[pmwiki-users] Persistant Spam even with blocklist
Bob Atkins
bobatkins at hotmail.com
Mon Aug 29 08:20:08 CDT 2005
I wonder if anyone eles has seen anything like this.
I'm getting the same porno spam posted to a particular page in my Wiki. It
appears every day and I clean it out by deleting the entire contents of that
page so it starts blank again.
I know the IP it's coming from (195.190.153.177 - it's a proxy in denmark) and
I've installed blocklist2 with the IP, the IP block and lots of the offending
keywords and URLs blocked. I know blocklist2 is working because if I try to
use any of the blocked words or URLs, the entry is rejected.
However the spam keeps coming, so when the spammer does it, he somehow must be
getting around the blocklist. How, I don't know.
I also have blockedit.php installed with the offending IP listed and still the
spam keeps coming.
The server log shows nothing unusual, just a normal edit. Here's the log entry:
=============================================================================
195.190.153.177 - - [29/Aug/2005:03:21:52 -
0700] "POST /photography/pmwiki/pmwiki.php/Main/DSLRs HTTP/1.0" 302 182 "-
" "Mozilla/6.0"
=============================================================================
Anyone have a clue as to how this might be happening? I'm worried about some
security hole in PmWiki, though I've seen no reports of such.
I used to get a lot more spam, and using blocklist2 has eliminated all but this
one persistant offender who seems to have found some way around it.
I know I could try password protecting that page, but that's not the issue. If
one page is vulnerable, all of them are. Right now I'd rather the spammer stuck
to the one page (which is blank anyway except for the spam), so I least I know
where to look and it's not (yet) disruption the rest of the Wiki.
More information about the pmwiki-users
mailing list