| I am a victim of HTTP Referrer attacks... |
|
|
| Wednesday, 17 May 2006 22:40 | |||||||||
|
I look today at my statistics, trying to discover some strange URLs (maybe an attack, I recommend You to do it) or tracking Referrer of my visitors in order to see who is back linking me, or where someone is talking about me. I found 201 referrer coming from a famous hardcore movie site, 201? this is not a hazard. Going there for the sake of truth (;-)) I found that they are offering free porn images, video and I immediately thought about The famous "Free porn CAPTCHA Attack" My site is powered by Joomla, and I have developed a CAPTCHA framework. A Capctha is a generated image containing some scrambled text, the idea is to require a human being to read it and so it prevent spammers from automatically generating million of comments, emails accounts,...One way to crack CAPTCHA is to offer a free porn site which requires that the user key in the solution to a captcha -- which has been inlined from my site for example -- before he can gain access. Free porn images or video attract a lot of users around the clock and in many countries. Solutions to block spammers: for a time
Firstly, the spammer creates a simple script that searches sites just like search engine bots do, but the only difference is that these scripts send a referrer header with their own site's address. Why to do this you may ask? My sites has its statistics page indexed by a number of search engines. This means that if the spammer can get his site listed in the stats page, then it will give this referrerÂ’s site higher ranking in search engines too. This also allows that more search engines will crawl the link back to their site. Solutions: Avoid publishing Your statistics page.
Powered by !JoomlaComment 3.20
3.20 Copyright (C) 2007 Alain Georgette / Copyright (C) 2006 Frantisek Hliva. All rights reserved."
|
|||||||||
| Last Updated ( Wednesday, 17 May 2006 22:51 ) | |||||||||
| Another articles: |
|---|
|



















My site is powered by
Firstly, the spammer creates a simple script that searches sites just like search engine bots do, but the only difference is that these scripts send a referrer header with their own site's address. 





