Check https:// for potential spam

This commit is contained in:
Helen Chong 2025-03-03 09:45:21 +08:00
parent 52b29f5a14
commit 5be90cee4d
3 changed files with 13 additions and 3 deletions

View File

@ -24,7 +24,11 @@ if ($_SERVER['REQUEST_METHOD'] == "POST") {
)
$points += 2;
if (strpos($_POST['comments'], "http://") !== false || strpos($_POST['comments'], "www.") !== false)
if (
strpos($_POST['comments'], "https://") !== false ||
strpos($_POST['comments'], "http://") !== false ||
strpos($_POST['comments'], "www.") !== false
)
$points += 2;
if (isset($_POST['nojs']))
$points += 1;

View File

@ -34,7 +34,10 @@ if (isset($_POST['submit'])) {
if (isBot() !== false)
$error_msg .= "No bots please! UA reported as: ".$_SERVER['HTTP_USER_AGENT'] . "\r\n";
if (substr_count($_POST['comments'], 'http://') > 1)
if (
substr_count($_POST['comments'], 'https://') > 1 ||
substr_count($_POST['comments'], 'http://') > 1
)
$error_msg .= "Too many URLs; we've assumed you're spam and 'lost' your application. Please try again without any extra URLs if you're a geniune person :)\r\n";
$exploits = "/(content-type|bcc:|cc:|document.cookie|onclick|onload|javascript|alert)/i";

View File

@ -40,7 +40,10 @@ if (isset($_POST['submit'])) {
if (isBot() !== false)
$error_msg .= "No bots please! UA reported as: ".$_SERVER['HTTP_USER_AGENT'] . "\r\n";
if (substr_count($_POST['comments'], 'http://') > 1)
if (
substr_count($_POST['comments'], 'https://') > 1 ||
substr_count($_POST['comments'], 'http://') > 1
)
$error_msg .= "Too many URLs; we've assumed you're spam and 'lost' your application. Please try again without any extra URLs if you're a geniune person :)\r\n";
$exploits = "/(content-type|bcc:|cc:|document.cookie|onclick|onload|javascript|alert)/i";