New Spam Frontier: Referer Logs
geoffsmith writes "Wired News is reporting that spammers are using referer logs as a cheap new way to
spam small sites. Anyone running a website has probably already seen this phenomenon; I'm thinking of writing a script to remove these entries from my access_log by looking for hits that don't grab my images. (sorry lynx users!)"
(sorry lynx users)
Don't worry. It's highly unlikely that any of the 4 current users will visit your website anyway.
Windows users are complaining that Microsoft is filling up their computer's System Event Log with spam about illegal exceptions and page faults.
I cant tell you how many times a referer log in my access log files contains someones email account pw for their web based email service... and being the ass that I am, i read their email. its quite fun.
I don't know spam that managed to involve a virgin, a cock, a septic tank, and a gentleman from Nigeria would almost have to be interesting.
Yes, referrer information makes an excellent authentication scheme for highly confidential system dealing with transfer of mission critical information. ... Just also check for a magic string in the user agent and voila! trusted computing reinvented. To make it unhackable - just add a few more levels of obfuscation. ;))) The sad part of this, is that I have actually seen authentication schemes like this. Don't know whether I should cry or laugh :)
But if there were no referer info, then there couldn't be cool tricks like the time Somethingawful.com redirected visitors from Slashdot to goatse.cx!