Welcome Guest, Not a member yet? Register   Sign In
Help With Contact Form Abuse - a Trivial solution
#3

Honeypots can be a good way to discover bad actors and ban the IPs.

What I was seeing was auto entry of the contact form without going through the website proper. This prevents that. I also have a small number of content rules and denature user input to prevent the form from sending messages which, when viewed, auto download malicious software. Contact form responses are never saved to prevent them from being a vector into my databases. Routing is decided at the program level based on the context within which the form was requested and not indicated in hidden form fields.
Reply


Messages In This Thread
RE: Help With Contact Form Abuse - a Trivial solution - by clancey - 10-28-2020, 03:35 AM



Theme © iAndrew 2016 - Forum software by © MyBB