You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

已部署Securimage验证码仍遭垃圾邮件攻击,如何解决?

联系表单验证码失效与垃圾邮件问题分析

去年我为某机构搭建了一个网站,其中包含一个基于PHP实现、集成Securimage验证码的联系表单。近日查看存储联系消息的数据库表时,发现其中充斥垃圾邮件:垃圾邮件始于2022年8月(联系表单上线约1个月后),在8-9月达到峰值,日均11条;目前每1-2天1条,远未达到验证码应有的防护效果,且从近期日志看并非暴力攻击。

联系表单渲染代码

<form method="post" action="contact">
    <div class="tabForm">
    <?php
        renderInlineField('name', 'Your name:');
        renderInlineField('email', 'Email address:');
        renderInlineField('subject', 'Subject:');
    ?>
        <p><?php renderLabel('message', 'Message:'); ?> <textarea style="width: 100%; height: 15em;" name="message" id="message"><?php echo htmlspecialchars($message); ?></textarea></p>
        <p><img id="captcha" src="securimage/securimage_show.php" alt="[CAPTCHA Image]" /></p>
        <p><audio id="captcha_one_audio" preload="none" controls="controls">
            <source id="captcha_one_source_wav" src="securimage/securimage_play.php?id=<?php echo uniqid(); ?>" type="audio/wav" />
        </audio></p>
        <p><?php renderLabel('captcha', 'Please enter the characters you see/hear:'); ?> <input type="text" name="captcha" id="captcha" size="10" maxlength="6" /></p>
        <p><input type="submit" value="Submit" /></p>
    </div>
</form>

辅助函数定义

function renderInlineField($fieldName, $htmlLabel) {
    global $errors;
    echo "<p class='inline'>";
    renderLabel($fieldName, $htmlLabel);
    echo "<input type='text' name='$fieldName' id='$fieldName' maxlength='255' value='", htmlspecialchars(@$_POST[$fieldName]), "' /></p>";
}

function renderLabel($fieldName, $htmlLabel) {
    global $errors;
    echo "<label for='$fieldName'>";
    if (!empty($errors[$fieldName])) echo "<span class='error'>($errors[$fieldName])</span> ";
    echo "$htmlLabel</label>";
}

验证码验证代码

if ($_SERVER['REQUEST_METHOD'] == 'POST') {
    $name = sanitise($_POST['name']);
    $email = trim($_POST['email']);
    $subject = sanitise($_POST['subject']);
    $message = trim($_POST['message']);
    $captcha = $_POST['captcha'];
    
    $errors = [];
    
    session_start();
    require_once 'securimage/securimage.php';
    $securimage = new Securimage();

    if (empty($name)) $errors['name'] = 'missing';
    
    if (empty($email)) {
        $errors['email'] = 'missing';
    } else if (!filter_var($email, FILTER_VALIDATE_EMAIL)) {
        $errors['email'] = 'not valid';
    }
    if (empty($message)) $errors['message'] = 'missing';
    
    if (empty($captcha)) {
        $errors['captcha'] = 'missing';
    } else if (!$securimage->check($captcha)) {
        $errors['captcha'] = 'not entered correctly';
    }
    
    if (empty($errors)) {
        // code to store the message in the database and email it to the intended recipient
    }
}

提问

  1. 这段代码是否存在垃圾邮件机器人可利用的漏洞?
  2. 有哪些可行的解决方案?

内容的提问来源于stack exchange,提问作者Stewart

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 10:53:19