We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 25124
    • 54 Posts
    Hi,

    I have some spammers who put
    <a href=http://fhptzci.100webspace.net/nu.html>hdmi pci adapter </a>
    such as this in the eform, even though the form only comes to my customers office.

    The eform writes to a database and emails the results to my customer and sends a confirmation to the sender (this links are live / clickable)

    How can I escape out ( or whatever the term is) to prevent HTML being placed in the content.

    Any advice would be appreciated.
    smiley
      • 7231
      • 4,205 Posts
      &allowhtml (Optional)
      Set to 1 to allow user to enter html tags. Defaults to 0
      Add &allowhtml=`0` to your eForm call. I think this will not allow html in the post.
        [font=Verdana]Shane Sponagle | [wiki] Snippet Call Anatomy | MODx Developer Blog | [nettuts] Working With a Content Management Framework: MODx

        Something is happening here, but you don&#39;t know what it is.
        Do you, Mr. Jones? - [bob dylan]
        • 25124
        • 54 Posts
        Hi, thanks for the reply. I tried that but it makes no difference. huh
          • 7231
          • 4,205 Posts
          I think we have two options depending on how you want this to work:

          1) Use a custom validation function to not allow e-mail with html in it. I think that #REGEX can handle that but you can also use a custom function and trigger it on the validation event. This will prevent the messages from being sent.

          2) Run a function on the beforeMailSent event to strip the tags (using the strip_tags php function) so that the email is still sent but all links (and any other html tags) are removed.

          To learn more about events and filters take a look at the eForm docs in assets/snippets/eform/docs.

            [font=Verdana]Shane Sponagle | [wiki] Snippet Call Anatomy | MODx Developer Blog | [nettuts] Working With a Content Management Framework: MODx

            Something is happening here, but you don&#39;t know what it is.
            Do you, Mr. Jones? - [bob dylan]
            • 3749
            • 24,544 Posts
            Bear in mind that these solutions will also prevent legit users from sending links via the forms.  You could have a validation function that counts "http" instances in the message and limits it to a certain number.  Something like this code:

            $linkCount = substr_count($content,'http:');  // count links in content
            if ($linkCount > $maxLinks) { 
                  return false; 
            }

            Another approach would be to institute some spam proofing features. The people who are sending the links are almost certainly doing it with a spam-bot and could likely be stopped with spam proofing options without preventing legitimate links from getting through.
              Did I help you? Buy me a beer
              Get my Book: MODX:The Official Guide
              MODX info for everyone: http://bobsguides.com/modx.html
              My MODX Extras
              Bob's Guides is now hosted at A2 MODX Hosting
              • 25124
              • 54 Posts
              Thanks guys for your comments,

              What spam proofing options would work for me then? The eform is currently configured to write the info to a database, email the form filling person a confirmation email, send an email to HQ of the business and forwards the form filling person to a page where they can check that what they’ve submitted is correct (they can then click back and correct the details if incorrect). I would want something that was easy enough to implement without  breaking the existing functions. It took many, many hours to get it works correctly and I can’t risk breaking it.

              I also don’t want something too complicated as sometimes people ’don’t read’ and will give up.

              Is there a simple captcha that might work for this? or is this easily bypassed by the spammers.


              ....or how about a message (similar to the missing email address validation message that pops up) that says "Sorry, HTML code noted in the xxxxx field, please remove and re submit" ? Just thinking ...

              Thanks again, in advance

                • 25124
                • 54 Posts
                Quote from: BobRay at Feb 04, 2009, 11:45 AM

                Bear in mind that these solutions will also prevent legit users from sending links via the forms. You could have a validation function that counts "http" instances in the message and limits it to a certain number. Something like this code:

                $linkCount = substr_count($content,'http');  // count links in content
                if ($linkCount > $maxLinks) { 
                      return false; 
                }

                Another approach would be to institute some spam proofing features. The people who are sending the links are almost certainly doing it with a spam-bot and could likely be stopped with spam proofing options without preventing legitimate links from getting through.

                Sorry bobray, just saw your message.

                $linkCount = substr_count($content,'http');  // count links in content
                if ($linkCount > $maxLinks) { 
                      return false; 
                }


                How could I implement this into the eform script then? where does this code need to go?

                Thx
                  • 25124
                  • 54 Posts
                  Done it. Using the verification image captcha!

                  &vericode=`1` parameter to the snippet call eForm will replace the [+verimageurl+]


                  Let’s see how this works out.

                  Thanks again.
                    • 7231
                    • 4,205 Posts
                    Using the verification image captcha!
                    I thought you already had captchas turned on> I think that I am mixing up two similar posts. Don’t forget to personalize the captcha words in the site configuration section (if you want that is) wink
                      [font=Verdana]Shane Sponagle | [wiki] Snippet Call Anatomy | MODx Developer Blog | [nettuts] Working With a Content Management Framework: MODx

                      Something is happening here, but you don&#39;t know what it is.
                      Do you, Mr. Jones? - [bob dylan]
                      • 3749
                      • 24,544 Posts
                      Quote from: SammyR at Feb 04, 2009, 04:41 PM

                      Done it. Using the verification image captcha!

                      &vericode=`1` parameter to the snippet call eForm will replace the [+verimageurl+]


                      Let’s see how this works out.

                      Thanks again.

                      Some spambots can read and respond to Captcha images now, so if you’re still getting spam, you may want to integrate the "http" counter I mentioned above. I’m not an eForm expert, but I’m sure someone here can tell you how to use that as a custom validator in eForm.
                        Did I help you? Buy me a beer
                        Get my Book: MODX:The Official Guide
                        MODX info for everyone: http://bobsguides.com/modx.html
                        My MODX Extras
                        Bob's Guides is now hosted at A2 MODX Hosting