On 9/16/05, Les Mizzell <[EMAIL PROTECTED]> wrote:
> Thought you folks would like to actually *see* what comes through a form
> filled out by one of these bots. Note that there are only 6 form fields
> here: Name, Email, Phone, Fax, Address and Message. Check what got put
> into the "Address" field, which is the bulk of the message.

Here's a really thorough description of what the script is trying to
do and how to get around it - albeit from a php point of view. Easily
applied to CF tho.

http://securephp.damonkohler.com/index.php/Email_Injection

-- 
Kay Smoljak
http://kay.zombiecoder.com/

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~|
Logware (www.logware.us): a new and convenient web-based time tracking 
application. Start tracking and documenting hours spent on a project or with a 
client with Logware today. Try it for free with a 15 day trial account.
http://www.houseoffusion.com/banners/view.cfm?bannerid=67

Message: http://www.houseoffusion.com/lists.cfm/link=i:4:218488
Archives: http://www.houseoffusion.com/cf_lists/threads.cfm/4
Subscription: http://www.houseoffusion.com/lists.cfm/link=s:4
Unsubscribe: 
http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=11502.10531.4
Donations & Support: http://www.houseoffusion.com/tiny.cfm/54

Reply via email to