已部署Securimage验证码仍遭垃圾邮件攻击,如何解决?
联系表单验证码失效与垃圾邮件问题分析
去年我为某机构搭建了一个网站,其中包含一个基于PHP实现、集成Securimage验证码的联系表单。近日查看存储联系消息的数据库表时,发现其中充斥垃圾邮件:垃圾邮件始于2022年8月(联系表单上线约1个月后),在8-9月达到峰值,日均11条;目前每1-2天1条,远未达到验证码应有的防护效果,且从近期日志看并非暴力攻击。
联系表单渲染代码
<form method="post" action="contact"> <div class="tabForm"> <?php renderInlineField('name', 'Your name:'); renderInlineField('email', 'Email address:'); renderInlineField('subject', 'Subject:'); ?> <p><?php renderLabel('message', 'Message:'); ?> <textarea style="width: 100%; height: 15em;" name="message" id="message"><?php echo htmlspecialchars($message); ?></textarea></p> <p><img id="captcha" src="securimage/securimage_show.php" alt="[CAPTCHA Image]" /></p> <p><audio id="captcha_one_audio" preload="none" controls="controls"> <source id="captcha_one_source_wav" src="securimage/securimage_play.php?id=<?php echo uniqid(); ?>" type="audio/wav" /> </audio></p> <p><?php renderLabel('captcha', 'Please enter the characters you see/hear:'); ?> <input type="text" name="captcha" id="captcha" size="10" maxlength="6" /></p> <p><input type="submit" value="Submit" /></p> </div> </form>
辅助函数定义
function renderInlineField($fieldName, $htmlLabel) { global $errors; echo "<p class='inline'>"; renderLabel($fieldName, $htmlLabel); echo "<input type='text' name='$fieldName' id='$fieldName' maxlength='255' value='", htmlspecialchars(@$_POST[$fieldName]), "' /></p>"; } function renderLabel($fieldName, $htmlLabel) { global $errors; echo "<label for='$fieldName'>"; if (!empty($errors[$fieldName])) echo "<span class='error'>($errors[$fieldName])</span> "; echo "$htmlLabel</label>"; }
验证码验证代码
if ($_SERVER['REQUEST_METHOD'] == 'POST') { $name = sanitise($_POST['name']); $email = trim($_POST['email']); $subject = sanitise($_POST['subject']); $message = trim($_POST['message']); $captcha = $_POST['captcha']; $errors = []; session_start(); require_once 'securimage/securimage.php'; $securimage = new Securimage(); if (empty($name)) $errors['name'] = 'missing'; if (empty($email)) { $errors['email'] = 'missing'; } else if (!filter_var($email, FILTER_VALIDATE_EMAIL)) { $errors['email'] = 'not valid'; } if (empty($message)) $errors['message'] = 'missing'; if (empty($captcha)) { $errors['captcha'] = 'missing'; } else if (!$securimage->check($captcha)) { $errors['captcha'] = 'not entered correctly'; } if (empty($errors)) { // code to store the message in the database and email it to the intended recipient } }
提问
- 这段代码是否存在垃圾邮件机器人可利用的漏洞?
- 有哪些可行的解决方案?
内容的提问来源于stack exchange,提问作者Stewart
相关产品推荐
相关产品推荐

