Results 1 to 10 of 10
  1. #1
    Join Date
    Jul 2007
    Posts
    10
    Plugin Contributions
    0

    Default Spam in email forms

    All of a sudden, our site is being innundated with spam mails through our "request quote" page.

    Is there any way we can stop this from happening?

  2. #2
    Join Date
    Dec 2005
    Location
    colorado
    Posts
    108
    Plugin Contributions
    0

    Default Re: Spam in email forms

    I am starting to get some of them also.

  3. #3
    Join Date
    Jun 2005
    Location
    Cumbria, UK
    Posts
    10,266
    Plugin Contributions
    3

    Default Re: Spam in email forms

    Try using a CAPTCHA feature (see the downloads).

    Make sure you do not put your e-mail address into the html/php code anywhere on your site.
    20 years a Zencart User

  4. #4
    Join Date
    Jan 2004
    Posts
    66,444
    Plugin Contributions
    279

    Default Re: Spam in email forms

    The contact-us page built-in to Zen Cart is designed to not allow people to submit inquiries unless they're logged in to an account. This at least deters a majority of spambots.

    You might try customizing your request-quote page to operate similarly.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  5. #5
    Join Date
    Dec 2005
    Location
    colorado
    Posts
    108
    Plugin Contributions
    0

    Default Re: Spam in email forms

    thanks guys. working on installing a Captcha now.

  6. #6
    Join Date
    Nov 2005
    Posts
    13
    Plugin Contributions
    0

    Default Re: Spam in email forms

    I tested the contact us form and am able to send an email without logging in as a customer. Can someone point to me if there is a place in admin where this option is turned on/off. Or please point me to the code that prevents unauthorized emails -- perhaps I deleted it by mistake during customization.

    I am currently not having spam in the Contact Us page, but from the home page where I put in some links to forms for "suggest a product". Before I install Captcha, can someone tell me if this is specific to "Contact Us" or can be used anywhere on the site and for all contact forms.

    Thanks Much

  7. #7
    Join Date
    Jan 2004
    Posts
    66,444
    Plugin Contributions
    279

    Default Re: Spam in email forms

    Quote Originally Posted by DrByte View Post
    The contact-us page built-in to Zen Cart is designed to not allow people to submit inquiries unless they're logged in to an account. This at least deters a majority of spambots.

    You might try customizing your request-quote page to operate similarly.
    I must correct my prior statement.

    The Contact Us page does not restrict comments from being submitted by non-logged-in-customers.
    However, the Tell-A-Friend page/form *does* do this restriction if the switch is enabled in the admin area (and is enabled by default).
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  8. #8
    Join Date
    Dec 2003
    Location
    UPstate NY
    Posts
    440
    Plugin Contributions
    0

    help question Re: Spam in email forms

    Two questions:

    1) Which of the four (4) captcha options in the downloads section is the most easily installed??

    2) Doesn't ZC have any form validation included in the contact and other forms?? If not, how does one include form validation??

    Thank you, Tom

  9. #9
    Join Date
    Oct 2006
    Location
    Alberta, Canada
    Posts
    4,571
    Plugin Contributions
    1

    Default Re: Spam in email forms

    1) It's a good question to ask about various Captcha scripts and which one works best, with Zen Cart or otherwise. I'm not familiar with the Cpatcha mods for Zen Cart but testing must be done with any Captcha script; many are easily circumvented.

    2) The Spam problem mentioned in this thread is not a problem with validation but more so with field input / checking. Zen Cart allows for sending Admin eMails for example, to more than one address. Although this requires the use and availability of CC & BCC, the code for certain pages (Contact & Tell a Friend) could be rewritten to not include those eMail features.

    OR

    Go with a Hoster that has Spam prevention of any Form already setup. Ask your Hoster if they provide that Service within their Firewall script.

    <comment>
    Speaking of which, tried to include code a Hoster could use within their Firewall but came up against either; the Firewall settings for the Server that hosts this Forum or protection within the vBullten script itself. One of them prevents the use of BCC code on a Forum Web page. Good to know.
    </comment>


    At one time it was quite the rage for Spammers to search the Web for Forms that allowed sending eMails using BCC but were insecure to the point where Spammers could use them to send their Spam. Spammers loved it. They are left blameless whilst the account Owner / Hoster takes the hit for sending Spam because it "did" come from their account / Server.

    Sounds like Spammers are still doing it.

  10. #10
    Join Date
    Dec 2003
    Location
    UPstate NY
    Posts
    440
    Plugin Contributions
    0

    Default Re: Spam in email forms

    Website Rob,

    Your comments are good ones, but ZC's form processing leaves something to be desired if the end users have to do the anti-spam work.

    At the very least, the built-in form validation could be: 1) no blank fields; 2) no HTML of any kind; 3) only valid characters (not worry about format, just prevent characters that would be invalid for a particular kind of field, such as no colons in an email, for example, or no semicolons in a name field.

    I will try to check if my hosting has any spam control; unfortunately their support has deteriorated in the past year, time will tell.

    Thank you, Tom

 

 

Similar Threads

  1. v139b Strange email spam
    By Yivo118 in forum General Questions
    Replies: 3
    Last Post: 29 Oct 2013, 03:34 AM
  2. Email Spam
    By supplyman in forum General Questions
    Replies: 2
    Last Post: 25 Jan 2010, 04:43 AM
  3. Creating Email Forms
    By ATC in forum Templates, Stylesheets, Page Layout
    Replies: 3
    Last Post: 16 Apr 2008, 08:43 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg