Shariff Wrapper opens site to spammers: "?view=mail" always available
-
I deliberately did not activate the “mail” option but I do only use “mailto”. The reason is simply that with “mail” it is just a matter of time that all kinds of spammers will use the mail form to send out there Spam mails.
I had this already on another website and once the spammers get to know about this, then it only takes a few hours and peng: Suddenly, they send out thousands mails within a very quick time… And then your whole mail domain gets blacklisted by spam protection. Very bad, especially in my case where I use the mailing to send out mails to customers…
So, as I said, I disabled the “mail” option. BUT: The form is still there, the spammers just need to append “?view=mail” to the URL and then they can easily send out mail! Can you please make sure that the form and also the server side data handling part is really only activated when the “mail” option is set? With “server side data handling” I mean that it is not enough to hide the form, a client must not be able to sent data in order to perform an email (otherwise spammers could just sent out mail by using “curl”).
- The topic ‘Shariff Wrapper opens site to spammers: "?view=mail" always available’ is closed to new replies.