solipsistnation: (leet hole)
[personal profile] solipsistnation
Referer spammers can bite me. I just learned how to use mod_security. It's sort of like a very specific (and less arcane) mod_rewrite that can also scan POST variables and stuff like that.

Here are my keywords:

"(holdem|poker|mortgage|hold-em|casino|diet-pill|gamble|viagra|phentermine|pharmacy)"

...and I'm catching dozens per hour. Icky.

(Hey, [livejournal.com profile] zonereyrie, maybe I should do the webby tech blog thingy after all.)

(no subject)

Date: 2005-06-16 03:11 pm (UTC)
From: [identity profile] zonereyrie.livejournal.com
What are they posting these to, some blogs?

And yeah, I think you should. You bailed on dinner Sunday so I still haven't heard the story you were going to tell. ;-)

(no subject)

Date: 2005-06-16 03:14 pm (UTC)
From: [identity profile] amymarr.livejournal.com
No, forms on our site. Damn them.

(no subject)

Date: 2005-06-16 03:14 pm (UTC)
From: [identity profile] solipsistnation.livejournal.com
Well, people's blogs and guestbooks and, even more annoyingly, the IT feedback forms and Continuing Ed question and request forms. It looks like it's coming from some kind of macro engine, too, probably in the form of something hidden in a web page or some kind of malware.

Now I just need to figure out how to make it so that this crap doesn't end up in the main logs at all... That would make the logs inaccurate, though, since this does end up being a hit on the web server.

(no subject)

Date: 2005-06-16 06:15 pm (UTC)
From: [identity profile] purly.livejournal.com
Actually, if you could keep two logs: one that shows accurate results and one that shows stripped results, then you would know which accounts were carrying the malware by comparing the two.

(no subject)

Date: 2005-06-16 06:17 pm (UTC)
From: [identity profile] purly.livejournal.com
(and once you know who's carrying it, you can examine their accounts and track it down)

(no subject)

Date: 2005-06-16 06:41 pm (UTC)
From: [identity profile] solipsistnation.livejournal.com
Unfortunately, it's not people coming _from_ here, it's random people out in the world hitting our site. Lots of students have blogs that allow comments, and some of those get heavily spammed. I found some interesting things looking through analog's search-term report a while ago and found a bunch of comment spam in a couple of student blogs there. I could then find the log entries for when the comments were posted and they were all off-campus.

(no subject)

Date: 2005-06-16 03:15 pm (UTC)
ext_137509: (Default)
From: [identity profile] usagijer.livejournal.com
you missed a tasty dinner. HouseO' was going heavy on the Spice. The Nose must Flow. I saw through time! the SCAdians at the next table were introducing some people to the joys of Indian food. they got a big surprise.

(no subject)

Date: 2005-06-16 05:23 pm (UTC)
From: [identity profile] jehanna.livejournal.com
Oh man, do I miss that place.

PA has no good Indian restaurants! Evil! At least we can get fantastic Thai and Chinese food here....

(no subject)

Date: 2005-06-16 09:51 pm (UTC)
From: [identity profile] stophittinyrslf.livejournal.com
PA has no good Indian restaurants!

that is totally true, at least as far as the south and east parts of the state go. prior to moving to worcester, i'd probably only seen one or two indian restaurants ever, and the one that i had eaten at was really, really bad. that worcester has indian restaurants all over the place and that many of them are actually good is a fact that amazes me to this day.

(no subject)

Date: 2005-06-16 04:30 pm (UTC)
From: [identity profile] prowler1971.livejournal.com
referrer spammers? Is this all the supposed referrers I see in my logs that don't actually have a link to my site?

(no subject)

Date: 2005-06-16 06:39 pm (UTC)
From: [identity profile] solipsistnation.livejournal.com
Yep. They're also often comment-spammers.

Here's a good writeup:

http://atomicplayboy.net/blog/2005/01/30/an-introduction-to-mod-security/

mod_security seeeems to be a little lighter-weight than mod_rewrite for this kind of specialized thing.

(no subject)

Date: 2005-06-17 02:25 am (UTC)
From: [identity profile] dariusk.livejournal.com
Yay mod_security! I read about this when I got hit with comment spam.

Profile

solipsistnation: page of cups (Default)
solipsistnation

October 2012

S M T W T F S
 123456
7 8910111213
14151617181920
21222324252627
28293031   

Style Credit

Expand Cut Tags

No cut tags