Forum Home
Press F1
 
Thread ID: 23991 2002-08-31 12:36:00 any php script kiddies out there?? comments needed sal (67) Press F1
Post ID Timestamp Content User
75374 2002-08-31 12:36:00 i have just placed an email forwarding page on my site

i know a little about php, but am still a bit iffy on the subject. could some one h\who knows a bit on the subject take a look over the coding and let me know if i have stuffed up the flow (it works alright) or made 'holes' inadvertenly

the page is here (sal.neopages.net)
the code is here (sal.neopages.net)

grtz sal.
nz
sal (67)
75375 2002-08-31 23:56:00 are you having problems with it, or does it seem to be working okay?

I've got a php script being used on one of my sites if you want to take a look at how that's set up...

investment.thinklab.co.nz ]Contact Page[/url] (the link will take you directly to the page with the script).

Mike.
Mike (15)
75376 2002-08-31 23:59:00 if you want I can post the actual scripts I use (if I can find them).

Mike.
Mike (15)
75377 2002-09-01 04:04:00 I send emails to/from anyone with that script (I just sent myself an email at work to test this). If the email is only supposed to be going to you then you should probably put it in your PHP, rather than having it as a form variable that the user can change.

Other than that it seems fine.
holloway (1694)
75378 2002-09-01 05:32:00 nah, i know it can be easily modified, by someone using the same script for them selves, but i got the script from an open source type of page, so i dont mind, just making it easier for visitors to email us, but other than that, where and how would i make it so the email address gets parsed?

grtz sal.
tga
sal (67)
75379 2002-09-01 05:34:00 oh, and yip, it does work, but m not sure how it exactly works (the from address i have no idea comes from where) anyone know how it works exactly?

grtz sal.
tga
sal (67)
75380 2002-09-01 07:10:00 It uses the mail function, www.php.net

The rest is standard PHP and HTML.
holloway (1694)
75381 2002-09-01 07:21:00 Change the line that contains "To: $toText <$toText>" into "To: artfx@ihug.co.nz <artfx@ihug.co.nz>" to tighten up the security. holloway (1694)
75382 2002-09-01 07:56:00 argh, silly me, thanks hollaway for pointing the obvious out to me, sometimes its just staring you in the face and....erk

grtz sal.
tga
sal (67)
75383 2002-09-01 09:43:00 you could also set the from field the same way so that it comes up with a understandable "from"... or you could put an email field in so that whoever sends you an email from the site can enter their email in and it'll include them as the from address.

Mike.

PS did that all make sense? :)
Mike (15)
1 2