Referer Spam

| | Comments (1) | TrackBacks (0)

In the last month I have been getting nailed with various forms of referral spam , and various annoying exploit attempts. Besides the sheer annoyance of it all, the way it screws up your logs and stats, I just didn't want them to think their stuff was working. So I finally implemented some mod_security rules into my apache.

I extended the default debian ruleset with a few that I found online, and things seem to be working well. I hope not too much of a performance hit on this little box (if so, please tell me). I've only had two issues with it so far:

  1. Default rules blocked my cookies. The default rules had a very basic regex for cookie data, didn't' work with my system
  2. Debug Log. The debugging by default is at 9, and that very quickly filled up a 2gb file, which then killed apache

Categories

0 TrackBacks

Listed below are links to blogs that reference this entry: Referer Spam.

TrackBack URL for this entry: http://halls.lug-nut.com/cgi-bin/mt/mt-tb.cgi/1094

1 Comments

jayce said:

One other bug, the force byte range *SecFilterForceByteRange* was by default set to start at 32 (which of course blocked newlines from posting. Made it hard to post that mesage. The "Debian":http://www.debian.org had that as a default, and right under it, the 0 -255 option commented, ready to use.
--------

Leave a comment

About this Entry

This page contains a single entry by Jayce^ published on August 3, 2006 9:00 PM.

Poll was the previous entry in this blog.

Perl Lectures and other Geek Knowledge is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.

Technorati

Technorati search

» Blogs that link here

February 2008

Sun Mon Tue Wed Thu Fri Sat
          1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29  
Creative Commons License
This weblog is licensed under a Creative Commons License.
Powered by Movable Type 4.01