,
    i.e. the "accept-charset" attribute is not set.

    The customers are local ones and should use either iso-8859-1 or utf-8.

    As we see the output generated by the script can be read but not the fields content.

    When I myself test the form, it is OK.

    I am suspecting some encoding problem(with UTF-8?) or a joke from robots.
    However, with a utf-8/iso-8859-1 issue, with words like "été", only the two "e acute" would be affected.

    I can hardly imagine some bad joke since the form has many fields that must be filled.
    Normaly Javascript checks the content type (alpha, numeric, alphanumeric,...) of each field and prevents the form to be sent if all is not OK.

    The strange emails also come with "dd mm yyyy" for a date.
    This is the initial content for date fields, but the form uses some Javascript code to check for numbers.

    Emails with "dd mm yyyy" as date content are only possible if JavaScript was disabled.

    Also, I observe that phone numbers replaced by random characters.

    One think is sure: the checking by Javascript is not done.

    Could this be due to robots filling the form randomly and sending it ?

    What should I do to find out where the problem comes from ?
    And how to solve it ?
    Are captcha codes always advised ?

    Many thanks in advance.

    J.
      • 28042 ☆ A M B ☆
      • 24,524 Posts
      I get those from time to time; I suspect it’s robots probing for weaknesses in form handling. I have a "dummy" field that must be left empty and is moved way off the side of the viewport with CSS, and if it’s not empty then the form just silently stops its processing. Since I added this (the bots will fill in empty text fields but often leave drop-downs, radio buttons and checkboxes unselected and fields with default content untouched) I haven’t gotten any of those.
        Studying MODX in the desert - http://sottwell.com
        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
        Join the Slack Community - http://modx.org
        • 16278
        • 928 Posts
        This input is almost certainly from some comment-spammer robot. They seem to have a go at any kind of input form. If you have your server logs, you can look for a POST entry at the time of the spurious form submission and check the IP of the submitter in http://www.projecthoneypot.org/home.php.

        I spend far too much time fuming over access logs at spamming attempts. >:( One thing that becomes clear very quickly is that the robots hardly ever use Javascript or read CSS files. I use that as a defence, by including a field full of spaces inside a NOSCRIPT tag, clearly labelled "LEAVE THIS FIELD EMPTY OR YOUR INPUT WILL BE DISCARDED". I keep the data that is submitted in a separate email to myself or log file in case it helps find more effective ways to keep these pests away (or in case my code mistakenly rejects a decent citizen). This is a similar approach to what Susan uses.

        In the short term, I add the IP of false submitters to a Deny From list in the .htaccess file.

        Unfortunately, you are unlikely to find an easy way to eliminate these unwanted visits. It’s more productive to concentrate on looking after the real visitors than to spend too much time on the scum who try to abuse your site.
        sad KP
          • 15001
          • 697 Posts
          Thanks for your interesting answers.

          The robot was capable of selecting an option other than the first one in a <select> drop list.

          Some urls were spammed in the "Ask your question" area but they there is no website at those urls. Names of the pointed websites sound also like random characters, excepted the an ending ".com".

          I don’t understand what the benefit for those spam robots.

          Do they try to get the email address contained in the PHP script?
          I really cannot figure myself would do they do.
            • 7155
            • 160 Posts
            Quote from: sottwell at Sep 03, 2009, 08:33 AM

            I get those from time to time; I suspect it’s robots probing for weaknesses in form handling. I have a "dummy" field that must be left empty and is moved way off the side of the viewport with CSS, and if it’s not empty then the form just silently stops its processing. Since I added this (the bots will fill in empty text fields but often leave drop-downs, radio buttons and checkboxes unselected and fields with default content untouched) I haven’t gotten any of those.
            clever! Will add that to my toolbox.

            I had a similar problem in my early days. I suspect the person used the form to send spam elsewhere. I was angered one day one I got an email from the supposed spammer/spam-bot author or user. He/she said "I know how to stop the spam emails you are getting." It was my own website, I simply removed the form. I didnt express how I would like to see fungi growing on his/her feet neither did I reply. It is NEVER advisable to aggrevate malicious users. Their level of skill could bring you and your clients’ websites down. But it just made me aware that there are "other people" out there with malicious intent.

            For free and open security info and advice:
            http://www.owasp.org/index.php/Main_Page