Re: Trackback SPAM

From: Date: Sat, 28 Jan 2006 14:54:08 +0000
Subject: Re: Trackback SPAM
References: 1 2 3  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-41118@lists.php.net to get a copy of this message
On Fri, 27 Jan 2006 09:42:12 +0100, Sebastian Nohn wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > David Coallier wrote: > >> 1. We could write a bayes algorithm[1] class that would check the >> trackback and refuse them if they seem too suspicious, which could make >> some certain trackback refused but most would, I believe, be correctly >> filtered. >> >> 2. check if stristr pear and the package name. Sounds a bit hardcore >> but that would stop, I'd stay what.. 50-60% of the attacks. > > Or make use of Net_DNSBL_SURBL and block all known supicious sites. And > maybe even make use of Net_DNSBL and block all known open HTTP proxies. As far as I know we us at least one of those, maybe even both, I can't remember but Toby knows since he wrote that part into pearweb. He used Services_Trackback which has spam checks using Wordlist, Regex, DNSBL, SURBL If you look at these files you see he added some site to his blacklist array and then uses Wordlist,DNSBL and SURBL to detect spam >:/ http://cvs.php.net/viewcvs.cgi/pearweb/include/Damblan/Trackback.php?view=markup&rev=1.12 http://cvs.php.net/viewcvs.cgi/pearweb/public_html/trackback/trackback.php?view=markup&rev=1.15 So I guess one of those are just failing to detect those spams ? Anyway, I'm not bashing anyone, just pointing out how things work in pearweb in regards to the trackbacks :) Regards Helgi

« previous php.pear.dev (#41118) next »