/    Sign up×
Community /Pin to ProfileBookmark

mail(); Security concern

I’m about to write some code to implement the “mail()” function.
However, I’ve heard some horror stories about hackers hijacking this function and using it for spam mail.

[code=php]
$recipient = $email;
$subject = “My Subject”;
$msg = “My Message”;
$mailheaders = “From: <[email protected]>”;
include(“include_mail.php”);

// mail($recipient, $subject, $msg, $mailheaders);
[/code]

[code=php]
//include_mail.php
mail($recipient, $subject, $msg, $mailheaders);
[/code]

This is the working code I’ve been using.
Is there any kind of extra security precautions that I should be aware of?

Thanks in advance
ano

to post a comment
PHP

2 Comments(s)

Copy linkTweet thisAlerts:
@NogDogSep 13.2007 — As you've hard-coded all the other values, the only possible weak spot would be the $recipient value. Assuming this comes from some external input, at a minimum you should probably validate that it contains no newlines or carriage returns, and throw an error if it does.
Copy linkTweet thisAlerts:
@anothenauthorSep 13.2007 — As you've hard-coded all the other values, the only possible weak spot would be the $recipient value. Assuming this comes from some external input, at a minimum you should probably validate that it contains no newlines or carriage returns, and throw an error if it does.[/QUOTE]


Thanks buddie
×

Success!

Help @anothen spread the word by sharing this article on Twitter...

Tweet This
Sign in
Forgot password?
Sign in with TwitchSign in with GithubCreate Account
about: ({
version: 0.1.9 BETA 5.21,
whats_new: community page,
up_next: more Davinci•003 tasks,
coming_soon: events calendar,
social: @webDeveloperHQ
});

legal: ({
terms: of use,
privacy: policy
});
changelog: (
version: 0.1.9,
notes: added community page

version: 0.1.8,
notes: added Davinci•003

version: 0.1.7,
notes: upvote answers to bounties

version: 0.1.6,
notes: article editor refresh
)...
recent_tips: (
tipper: @AriseFacilitySolutions09,
tipped: article
amount: 1000 SATS,

tipper: @Yussuf4331,
tipped: article
amount: 1000 SATS,

tipper: @darkwebsites540,
tipped: article
amount: 10 SATS,
)...