Re: Spammer on Bugs page
| From: | Wez Furlong | Date: | Tue, 20 Jul 2004 19:17:04 +0000 |
| Subject: | Re: Spammer on Bugs page | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-11388@lists.php.net to get a copy of this message | ||
I know this is just a quick measure, but isn't the whole idea to not
emit the code in plain text on the form? It's really very easy to
scrape it out.
--Wez.
On Tue, 20 Jul 2004 14:32:44 -0400, Daniel Convissor
<danielc@analysisandsolutions.com> wrote:
> It's pretty crude. All it does is set a session var with a segment of the
> microtime then asks the user to confirm that number. So, if a bot tries
> to submit directly via POST, the value won't be set, so they get rejected.