We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 6681
    • 14 Posts
    Hi guys,

    I have used the E-form snippet on a site and somebody is sending odd stuff through and I was wondering if this is any kind of hack they are trying to do.

    the e-mail they submit is always bogus and in the comments section the submit 2 or 3 urls.
    the form data is simply sent to a clients e-mail address so it is annoying for them if nothing else.

    Has anybody else experienced this or have any idea what these people are trying to achieve?

    Thanks for any help on this.
      • 28042 ☆ A M B ☆
      • 24,524 Posts
      I get this from time to time, although adding a "hidden" field that must not be filled in has pretty much put a stop to it. It’s automated scripts, usually, which is why the empty hidden field defeats them, as they will fill all fields. But as long as you pay attention and sanitize all input from the forms it can’t do more than annoy. It might be useful to add a function to process the comment field before mailing, and modify any URLs so they don’t show up in the mail client as clickable links.
        Studying MODX in the desert - http://sottwell.com
        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
        Join the Slack Community - http://modx.org
        • 6681
        • 14 Posts
        Cheers for that.

        I think I know how to add a hidden field in to the form itself but how do i tell the form handler to check this and make sure its empty?

        I.E: the required field is a Boolean either 0 or 1 i think but how does e-form know that it should be blank?

        Hope this question makes sense.

        thanks again for your help.
          • 28042 ☆ A M B ☆
          • 24,524 Posts
          I have two custom snippet/functions for my contact form, so my snippet call looks like this:
          [!getServer!]
          [!checkField!]
          [!eForm? &formid=`ContactForm` &tpl=`ContactForm` &report=`ContactReport` &to=`[email protected]` &subject=`sottwell.com Contact` &thankyou=`ThankYou` &from=`[+email+]` &fromname=`[+name+]` &replyto=`email` &eformOnBeforeMailSent=`getServer` &eformOnValidate=`checkField`!]

          The checkField snippet looks like this:
          <?php
          function checkField(&$fields,&$vMsg,&$rMsg) {
              if(!empty($fields['Last__Name'])) {
                  return false;
              } else {
              return true;
              }
          }
          ?>

          The bogus field is moved off the screen in the CSS file:
          #contactArea #LastName{position:absolute;text-decoration:underline;background-color:#CC0000;left:0px;top:-500px;width:1px;height:1px;overflow:hidden;}

          You can see the form if you view source on my site (http://sottwell.com); even though I’m using a silly jQuery popup for my contact form, I haven’t implemented the AJAX version yet so you can see the form in the source.

          I have a sneaking suspicion that I should be able to use eForm’s custom validation in the form field’s eform attribute to check that it’s empty, but I really hate regular expressions.
            Studying MODX in the desert - http://sottwell.com
            Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
            Join the Slack Community - http://modx.org