Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PHP Formmail secure?

Status
Not open for further replies.

LTeeple

Programmer
Aug 21, 2002
362
CA
Hi all,
We suspect that our formmail cgi script was hijacked on our server, and am now looking into more secure options.

Would the PHP experts out there say that PHP mail functions can be safer?

Thanks for the tips.

[cheers]
Cheers!
Laura
 
You must keep in mind that it was not perl's email-sending features, used by formmail, which are not necessarily insecure. It is the formmail script itself which is insecure.

A PHP script with equivalent functionality could be just as insecure, but it all depends on how the script is written. If the author of the script is sufficiently paranoid about hostile user input, a PHP formmail-equivalent script could be, but is not necessarily, secure.


Want the best answers? Ask the best questions!

TANSTAAFL!!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top