Forum Moderators: DixonJones

Message Too Old, No Replies

full-on log-spamming attack

what triggered it?

         

RobBroekhuis

12:30 pm on Nov 17, 2004 (gmt 0)

10+ Year Member



Starting sometime yesterday, and continuing in full force today, my logs are being hit by a continuous stream of log-spamming requests, with referrer strings invariably going to adult-type sites (or so I assume, by their urls). They all grab just my home page, use different user-agents, and seem to come from a wide range of IPs. Did I do something foolish to trigger this onslaught? It's not hurting me too much bandwidth-wise, but it's sure annoying having to wade through these entries in my logs to find the relevant ones...
Rob

Rosalind

10:47 pm on Nov 17, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member




Did I do something foolish to trigger this onslaught?

You put up a website. Anyone with an even vaguely popular site is getting this, and the problem may well be getting worse. If you have Apache, a .htaccess file with a long list of banned referrer strings will help, including common porn words. This type of site tended to pioneer the log spamming assault, but unfortunately referrer spam is branching. I have come across this originating from all sorts of subject areas and niches. Hosting and webmaster type sites are doing it a lot, for obvious reasons.

Don't make your stats public because this is how these log spammers can profit from it. You probably don't do this anyway. The spammers are simply using a scattergun approach, so probably nothing short of convincing every single webmaster everywhere to password protect their stats will put a stop to this annoyance.

RobBroekhuis

12:11 pm on Nov 18, 2004 (gmt 0)

10+ Year Member



I was just surprised at the suddenness of the onslaught - I've had sporadic log spamming occurring throughout the life of my website - but this is ridiculous! While I did deny a few of hte IP addresses, I'm not convinced it's a useful approach - it's not like these guys want my content anyway, and they still make it into the logs (albeit with a 403).
Rob

Rosalind

8:41 pm on Nov 18, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Denying the IP and referrers will just minimise the bandwidth they use, that's pretty much the most you can do.