Re: [PHP] if http_referer is not reliable then how do we ...

2012-01-19 Thread Alex Nikitin
Capchas can't hold off any decently smart robots, anyone doing their research can find at least 3 tools that will defeat various capchas. For example pwntcha is one, Dan Kaminsky did a talk at black hat and defcon 16 on pwning audio capchas (and a lot of even good ones will offer audio as an

Re: [PHP] if http_referer is not reliable then how do we ...

2012-01-19 Thread tamouse mailing lists
On Tue, Jan 17, 2012 at 2:34 AM, ma...@behnke.biz ma...@behnke.biz wrote: You should not write the recipients email address in a hidden form, but instead read it from a config file. This way you can make sure, that no one alters it. Although this won't stop anyone from using the mailform.

Re: [PHP] if http_referer is not reliable then how do we ...

2012-01-17 Thread ma...@behnke.biz
Haluk Karamete halukkaram...@gmail.com hat am 17. Januar 2012 um 04:51 geschrieben: Let' say we have a form mailer script, which takes any form ( whose action is directed to it ) and goes thru the submitting form's fields list ( programmatically) , to build a nice email on the fly and email