in reply to newb: Best way to protect CGI from non-form invocation?
A quick and dirty trick is to add a text field (not a hidden field) named subject to your form. Hide this field from your users using CSS (input[name="subject"] { display: none; }). Most spam bots will fill that field. If that field is set, assume the form was submitted by a bot.
This trick can be used in conjunction with other methods for defense in depth.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: newb: Best way to protect CGI from non-form invocation?
by chromatic (Archbishop) on Feb 05, 2007 at 22:10 UTC | |
by ikegami (Patriarch) on Feb 05, 2007 at 22:30 UTC | |
by JCHallgren (Sexton) on Feb 05, 2007 at 22:32 UTC | |
by chromatic (Archbishop) on Feb 06, 2007 at 02:54 UTC | |
by eric256 (Parson) on Feb 05, 2007 at 22:45 UTC |