Inactive
- Join Date:
- Jan 2006
- Posts:
- 228
- Plugin Contributions:
- 0
Quick question about the contact form
I just had a quick general question about the contact form. I've searched, but I can't find a straightforward answer on this.
I've created my own contact form that works very well agains injection attacks, but the person I'm doing this site for wants to use the one that comes with ZenCart. That's fine with me - but my question is this:
Does the standard contact from come with the proper input checks? Like stripping the "/r/n" tags and looking for other methods of injection? I just implemented the contact form on the site I'm working on, and I tried to inject it with my own spam (and sent it to myself!) and the emil sent.
Now, the good thing is that it hasn't arrived to any of my inboxes - not the one set for the form, nor any of the ones I entered into the fields. So I like that it looks like it's sent, but it really doesn't go through. But then again, I'm not usually a spammer by trade, so I don't know how effective my method for testing is.
So I was wondering if my initial assumption here is correct - that the standard contact form does come with such protection, and checks all user input for injection attempts? From what I'm seeing - it does, but I just wanted to be absolutely sure.
Thanks!