Re: Re: [PEAR-DEV] Trackback SPAM

From: Date: Mon, 30 Jan 2006 14:30:20 +0000
Subject: Re: Re: [PEAR-DEV] Trackback SPAM
References: 1 2 3 4  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-41135@lists.php.net to get a copy of this message
Ok, I looked in pearweb in cvs and the one we are not doing is the Regex so, in http://cvs.php.net/viewcvs.cgi/pearweb/public_html/trackback/trackback.php?view=markup&rev=1.15 [code] // Check for possible spam $trackback->createSpamCheck('Wordlist'); $trackback->createSpamCheck('DNSBL'); $trackback->createSpamCheck('SURBL'); // Gotta add $trackback->createSpamCheck('Regex'); [/code] I found some lists of spam words that maybe we could do some kind of merge that we pass something like in: http://cvs.php.net/viewcvs.cgi/pear/Services_Trackback/Services/Trackback/SpamCheck/Regex.php?view=markup&rev=1.2 [code] $sql = "SELECT words FROM listofwords"; $words = $dbc->queryAll($sql); $list = implode('|', $words); Services_Trackback_SpamCheck_Regex::_options['sources'] = $list; //Allegations to give an idea ^^ [/code] which instead of being hardcoded would be a table with words that can easily be updated. And even a cron job running every week can update that table, that'd be pretty easy to maintain I believe. --David Helgi Þormar wrote:
On Fri, 27 Jan 2006 09:42:12 +0100, Sebastian Nohn wrote:
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 David Coallier wrote:
1. We could write a bayes algorithm[1] class that would check the trackback and refuse them if they seem too suspicious, which could make some certain trackback refused but most would, I believe, be correctly filtered. 2. check if stristr pear and the package name. Sounds a bit hardcore but that would stop, I'd stay what.. 50-60% of the attacks.
Or make use of Net_DNSBL_SURBL and block all known supicious sites. And maybe even make use of Net_DNSBL and block all known open HTTP proxies.
As far as I know we us at least one of those, maybe even both, I can't remember but Toby knows since he wrote that part into pearweb. He used Services_Trackback which has spam checks using Wordlist, Regex, DNSBL, SURBL If you look at these files you see he added some site to his blacklist array and then uses Wordlist,DNSBL and SURBL to detect spam >:/ http://cvs.php.net/viewcvs.cgi/pearweb/include/Damblan/Trackback.php?view=markup&rev=1.12 http://cvs.php.net/viewcvs.cgi/pearweb/public_html/trackback/trackback.php?view=markup&rev=1.15 So I guess one of those are just failing to detect those spams ? Anyway, I'm not bashing anyone, just pointing out how things work in pearweb in regards to the trackbacks :) Regards Helgi


« previous php.pear.dev (#41135) next »