Home

drupal.ls.net

Navigation

  • About
  • Blogs
  • Contact
  • Forums
  • Image galleries
  • Log in
  • Feed aggregator
Home Blogs webmaster's blog
    • Drupal
    • LSNet

Core security advisories

  • SA-CORE-2010-002 - Drupal core - Multiple vulnerabilities
more

Contrib security advisories

  • SA-CONTRIB-2010-089 - Simplenews Content Selection - Cross Site Scripting
  • SA-CONTRIB-2010-088 - Content Construction Kit (CCK) - Access Bypass
  • SA-CONTRIB-2010-087 - GovDelivery - Cross site scripting
  • SA-CONTRIB-2010-086 - Prepopulate - Access Bypass
  • SA-CONTRIB-2010-085 - Pathauto - Cross Site Scripting
more

Drupal security announcements

  • PSA-2010-002 - Views - Administer views permission
  • PSA-2010-001: Policy on release versions and permissions
more

Drupal.org jobs feed

  • Marketing Website Developer | Western Governors University
  • Coder | Fidoli Bilişim Teknolojileri
  • Drupal developer | ubergig
  • Javascript developer | ubergig
  • Web Developer | MIT
more

Visit our client's websites

  • http://bridle-creek.com
  • http://demo.mydllurth.com
  • http://downtowngalax.com
  • http://drupal.ls.net
  • http://crossleft.org/
  • http://cuttingedgelaw.com/
  • http://new-river.dixongarner.com/
  • http://import.mydllurth.com
  • http://lyceum.mydllurth.com
  • http://mtvaleumc.org
  • http://news.mydllurth.com
  • http://oldcranks.com
  • http://psychguides.com
  • http://starbuck.net
  • http://stewartfurniture.com
  • http://tarvid.org
  • http://ubercart.ls.net
  • http://wolfeservices.net

Events

« September 2010
SunMonTueWedThuFriSat
1234
567891011
12131415161718
19202122232425
2627282930

Moderation

Submitted by webmaster on Fri, 01/29/2010 - 11:31

One of the hazards of making registration easy is that you get spammers as well as the people you really want to connect to. Once moderation is set up, your site is a "honey pot". Sooner or later someone will post something objectionable.

You can easily check Content management - Moderated content (admin/content/modr8) and click on the user name then Track and Track page visits. Pick one and then click "details".  The "hostname" is the IP address of your spammer.

You can chase the IP address at https://ws.arin.net/whois and if it is not an "American" IP, find the "whois" server for the region associated with the IP. One recent case was IP 59.108.91.148 and I found the network information at http://wq.apnic.net/apnic-bin/whois.pl - Beijing Capital Telecom.

Now it is time for a judgment call. I can block the individual IP or the entire "Class B" block. I will choose the later even though that will poke the eyes out of potentially 65,535 IP addresses. This is a local site and I don't really expect Bejing Capitol Users will have much purpose in visiting to I opt for the latter.

User management - Access rules - Add rule (admin/user/rules/add), choose Hostname and enter 59.108.%, Add rule. Now it is time to clean up the post. Back to Content management - Moderated content (admin/content/modr8)  and choose Delete - Save. Then back to the user, Edit and Delete..

Tomorrow we can go after another spammer.

  • webmaster's blog
  • Login or register to post comments
  • Printer-friendly version
  • Send to friend
  • PDF version
  • Delicious
  • Digg
  • StumbleUpon
  • Facebook
  • Google
  • Technorati

User login

What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Powered by Drupal, an open source content management system
RoopleTheme