Overview


The e-mail injection is a security vulnerability that allows malicious users to send e-mail messages using someone else's server without prior authorization. These messages are usually spam and may cause problems to the owner of the server the spammer used.

To prevent your server (or your hosting account) from being used for spam without your knowledge, you must be sure your forms are not vulnerable to mail injection.

On this site we discuss about the e-mail injection on the mail() function of php. When a form is made to use the php mail() as the mailer, some details must be checked.

The spammers may exploit the MIME format to include additional data to the message that is being sent. This data may be a new recipient list, a new message or anything the malicious user wants to.

If the malicious user can exploit your script, his spam will be sent with your server IP - even if the spammer spoofs the sender's e-mail address. So, if you have your own server or even an simple shared hosting account, the e-mail injection may affect you.

Now you know what the e-mail injection is, you may also want to know the details on how it works. Click here.

Latest News >>
Unplugging The World's Biggest Spam Host-- Temporarily (Linux Today)
"The volume of junk e-mail sent worldwide dropped drastically today after a Web hosting firm identified by the computer security community as a major host of organizations allegedy engaged in spam activity was taken offline, according to security firms that monitor spam distribution online.

Webroot E-Mail Security SaaS Enhancements Deliver Cost-Effective Solution for Improving Security and Manageability (Business Wire via Yahoo! Finance)
BOULDER, Colo.----Webroot, a leading security provider for the consumer, enterprise and SMB markets, today announced significant enhancements to Webroot® E-Mail Security SaaS that provides better protection from the latest email threats, supports the effective enforcement of usage policies, and eases the management of critical email communications.

ColdSpark Integrates Commtouch Messaging Security Suite into Mail Platform for Large Enterprises (Business Wire via Yahoo! Finance)
SUNNYVALE, Calif. & BROOMFIELD, Colo.----ColdSpark and Commtouch® today announced that ColdSpark will be offering Commtouch messaging security services based on Recurrent Pattern Detection™ and GlobalView™ Reputation technology with its SparkEngine™ Mail Transfer Platform.




About us Portuguese version