[pmwiki-users] Honeypots for Spam (was Spam status and suggestion for PmWiki.org)

Patrick R. Michaud pmichaud at pobox.com
Mon Oct 16 11:14:01 CDT 2006


On Mon, Oct 16, 2006 at 08:02:31AM -0700, Pico wrote:
> > From: Thomas -Balu- Walter <list+pmwiki-users at b-a-l-u.de>
> > 
> > On Tue, Oct 10, 2006 at 02:07:28PM -0700, Pico wrote:
> > > If we were to start using honeypots to deal with automated attacks, then
> > 
> > I wonder how fast those bots post to the wiki. If they change e.g. X
> > pages in Y seconds we could probably block them this way too?
> > 
> 
> That is what should be happening with the new Site.Blocklist-Honeypot
> (where ip addresses are added when a save is attempted and the
> Site.Blocklist-Honeypot is part of the array of pages used for
> blocking).
> 
> Which raises the issue of what happens when the honeypot gets "filled
> up"?
> 
> Right now, I get a timeout when I try to view the honeypot.  
> 
> When I viewed it in the past, I noticed that much of the content appears
> to be the content of the links that the spammers are trying to post.  
> 
> Assuming that the entries in the Blocklist-Honeypot page is being used
> to determine what IP addresses should be blocked, maybe we should only
> save the ip information in that page.  (The other information could be
> saved to some other page that is not read by the blocklist).

I'm thinking of having a separate Blocklist-Log page that logs the
results of any blocked postings (including unapproved urls).  Then 
Blocklist-Honeypot would simply contain the blocked IP addresses
and the reasons a post was blocked (but not the details).

Pm




More information about the pmwiki-users mailing list