
What is the general concept behind XSS?

时间秒杀一切 提交于 2019-12-17 07:02:52
问题 Cross-site scripting (XSS) is a type of computer security vulnerability typically found in web applications which enable malicious attackers to inject client-side script into web pages viewed by other users. An exploited cross-site scripting vulnerability can be used by attackers to bypass access controls such as the same origin policy. Cross-site scripting carried out on websites were roughly 80% of all security vulnerabilities documented by Symantec as of 2007. Okay so does this mean that a

Hiding email from spambots without using javascript

纵饮孤独 提交于 2019-12-14 03:42:24
问题 I have a "contact us" form that uses Ajax (i.e. relies on asynchronous requests). In case the user has javascript disabled, I want to display a message, saying something like: You need to enable Javascript to use this contact form. If you can't, or don't know what Javascript is, then use your email and contact us at <the_email_address> . But of course, I want to hide the_email_address from spambots. Since this email address has to be displayed inside a <noscript> , it makes no sense to

Is it still worth obfuscating email-addresses to prevent harvesting?

故事扮演 提交于 2019-12-13 08:14:52
问题 I was wondering, is it really worth the trouble to implement email-obfuscation techniques in order to prevent emails from being harvested these days? My initial thought is no but i might be wrong. My (possibly inaccurate) arguments: spam filtering and detection is superior these days (when looking at my gmail spambox over 90% of all mail i receive is spam but none ends up in my inbox). Is it safe to assume the same for most other email services? most techniques aren't 100% proof against

Combat spambots by hiding email address (display: none)

此生再无相见时 提交于 2019-12-13 02:44:29
问题 Is it possible to prevent spambots from crawling all over my email address if I set it display: none ? I had an idea for a little minigame if you will, where the user clicks the link for the email and it then displays one or two "are you sure you're not a bot" sort of questions. Once these have been answered, it then displayed the real link. The issue is I'm assuming that bots can see the link because it's obviously there in the HTML even if it's not visible. Is there a way around this? Also,

Looking for a very simple spam-prevention class/function for ASP Classic

好久不见. 提交于 2019-12-13 00:17:15
问题 I am looking for a very simple solution to prevent (or reduce) form spamming. I've got quite a few ASP classic applications that contain contact us/miscellaneous forms here and there that generate emails. Few of them have been caught by spam bots and are being abused. I need very simple solution(s) to reduce spam if not eliminate it. Audio/Visual CAPTCHAs are out of question as visitors will end up spending more time solving captchas than to use the form itself. Session/timestamp/javascript

fighting spam bots

ぃ、小莉子 提交于 2019-12-12 11:15:14
问题 I have C# form in the site and want to prevent spam bots from filling it. The trick is, that I want to avoid CAPTHA or any other user input to avoid loosing a single registration. Here are some techniques I have in my mind: Hidden input field (question: is this still effective?) Track time, since the first user input (focus on FirstName) till posting a form.. Humans will take more than 3 seconds to complete a form (even with auto-fill), where bots take a second or less to fill in registration

Chat spam auto block for C# chat client

本小妞迷上赌 提交于 2019-12-12 05:38:17
问题 I'm really new to C#, so Currently I'm working on this LAN messenger, for use at school. Code for the messenger itself, including server and client I have found on the internet, so I haven't programmed all of it myself. The very basic code, as sending and recieving messages has been copied. Anyways! Im having problems with people spamming the chat. The client contains connecting options, as well as a multiline textbox for all incoming messages, a textbox for writing a message and a send

How to prevent spam on a form [duplicate]

只愿长相守 提交于 2019-12-12 01:25:57
问题 This question already has answers here : How to Prevent SPAM without CAPTCHAs or a Centrally managed system (e.g. akismet) (10 answers) Closed 6 years ago . I have a simple form that users use to register their email address for a newsletter. I want to prevent spammers submitting 000's of fake emails. What's the best way to do this? I thought about limiting the number of inputs from each IP address to, say, 60 per hour, but then thought anyone determined will simply spoof their IP as part of

How to Code phpMailer to prevent sending email if hidden field is filled in contact form

点点圈 提交于 2019-12-11 23:26:26
问题 I like phpMailer but when I used a previous mailer it had an anti spam code. You added a hidden field in the contact form and the mail.php script was coded that if the hidden field was filled in (i.e. only a spam robot would do that) the mail wouldnt send How would I add that to this script? This is my mail.php code as follows <?php // $email and $message are the data that is being // posted to this page from our html contact form $email = $_REQUEST['email'] ; $message = $_REQUEST['message']

Is this junk input, from a bot filling up a form on my website, safe?

醉酒当歌 提交于 2019-12-11 14:29:41
问题 So I use PHP and have a contact form on my website. Once users fill up the form and submit, it will shoot an email to me. I have been receiving junk input from bot, I assume, like below. This is the result of print_r($_REQUEST) . I removed some parameter for simplicity. Array ( [name] => rycpufrwq [email] => [company] => naCuklaLMab [website] => [message] => cBimwx <a href=\"\">pxlahgqmdrhs</a>, [url=