Re: Trackback SPAM
| From: | Helgi Þormar | Date: | Sat, 28 Jan 2006 14:54:08 +0000 |
| Subject: | Re: Trackback SPAM | ||
| References: | 1 2 3 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-41118@lists.php.net to get a copy of this message | ||
On Fri, 27 Jan 2006 09:42:12 +0100, Sebastian Nohn wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> David Coallier wrote:
>
>> 1. We could write a bayes algorithm[1] class that would check the
>> trackback and refuse them if they seem too suspicious, which could make
>> some certain trackback refused but most would, I believe, be correctly
>> filtered.
>>
>> 2. check if stristr pear and the package name. Sounds a bit hardcore
>> but that would stop, I'd stay what.. 50-60% of the attacks.
>
> Or make use of Net_DNSBL_SURBL and block all known supicious sites. And
> maybe even make use of Net_DNSBL and block all known open HTTP proxies.
As far as I know we us at least one of those, maybe even both, I can't
remember but Toby knows since he wrote that part into pearweb. He used
Services_Trackback which has spam checks using Wordlist, Regex, DNSBL,
SURBL
If you look at these files you see he added some site to his blacklist
array and then uses Wordlist,DNSBL and SURBL to detect spam >:/
http://cvs.php.net/viewcvs.cgi/pearweb/include/Damblan/Trackback.php?view=markup&rev=1.12
http://cvs.php.net/viewcvs.cgi/pearweb/public_html/trackback/trackback.php?view=markup&rev=1.15
So I guess one of those are just failing to detect those spams ?
Anyway, I'm not bashing anyone, just pointing out how things work in
pearweb in regards to the trackbacks :)
Regards
Helgi