Web2Lead Spam Solution
Wednesday, 25 April 2007 . by Randy Saunders
Are you attracting a lot of SPAM through your Salesforce.com Web2Lead form? If so, it seems you’re not alone. Of course any time you are running something as popular as Microsoft Windows or SalesForce.com, the evil-doers will try to invade.
Since there are so many Web2Lead forms easily accessible across the web, hackers write programs to search and harvest Salesforce.com account identifiers from these forms. And once they have that, they can begin pushing fictitious leads through the Salesforce.com interface which soon arrive as “open leads” in your system.
Here’s how blogger Rick Klau describes the issue:
“The exploit is simple: spammers scrape your lead intake form, capture your Salesforce.com OID number, and then use that to bypass your form and hit the Salesforce.com lead submission script directly. The result? Thousands upon thousands of bogus leads cluttering up our system”
Fortunately Rick offers a solution to this issue in his article “Salesforce spam: fixing web-to-lead.”

Posted in 



