The easy Weblog and Wiki Software
[ start | index | login ]
start > comment-Spam-3

comment-Spam-3 commented Spam

Created by heabdogg. Last edited by heabdogg, 4 years and 88 days ago. Viewed 179 times. #5
[diff] [history] [edit] [rdf]
labels
attachments
Is there any way to do what you suggested (removing the referer) via configuration? The only way I was able to do it was to literally comment out the
<s:backLinks snip="${snip}" count="15"/ />
tag in /snip.jsp.

I too was having my server pounded by a bot who manipulated the referer header to point to what presumably are random porn links (all on xtgp.org).

I would see this as a huge security issue. Any chance this could become a bug/issue in jira?

Note: I was able to squelch this particular spammer two ways:
  1. I use Apache as a proxy to Tomcat5 (running snipsnap-war) and used mod_rewrite to redirect this stupid spammer's traffic back at himself. I followed the instructions on >>this tutorial. So far, so good.
  2. I modified /snip.jsp to replace the
    <s:backLinks snip="${snip}" count="15"//>
    tag with this:
    <%--<s:backLinks .../>--%>referer disabled
    which basically comments out the backLinks tag.

So annoying! What's worse is, right now this spammer doesn't really crawl ths site for sub-snips… he just hits /space/start. It will get particularly nasty when he updates his script to recursively hit all snips.

Hope my meager solution helps. I don't know what to suggest if you're not using Apache as a proxy.

-Scott

24 comments (by lee, WmLongman, fries, wpugh, caseyd, heabdogg, joris, omoikane, leo) | post comment

What is SnipSnap?
SnipSnap is a free and easy to install weblog and wiki tool written in Java.

SnipSnap download
Current version: 1.0b3-uttoxeter
Try our >>Web Start Demo!

Resources

5567 Users and 13713 Snips. Installed 6 years and 48 days ago

Logged in Users: (2)
… and 45 Guests.

snipsnap-changed for older changes.

< August 2008 >
SunMonTueWedThuFriSat
12
3456789
10111213141516
17181920212223
24252627282930
31

snipsnap
Listed on BlogShares
XHTML 1.0 validated
CSS validated
RSS 2.0 validated
RSS Feed

pico-powered

Powered by SnipSnap 1.0b3-uttoxeter
YourKit >>Java Profiler

Fraunhofer FIRST

snipsnap.org | Copyright 2000-2006 Fraunhofer FIRST