M
M
mitrofan234122021-02-16 16:03:27
Burglary protection
mitrofan23412, 2021-02-16 16:03:27

Trying to hack a site through a feedback form? what to do?

The site consists of a couple of pages in php (two landing pages), there is a feedback form, and hundreds of requests per minute from some bot arrive through this form. The query strings are something like this, there are a bunch of different ones:

<IMG SRC=javascript:alert('XSS')>

javascript:/*</script><svg/onload='+/"/+/onmouseover=1/+/[*/[]/+((new(Image)).src=([]+/\

%{(#[email protected]@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context['com.opensymphony.xwork2.ActionContext.container']).(#ognlUtil=#container


Regular shared hosting on php 5.6

How can you cut off such requests without setting captcha, and is it not a problem to bypass captcha now?
IP this spammer also changes constantly..

Answer the question

In order to leave comments, you need to log in

2 answer(s)
V
Vladimir Korotenko, 2021-02-16
@firedragon

Install clodfire. It will automatically add the captcha.

T
ThunderCat, 2021-02-16
@ThunderCat

fail2ban

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question