Zen Cart Logo
Forums / General Questions / Spam sent through contact form

Spam sent through contact form

Locked

Views: 18,448

Results 21 to 28 of 28
This thread is locked. New replies are disabled.
11 Dec 2009, 8:56 PM
#21
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Spam sent through contact form

bizshop1:

Mine is definitely coming from the email function of PHPMailer, and I'm sure from the contact form since users are not logged in.
That is a perfectly legitimate email message, sent via your Contact Us page.
There's nothing rogue happening there other than someone entering garbage in the form.
bizshop1:

and I don't know if this is being used to send to others as well...
The only way someone could abuse the default contact-us form to send to other addresses would be if they hacked into your admin and changed the email address that your contact-us emails are sent to.
bizshop1:

people should not be able to post URLsI'm not sure I agree. Posting a URL isn't something that should be forbidden. A URL is just text like any other text.
What if you had a potential customer asking you how one of your products is better than a competitor's products, and gave you the URL to that website? Would you want to forbid them from contacting you then? Would you want their email deleted then? Would you want to tell them to go away because they're bad ... just because they were asking a legitimate question that had a URL in it?
bizshop1:

This should be fixed without the need for a captchaWhat's to fix? It's working just fine.
Most likely whoever did it was human, so captcha would be pointless anyway.
If you're really desperate about it, use the most efficient solution and add the FormArmor service to your site: http://www.zen-cart.com/index.php?main_page=infopages&pages_id=27#formarmor

16 Apr 2010, 2:18 AM
#22
shaztesting avatar

shaztesting

New Zenner

Join Date:
Jun 2009
Posts:
71
Plugin Contributions:
0

Re: Spam sent through contact form

We are experiencing a similar problem. Getting hit by a spam bot using the form to send us over 100 emails an hour, all with the following structure.

[url=http://spamdomain.com/]spamdomain[/url],
[link=http://spamdomain.com/]spamdomain[/link], [url]http://spamdomain.com/[/url]

DrByte:

What's to fix? It's working just fine.
In our case, legitimate enquiries are getting lost amongst thoasands of spam emails. Given that the spam is only coming into our inbox's, they have no way of knowing whether they are succesful or not. How would we best stop this?

incorporating somthing like this into the contus us form validation?

if (preg_match("/^(http(s?):\/\/|ftp:\/\/{1})((\w+\.){1,})\w{2,}$/i", $url)) {
echo "Don't accept this spam";
}
else {
echo "Accept this enquiry";
}

or perhaps

<?php

function isValidURL($url) {
    $pattern = "#^(http:\/\/|https:\/\/|www\.|//)*(([A-Z0-9][A-Z0-9_-]*)(\.[A-Z0-9][A-Z0-9_-]*)+)(:(\d{1,5}))?([A-Z0-9_-]|\.|\/|\?|\#|=|&|%)*$#i";
    if (!preg_match($pattern, $url)) {
        return false;
    } else {
        return true;
    }
}

if (isset($_POST['submit'])) {
        $_POST['url'] = stripslashes($_POST['url']);
        if (isValidURL($_POST['url'])) {
                echo '<div style="color:green;">' . $_POST['url'] . ' is NOT valid</div>';
        } else {
                echo '<div style="color:red;">' . $_POST['url'] . ' is valid</div>';
        }
}
?>
<html>
<body>
<form method="post">
<input type="text" name="url" value="<?=htmlspecialchars($_POST['url']) ?>">
<input type="submit" name="submit" value="submit">
</form>
</body>
</html>

or will it be simpler to look for "[url" inside the enquiry filed for the time being. Since the spammer doesn't know whether it works or not, he/she is unlikely to change thier message. How would we do this?

DrByte:

What if you had a potential customer asking you how one of your products is better than a competitor's products, and gave you the URL to that website?

I can validate by jquery on the frontend to warn legitamate customers that their URL isn't allowed. The spammer obviously won't be affected by any frontend validation.

Thanks in advance, any help would be greatly appreciated!

16 Apr 2010, 2:30 AM
#23
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Spam sent through contact form

shaztesting:

In our case, legitimate enquiries are getting lost amongst thoasands of spam emails. Given that the spam is only coming into our inbox's, they have no way of knowing whether they are succesful or not. How would we best stop this?
The very best most effective solution would be to use the FormArmor service I mentioned in my last post. It specifically deals with the very concerns you just stated.

20 Apr 2010, 2:41 PM
#24
hdg avatar

hdg

New Zenner

Join Date:
Jul 2006
Posts:
71
Plugin Contributions:
0

Re: Spam sent through contact form

We are getting this same problem on a very low traffic site. Someone is mass spamming the Tell a Friend form with spam. Hundreds of emails in minutes.

Something should be built in by default to stop this.

Time: Tue Apr 20 09:36:34 2010 -0400
Type: LOCALRELAY, Local Account - user
Count: 101 emails relayed
Blocked: No

Sample of the first 10 emails:

2010-04-20 09:24:58 1O4DRi-0006f2-2M <= [email protected] U=user P=local S=3062 id=[email protected] T="Your friend alexis has recommended this great product from ..."

20 Apr 2010, 3:04 PM
#25
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Spam sent through contact form

In v1.3.9 there is automatic throttling enabled to at least discourage abuse.

As mentioned previously, the FormArmor plugin is the most efficient way to completely curtail spam coming from your website.

22 Apr 2010, 2:55 PM
#26
hdg avatar

hdg

New Zenner

Join Date:
Jul 2006
Posts:
71
Plugin Contributions:
0

Re: Spam sent through contact form

I updated to 1.3.9 when you mentioned it. But it didn't help.

Time: Thu Apr 22 03:30:52 2010 -0400

Path: /home/user/public_html
Count: 101 emails sent

Sample of the first 10 emails:

2010-04-22 03:18:47 1O4qgR-0006bn-KG <= [email protected] U=user P=local S=3113 id=[email protected] T="Your friend alexis has recommended this great product from..."

I will look into FormArmor, but I think ZenCart really needs to step up and fix this by default without addons.

28 Apr 2010, 3:01 PM
#27
tlyczko avatar

tlyczko

Zen Follower

Join Date:
Dec 2003
Location:
UPstate NY
Posts:
398
Plugin Contributions:
1

Re: Spam sent through contact form

HDG:

I will look into FormArmor, but I think ZenCart really needs to step up and fix this by default without addons.

I agree with this comment -- at the very least ZC should provide or contain ways for people to do:

  1. server-side form validation
  2. filter out undesired text

Neither are super-hard for a good PHP programmer, the hard part is making them work within ZC such that most use cases are adequately addressed.

No downloadable mods/addons that I could find to do this.

Thank you, Tom

4 Oct 2011, 5:15 PM
#28
ecommercefree avatar

ecommercefree

New Zenner

Join Date:
Jul 2010
Posts:
38
Plugin Contributions:
0

Re: Spam sent through contact form

DrByte:

The very best most effective solution would be to use the FormArmor service I mentioned in my last post. It specifically deals with the very concerns you just stated.

$19 month is to expensive to pay per month for other country like malaysia bcoz the conversion rate is $1=RM3.2 Which nearly RM60 permonth..while hosting only RM60 per year