Baccou Bonneville Blogs Eclipse Blog Process Improvement Blog Java Blog Web Design Blog Miscellaneous .NET Blog

08/11/05

English (US)   What is and how to fight the referer spam attack?  -  Categories: Blogs, Security  -  @ 10:35:30 pm
Attack

I was wondering why we had a big number of connections on our web site for the first days of August. The answer is that our web site was the victim of the so-called referer* spam attack. I have found this article on Referer Spam by Mike Healan from Spywareinfo that explains what is a referer, how is done the attack and how to protect your web site or blog.

Another article "Blocking bad bots without mod_rewrite" by Johan Petersson explains how to protect your web site even if your hosting company does not offer mod_rewrite (like for Francexpress that hosts www.baccoubonneville.com).

* A referer is the previous URL from which a link was followed to finally go on your web site.

1 comment

Comments:

Comment from: Jerome [Visitor] · http://www.cv.sioban.net
There's another method called mod_security which you can find here :
http://www.modsecurity.org/

it's a keyword filter, with little to no, performance impact on the web server.

it deserves more than only filtering spam referer, but can be used also for that.

you can find good spamlist (along other security filtering list) here :http://www.gotroot.com/tiki-index.php?page=mod_security+rules

of course you have to be the master of your server... which is very useful.

Jerome.
PermalinkPermalink 10/01/05 @ 12:27

Leave a comment:

Your email address will not be displayed on this site.
Your URL will be displayed.

Allowed XHTML tags: <p, ul, ol, li, dl, dt, dd, address, blockquote, ins, del, span, bdo, br, em, strong, dfn, code, samp, kdb, var, cite, abbr, acronym, q, sub, sup, tt, i, b, big, small>
(Line breaks become <br />)
(Set cookies for name, email and url)
(Allow users to contact you through a message form (your email will NOT be displayed.))
This is a captcha-picture. It is used to prevent mass-access by robots.

Please enter the characters from the image above. (case insensitive)

Pingbacks:

No Pingbacks for this post yet...

powered by
b2evolution

Credits: blog software | web hosting | monetize