pf » Trackback Salt

Trackback Salt

web

When I implemented the new trackback feature on my blog, I was aware that spammers like to use trackbacks, so I coded in a keyword blacklist. Roger Benningfield added a comment about track back autodiscovery and spamming that got me thinking.

Pete: Unless you've got some industrial-strength spam control running in the background, make sure you don't add any TB autodiscovery elements to your pages. 'Cause if you do, the bots will find you, and you'll wake up one morning with a few thousand Trackbacks for poker and drugs.

I had assumed that since I'm not using main stream blogging software, I wouldn't have much of a problem (I don't have much of a problem with comment spam), since my url's were not common. But My url's were quite easy to exploit I realized: http://www.petefreitag.com/tb/entryid all a spammer has to do is loop from 1 to n, and avoid my blacklist and they have just posted a trackback in all my posts... So my solution to this is Trackback Salt. I create a somewhat unique hash for each entry, and include it in the trackback url. That way its impossible for someone to just loop over all my entry id's.

There are lots of ways you can do this, you could create a salt based on the current day, so trackback url's would change every day. You could generate a unique id, and store it in your database, or you could simply use the entry id, and a predefined string to generate the hash.



Related Entries
10 people found this page useful, what do you think?

Trackback Address: 300/3ADCCE22A5C20B32F937629BAFC09293
On 06/23/2007 at 7:31:22 AM MDT AAS wrote:
1
taYu01 Hey, there is what you need.

On 09/21/2007 at 7:55:45 AM MDT downloadmp3 wrote:
2
http://listoy.100webspace.net/index.html Download Music

http://listomski.100webspace.net/index.html HQ Mp3

http://downloadmusic.makesha.net/indexxx.html Best music




  



Spell Checker by Foundeo





Subscribe to my RSS Feed: solosub RSS
Tags