Canadian Mysteries

  • Front Page
  • Contact
  • Log in
  • « documentation for Franklin transcription and markup
  • internal email to virtual domain »

tighten security on teacher registration form

Posted by sarneil on 30 Jan 2013 in Activity log
MF reported a bunch of spam submissions through the "register for a teacher's password" form on http://canadianmysteries.ca/teachers/login/indexen.php There was a javascript function that was supposed to be invoked onSubmit, but from what I could see, the js file (jscripts.js) was not included, so the invocation obviously would fail, and that must be treated the same as returning true, because the action does happen successfully. I also noticed that there are two forms on the register page, and each of them had an email field. That became apparent when I successfully invoked the javascript check function and got an unexpected error. So I renamed/re-id'd the email field in the login form to loginEmail and made necessary modifications to js and php code that relies on that element's name or id. Finally, as a test I added a form element mathsum, into which the user would have to put the value of a simple math question posed on the form. I don't know if implementing that will do any good at all, but I'm not going go to proceed any further unless MF reports that the other modifications have not helped reduce the spam submissions
This entry was posted by Stewart and filed under Activity log.

Canadian Mysteries

The Canadian Mysteries site consists of a production site containing 12 mysteries, a containing shell and 30 mysteryquests; and a database-driven development site. HCMC took over tech support in summer 08. This blog documents work done on the site from Sept 08. Earlier work is documented in the depts blog in posts prepended with CanMys
  • Home
  • Recently
  • Archives
  • Categories
  • Latest comments

Search

Categories

  • All
  • Activity log
  • Announcements
  • Tasks

XML Feeds

  • RSS 2.0: Posts
  • Atom: Posts
More on RSS

Recent Posts

  • Added Sarah Taekema as new Mysteries Admin
  • fix urlencode problem on photo.php pages
  • Batch process images
  • moved learning materials pages
  • de-orphaning links pages on Franklin site
  • Request for teacher locations
  • fix broken links in mysteryquest
  • change backend database pointers
  • landing pages for parks canada
  • Franklin Google search styled

Sidebar 2

This is the "Sidebar 2" container. You can place any widget you like in here. In the evo toolbar at the top of this page, select "Customize", then "Blog Widgets".

This collection ©2022 by admin • Help • b2evolution