Z
Z
z0rgoyok2014-09-12 21:13:30
SMS
z0rgoyok, 2014-09-12 21:13:30

They drain the balance on the SMS gate (authorization in the mobile application), how to protect?

There is a script like client.php?action=get_code&phone=phone.
Someone thought of substituting numbers there and getting codes, so the balance decreases very quickly. How to protect?

Answer the question

In order to leave comments, you need to log in

2 answer(s)
D
Dmitry Skogorev, 2014-09-12
@z0rgoyok

captcha
tokens

S
Spin7ion, 2014-09-19
@Spin7ion

Try to remove the phone number from the session to begin with and not pass it in a get request if possible. Each device (you have a mobile application, as I understand it) has a unique id ( how to get it ), limit the frequency and number of SMS for each id.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question