Forum Moderators: coopster & phranque

Message Too Old, No Replies

CGI Guestbook Spammed to Hell ...

Any secure ones out there?

         

pab1953

3:35 pm on Feb 4, 2005 (gmt 0)

10+ Year Member



For a client's website I installed a CGI guestbook offered by my ISP ... and it got spammed to hell. Naturally, the client was upset and I'm ticked to, both at the ISP for not giving any warning and at myself for not being better informed.

Are there any secure CGI guestbooks out there? Or non-CGI? Or should one just stay away from guestbooks altogether because they can so easily be spammed?

Thank you.

moltar

4:08 pm on Feb 4, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Most guestbooks can be spammed. You best bet would be finding some un-popupar script, or write your own.

Generally guestbooks don't look so professional. To me they remind JOe's homepages...

pab1953

4:21 pm on Feb 4, 2005 (gmt 0)

10+ Year Member



The client asked for the guestbook. Actually on her site -- she's an artist, and her site is essentially an ecommerce gallery -- it makes sense because physical galleries often have physical guestbooks.

Having said that, it sounds like a guestbook can't be made secure (and I can't code PERL).

Thank you for your thoughts.

jatar_k

6:21 pm on Feb 4, 2005 (gmt 0)

WebmasterWorld Administrator 10+ Year Member



guestbooks can't really be secured very well.

The problem is inherent in how they are supposed to work. Anyone from anywhere can just post a comment to them, no login or control of any kind. diligent management of new comments is really the only answer. Maybe look if there is one where new comments are entered into a queue of some sort and must be verified before they are shown on the site.

It won't limit the spam but at least it won't show publicly.

rocknbil

6:45 pm on Feb 4, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



All you have to do is code it so the data does not display until it's approved by the administrator. Active/not active.

People will still try, but if they don't get what they want they will give up (sooner.)

TheWhippinpost

11:34 pm on Feb 4, 2005 (gmt 0)

10+ Year Member



Best 1st line of defence with provided-scripts is to change filename(s) and form-fields.