Site news: No referrer, no comment
by Volker Weber
If your personal firewall* blocks referrers, you can no longer post comments to the site. This is another effort to block malicious bots:
RewriteCond %{REQUEST_FILENAME} mt-cmmnt.cgi [NC]
RewriteCond %{HTTP_REFERER} !^http://vowe\.net.*$ [NC]
RewriteRule (.*) - [F,L]
Comment spam bots call cgi without going through the site. For now they are coming in with a blank referrer. Using mod_rewrite it is rather simple to divert them with a 403 return code before they hit cgi, thus avoiding any unnecessary load on the server.
Maybe I will add another rule for those smartass people that send a long string of ++++ instead of a referrer.
*) Technically you are not using a firewall but rather a local proxy server that takes requests from your browser, processes them and then relays the request to the site. Symantec calls the stripping of referrers Browser-Datenschutz in german. No idea how they call this in english.
Comments
Hi Volker,
there have been bits and pieces of defense information published on your blog. Do you have a summary? Kind of problem/solution table?
:-) stw
I guess, that would probably be read by spam bot authors pretty soon and would be a comprehensive compendium on which countermeasures to by-pass to even access a well-protected blog. In order to be one step ahead, this might not be such a good idea.
I published a summary of anti-spam measures here (in German):
http://vnude.typepad.com/itfrontal/2004/12/spamschutz_in_w.html
I'm using this rule since two weeks, no more spam so far - but hundreds of HTTP 403s in my log file.
Since you have to allow the comment script's URL as a referrer (because of comment previewing), it will be easy for spambots to fake a correct referrer - they just have to insert the script address. Guess it won't take too long until "smart" spambots will exploit that weakness.
I guess in English it´s call privacy protection. :-)
I can live without previews. Personally, I find them annoying. I proof read in the edit form and I an error slips through, well, that's life.
We could enforce the referer rule by using a regex like
!^http://vowe\.net/([0-9]+)\.html$
to ensure only requests made from entry archives are accepted.
And to check for either an entry archive or the comment cgi, we could use this (untested, but should work after some testing ;) )
RewriteCond %{REQUEST_FILENAME} mt-cmmnt.cgi [NC]
RewriteCond %{HTTP_REFERER} !^http://vowe\.net/([0-9]+)\.html$ [OR]
RewriteCond %{HTTP_REFERER} !^http://vowe\.net/cgi-bin/mt-cmmnt\.cgi$ [NC]
RewriteRule (.*) - [F,L]
If not this way, mod_rewrite also provides chaining, which also could solve the problem.
Post a comment
Recent comments
Sascha Westphal
on How to Setup Your Own Web Proxy Server For Free with Google App Engine at 19:19
Moritz Schroeder
on The Single Sign On at 13:43
Nils Halvorsen
on How to Setup Your Own Web Proxy Server For Free with Google App Engine at 22:35
Mitch Cohen
on How to Setup Your Own Web Proxy Server For Free with Google App Engine at 22:12
Nick Daisley
on The Single Sign On at 20:54
Volker Weber
on The Single Sign On at 14:17
Tobias Hauser
on The Single Sign On at 13:12
Martin Böhm
on As if Palm needed more problems at 13:03
Ralf Stellmacher
on Zitat des Tages at 11:40
Philipp Sury
on The Single Sign On at 11:33
Jan-Piet Mens
on The Single Sign On at 10:48
Chris Frei
on The Single Sign On at 09:55
Volker Weber
on iPhone OS 3.1.3 brings back Internet Tethering to unlocked iPhones at 00:18
Steven Payne
on iPhone OS 3.1.3 brings back Internet Tethering to unlocked iPhones at 00:15
Robert Dahlem
on Zitat des Tages at 22:22
Volker Weber
on Steve Jobs at the 2010 Oscars at 22:21
Richard Kaufmann
on Who wants a free Sonos? Better: who wants four? at 21:23
Jan Schierkolk
on Steve Jobs at the 2010 Oscars at 18:47
Volker Weber
on iPhone OS 3.1.3 brings back Internet Tethering to unlocked iPhones at 18:44
Steven Zwerink
on iPhone OS 3.1.3 brings back Internet Tethering to unlocked iPhones at 18:33
Ragnar Schierholz
on Who wants a free Sonos? Better: who wants four? at 18:31
Ragnar Schierholz
on Zitat des Tages at 18:30
Keith Taylor
on Who wants a free Sonos? Better: who wants four? at 17:59
John James
on Who wants a free Sonos? Better: who wants four? at 17:42
Volker Weber
on Who wants a free Sonos? Better: who wants four? at 17:40


