|
Malicious code content detected.
Your IP Number of ".getenv("REMOTE_ADDR")." has been logged."; // Colour/Style Values for your page - hexy! //Background Colour $bgcolor = "#99ff99"; //Table Border $bocolor = "#99ff99"; // Font Colour $fcolor = "#ffff33"; // Link Colour $lcolor = "#ff0000"; // Font Style $font = "verdana"; // Font Size $fontsize = "4"; /******** END OF CONFIG SECTION *******/ $fname = $HTTP_POST_VARS['fname']; $lname = $HTTP_POST_VARS['lname']; $email = $HTTP_POST_VARS['email']; $message = $HTTP_POST_VARS['message']; $headers = "From: $email\n"; $headers . "MIME-Version: 1.0\n" . "Content-Transfer-Encoding: 7bit\n" . "Content-type: text/html; charset = \"iso-8859-1\";\n\n"; if ($SpamCheck == "Y") { // Check for Website URL's in the form input boxes as if we block website URLs from the form, // then this will stop the spammers wastignt ime sending emails if (preg_match("/http/i", "$fname")) {echo "$SpamErrorMessage"; exit();} if (preg_match("/http/i", "$lname")) {echo "$SpamErrorMessage"; exit();} if (preg_match("/http/i", "$email")) {echo "$SpamErrorMessage"; exit();} if (preg_match("/http/i", "$message")) {echo "$SpamErrorMessage"; exit();} // Patterm match search to strip out the invalid charcaters, this prevents the mail injection spammer $pattern = '/(;|\||`|>|<|&|^|"|'."\n|\r|'".'|{|}|[|]|\)|\()/i'; // build the pattern match string $fname = preg_replace($pattern, "", $fname); $lname = preg_replace($pattern, "", $lname); $email = preg_replace($pattern, "", $email); $message = preg_replace($pattern, "", $message); // Check for the injected headers from the spammer attempt // This will replace the injection attempt text with the string you have set in the above config section $find = array("/bcc\:/i","/Content\-Type\:/i","/cc\:/i","/to\:/i"); $email = preg_replace($find, "$SpamReplaceText", $email); $fname = preg_replace($find, "$SpamReplaceText", $fname); $lname = preg_replace($find, "$SpamReplaceText", $lname); $message = preg_replace($find, "$SpamReplaceText", $message); // Check to see if the fields contain any content we want to ban if(stristr($fname, $SpamReplaceText) !== FALSE) {echo "$SpamErrorMessage"; exit();} if(stristr($lname, $SpamReplaceText) !== FALSE) {echo "$SpamErrorMessage"; exit();} if(stristr($message, $SpamReplaceText) !== FALSE) {echo "$SpamErrorMessage"; exit();} // Do a check on the send email and subject text if(stristr($sendto, $SpamReplaceText) !== FALSE) {echo "$SpamErrorMessage"; exit();} if(stristr($subject, $SpamReplaceText) !== FALSE) {echo "$SpamErrorMessage"; exit();} } // Build the email body text $emailcontent = " ----------------------------------------------------------------------------- WEBSITE CONTACT ENQUIRY ----------------------------------------------------------------------------- Name: $fname $lname Email: $email Message: $message _______________________________________ End of Email "; // Check the email address enmtered matches the standard email address format if (!eregi("^[A-Z0-9._%-]+@[A-Z0-9._%-]+\.[A-Z]{2,6}$", $email)) { echo " It appears you entered an invalid email address "; } elseif (!trim($fname)) { echo "Please go back and enter a First Name "; } elseif (!trim($lname)) { echo "Please go back and enter a Last Name "; } elseif (!trim($message)) { echo "Please go back and type a Message "; } elseif (!trim($email)) { echo "Please go back and enter an Email "; } // Sends out the email or will output the error message elseif (mail($sendto, $subject, $emailcontent, $headers)) { echo "Thank You $fname $lname
|