PHP Secure E-mails
There is a vulnerability in the PHP e-mail script from the previous section.
PHP E-mail Injection
First, look at the PHP code from the previous chapter:
<html>
<head>
<meta charset="utf-8">
<title>Example(example.com)</title>
</head>
<body>
<?php
if (isset($_REQUEST['email'])) { // 如果接收到邮箱参数则发送邮件
// 发送邮件
$email = $_REQUEST['email'] ;
$subject = $_REQUEST['subject'] ;
$message = $_REQUEST['message'] ;
mail("someone@example.com", $subject,
$message, "From:" . $email);
echo "邮件发送成功";
} else { // 如果没有邮箱参数则显示表单
echo "<form method='post' action='mailform.php'>
Email: <input name='email' type='text'><br>
Subject: <input name='subject' type='text'><br>
Message:<br>
<textarea name='message' rows='15' cols='40'>
</textarea><br>
<input type='submit'>
</form>";
}
?>
</body>
</html>
The problem with the above code is that unauthorized users can insert data into the email headers through the input form.
What would happen if a user adds the following text to the email in the input fields of the form?
someone@example.com%0ACc:person2@example.com %0ABcc:person3@example.com,person3@example.com, anotherperson4@example.com,person5@example.com %0ABTo:person6@example.com
As usual, the mail() function places the above text into the email headers, so now the headers have additional Cc:, Bcc:, and To: fields. When the user clicks the submit button, this e-mail will be sent to all the addresses above!
PHP Preventing E-mail Injection
The best way to prevent e-mail injection is to validate the input.
The following code is similar to that in the previous chapter, except that we have added an input validation routine that checks the email field in the form:
<html>
<head>
<meta charset="utf-8">
<title>Example(example.com)</title>
</head>
<body>
<?php
function spamcheck($field)
{
// filter_var() 过滤 e-mail
// 使用 FILTER_SANITIZE_EMAIL
$field=filter_var($field, FILTER_SANITIZE_EMAIL);
//filter_var() 过滤 e-mail
// 使用 FILTER_VALIDATE_EMAIL
if(filter_var($field, FILTER_VALIDATE_EMAIL))
{
return TRUE;
}
else
{
return FALSE;
}
}
if (isset($_REQUEST['email']))
{
// 如果接收到邮箱参数则发送邮件
// 判断邮箱是否合法
$mailcheck = spamcheck($_REQUEST['email']);
if ($mailcheck==FALSE)
{
echo "非法输入";
}
else
{
// 发送邮件
$email = $_REQUEST['email'] ;
$subject = $_REQUEST['subject'] ;
$message = $_REQUEST['message'] ;
mail("someone@example.com", "Subject: $subject",
$message, "From: $email" );
echo "Thank you for using our mail form";
}
}
else
{
// 如果没有邮箱参数则显示表单
echo "<form method='post' action='mailform.php'>
Email: <input name='email' type='text'><br>
Subject: <input name='subject' type='text'><br>
Message:<br>
<textarea name='message' rows='15' cols='40'>
</textarea><br>
<input type='submit'>
</form>";
}
?>
</body>
</html>
In the code above, we used PHP filters to validate the input:
- The FILTER_SANITIZE_EMAIL filter removes illegal characters of an email from the string.
- The FILTER_VALIDATE_EMAIL filter validates the value of an email address.
You can in ourPHP Filterread more about filters.