Preventing Webform Based Spam


Have you ever wondered why your email server is sending you a lot of ‘bounced’ email reports? This might be due to a Hacker attack called “spam injection” on web forms that are poorly written.

First they use “zombies” (PC’s that they have been able to take over) to scan the Internet for web pages containing forms.

Then they try to insert some special code into the fields of your form that will trick your server into sending the form email to a different address, an address that your server is fooled into thinking is specified in a “bcc” field.

To begin they will test your server to see if they can re-route the form to send email to a throwaway email address (usually an AOL address). Once they are successful, they start sending spam emails via YOUR webform. And when those emails bounce, they bounce back to YOUR email server!

Several tips on how to prevent webform spams:

1. Use Captchas.
(http://webdesign.about.com/od/forms/qt/protect-forms-from-spammers.htm)
A CAPTCHA is a visual image (usually of a series of characters) that are written in a strange font and are difficult to read. They are supposed to be impossible for a computer to read, but a human can read them. Then your readers read the text, fill in the correct letters, and their form is submitted.

2. Use CSS and Javascript to fool spam bots
(http://webdesign.about.com/od/forms/qt/protect-forms-from-spammers.htm)
Many of the spam bots don’t read JavaScript, or they don’t read it well, so you can encrypt an entire form in JavaScript and block the spam bots from seeing it. Your readers will only have a problem if they don’t have JavaScript turned on.

One way that I like to fool spammers is to add CSS to forms to hide certain fields. When the spam bot comes in and reads the HTML, their bot sees that form field and fills it in. Then when I get the results any entries that have that field are automatically deleted. To do this use the display: none; property on the field. Web browsers will leave that form field completely off the page, but spam bots will see it in the HTML and fill it in.

3. Environment Checks
(http://askmichel.icoder.com/2007/01/28/how-to-protect-a-contact-form-from-form-spam-bots/)
Every browser sends a HTTP_USER_AGENT value to a server. So a missing HTTP_USER_AGENT value almost always indicates a spammer bot.
The most of browsers (all modern browsers) send a HTTP_REFERER value, which would contain the submitted form URL. Whereas clever bots send this value, a missing HTTP_REFERER value could mean a bot submitting.
Note. There are several firewall and “security” products which block HTTP_REFERER by default. So, none of these people could send a message if you block posting without HTTP_REFERER.
You can use this PHP-code to do the Environment Checks:

 

4. Extra Form Fields
(http://askmichel.icoder.com/2007/01/28/how-to-protect-a-contact-form-from-form-spam-bots/)
Yet another way to avoid of spamming by bots is Extra Form-fields where people have to answer an intellectual question like “which day comes after tuesday?” or “spell the number 7 in lowercase letters”. You can take a look at such form at the blog of Kim K. Jonsson.

In order to do not bother people with extra questions, you can invert the Extra Form-fields tactics. Place a blind field with an attractive name into your form. Only bots could detect this fields and fill it out. For example:

Your Name:
Your Email:

Only bots would fill the “email” field, real people will enter emails into the “x” field.

Anders Brownworth suggests to make the Submit button as image and require realistic mouse coordinates with the form posting. Your form processor should then approve the coordinates with etalon. You can take a look at this way realized in the Anders blog.

Anvil Live Streaming

Visit live streaming http://live.anvil.ph/

The 48th Anvil Awards, the Anvil of many “firsts”

by Lou de Guzman, APR

On March 6, 2013, the 48th Anvil Awards will earn its place in the industry as the Anvil of many “firsts” as it honors the best in PR practice. An overwhelming support from industry players turned in almost 400 entries, breaking past records of the Anvil Awards.

For the first time this year, digital campaigns are recognized as a distinct category under PR Programs – on a sustained basis. Likewise, multimedia and digital tools are grouped in a single Multimedia category under PR Tools. The criteria for the Anvil’s highest honor, the Hall of Fame Award, are also now defined and established.

Another achievement of the 48th  Anvil Awards is having Vishnu Mohan, CEO of Havas Media, Asia Pacific, as the Chairman of the Board of Jurors, bringing in his expertise and experience in traditional and digital media, as well as sharing the benefits of a regional and perhaps global perspective in the judging process.

This year, there are 33 Jurors, and the composition of the Board of Jurors has expanded to include IT specialists, members of academe, social media experts, specifically for the newly recognized categories of digital campaigns, multimedia, and digital tools.

For the first time ever, the 48th Anvil Awards will go digital, live streaming through live.anvil.ph with delayed telecast at Kapuso GMA News TV.  The winners and guests can join the online conversations via Twitter #anvilawards.  The event is slated at 6pm at the Makati Shangrila Hotel.

Award sponsors include Globe Telecom, Pepsi Cola, PCSO, Certified Digital Marketer Program, Photo Live, eRadioPortal.com.  Media partners include GMA News TV, ABS CBN, Philippine Daily Inquirer, Manila Bulletin, Philippine Star, Business Mirror, and Business World.

The Anvil Awards is an annual recognition program of the Public Relations Society of the Philippines (PRSP) to recognize excellence in PR Programs and Tools.

Baguio’s Panagbenga 2013 Flower festival live stream!!

panagbenga2013

It’s time, once again, to dance on the streets of Baguio as the Panagbenga Festival officially opens on February 1! With a Grand Opening Parade from Panagbenga Park to Athletic Bowl, the first day of Panagbenga will set the festive mood as the month-long celebration starts!

Watch Baguio’s Panagbenga 2013 Flower festival live stream brought to you by Baguio City Government, Pixel hub and BNSHosting.

Visit this link: http://www.panagbengaflowerfestival.com/live/

 

 

APNIC Network Security Workshop BAGUIO, PHILIPPINES 20-22 Feb 2013

APNIC is pleased to announce that we will be conducting the following training course in BAGUIO, PHILIPPINES with the support of Bitstop Network Services and the University of Cordillera.

Course: Network Security Workshop (3 days)
Dates: FEB 20-22, 2013
Venue: University of the Cordilleras
3F-Main Building,
Gov. Pack Road
Baguio, PHILIPPINES

Contact: Nancy M. Flores
Dean, UC-CITCS
Tel: 442-3316 loc. 131
Email: nancy@uc-bcf.edu.ph

Fees: Pay onsite Early Bird
(cash only) (credit card)
———– ————-
APNIC Members PHP 5,200 AUD 96
Standard PHP 7,800 AUD 144
NOTES
—–
– Training course run from 0900h – 1700h local time
– Participants are advised to bring their own laptop computers for
hands-on lab exercises
– Lunch and refreshments will be provided
– Training certificate is provided upon successful completion of the
course
– Seats are limited and registration is on a “first come, first
served” basis
– Registration priority is given to APNIC Members
– Early Bird rates end on 20 January 2013

REGISTRATION NOW OPEN
———————
For registration and course information, please go to:

http://www.apnic.net/events/calendar/training/2013/netsec-20Feb13

You will receive a confirmation email shortly after completing your online registration.
CANCELLATION POLICY
——————–
Cancellations will incur a 10 per cent administration fee. Cancellations made less than five working days before the training event will not be eligible for a refund. If you cannot attend an event, you can nominate a substitute.

To read the full Training Event Cancellation Policy go to:

http://www.apnic.net/cancellation-policy

If you would like to receive upcoming training announcements, please subscribe to our mailing list:

http://mailman.apnic.net/mailman/listinfo/training-announce

From: Champika Wijayatunga
Training Manager

————————————————————————
APNIC Training training@apnic.net
Asia Pacific Network Information Centre (APNIC) Tel: +61-7-3858-3100
PO Box 3646 Fax: +61-7-3858-3199
6 Cordelia Street, South Brisbane,
QLD 4101 Australia http://www.apnic.net/training
————————————————————————

Establishment of the Association for Small-to-Medium Sized Call Centers in the Philippines:Philcall

We would like to reach out to the different ICT councils, so that, you can help forward this invitation to some of your members that we are trying to reach out to.

I hope you can even encourage them to at least participate with our first meeting in a long time. One of the executive officers of PhilCall is also the co-founder of the Pangasinan ICT chapter, Ronald Punzalan.

We would like to invite them to join a short 3~4 hour round table discussion that will be held in Rastro Tapas Bar and Restaurant in Burgos Circle, Bonifacio Global City, Taguig at 1pm on November 6, 2012.

The Philippine Call Center Alliance, Inc. (PhilCall) is an association for the Small-to-medium sized enterprise (SME), and, Filipino-owned call centers all over the country. These are for call centers with an operating seat capacity ranging from 10 to 1500 seats per company.

We are reactivating PhilCall since we need an organization that will represent our real needs to make our businesses grow and develop further. PhilCall’s primary objectives are to unify the contact center SME industry, representing the member’s individual and collective interests in policy making, standard setting, and, serving as a prime catalyst for industry development.

“From fred Chua:”

Summit Digital “Esquire Ball 2012”

Bitstop Network Service is proud to be part of the Summit Digital at live webcasting the Esquire Ball happening this October 2, 2012, 8pm at the Makati Shangri-La Hotel. Bitstop Network Service team headed by Jessie Najera. The video is coursed through eradioportal’s worldwide CDN network to bring the Esquire Ball live not only to the Philippines, but all over the world.

The webcast stream uses mulitple bitrate of 256 kbps and 512kbps to allow viewers with smaller DSL bandwidths to view the webcast. Here is the link to the webcast: http://eradioportal.com/index.php?p=7&type=2&sec=4&aid=128

BNSHosting Needs YOU

If you are looking for a challenging and rewarding career in data center operations in Dagupan City, Philippines, look no further! We are in need of *nix system administrators and LAMP interns (Linux, Apache, Mysql, PHP) that are willing to learn and be trained.

We have a great track record of training and developing our team members into extremely proficient data center engineers. Most of our ex staffers are now in teaching professions or in Data centers here and abroad.

Here is your chance to join a great team! Apply now. Email us at team[at]bnshosting.net