[pmwiki-users] Persistant Spam even with blocklist

Bob Atkins bobatkins at hotmail.com
Mon Aug 29 08:20:08 CDT 2005


I wonder if anyone eles has seen anything like this.

I'm getting the same porno spam posted to a particular page in my Wiki. It 
appears every day and I clean it out by deleting the entire contents of that 
page so it starts blank again.

I know the IP it's coming from (195.190.153.177 - it's a proxy in denmark) and 
I've installed blocklist2 with the IP, the IP block and lots of the offending 
keywords  and URLs blocked. I know blocklist2 is working because if I try to 
use any of the blocked words or URLs, the entry is rejected.

However the spam keeps coming, so when the spammer does it, he somehow must be 
getting around the blocklist. How, I don't know.

I also have blockedit.php installed with the offending IP listed and still the 
spam keeps coming.

The server log shows nothing unusual, just a normal edit. Here's the log entry:

=============================================================================
195.190.153.177 - - [29/Aug/2005:03:21:52 -
0700] "POST /photography/pmwiki/pmwiki.php/Main/DSLRs HTTP/1.0" 302 182 "-
" "Mozilla/6.0"
=============================================================================

Anyone have a clue as to how this might be happening? I'm worried about some 
security hole in PmWiki, though I've seen no reports of such.

I used to get a lot more spam, and using blocklist2 has eliminated all but this 
one persistant offender who seems to have found some way around it.

I know I could try password protecting that page, but that's not the issue. If 
one page is vulnerable, all of them are. Right now I'd rather the spammer stuck 
to the one page (which is blank anyway except for the spam), so I least I know 
where to look and it's not (yet) disruption the rest of the Wiki.





More information about the pmwiki-users mailing list