I know postmark has a credit system, and when you run low they email you. The rates are low enough that it would take a huge volume to cost you.
I've never thought of that attack vector before.
not allow cross site form filling (using CSRF Cross site request forgery protection) would probably help a lot in that regard. And sleep 2. Your users can wait a couple seconds.
I've never thought of that attack vector before.
not allow cross site form filling (using CSRF Cross site request forgery protection) would probably help a lot in that regard. And sleep 2. Your users can wait a couple seconds.