Home

drupal.ls.net

Navigation

  • About
  • Blogs
  • Contact
  • Forums
  • Image galleries
  • Log in
  • Feed aggregator
Home Blogs webmaster's blog
    • Drupal
    • LSNet

Core security advisories

  • SA-CORE-2010-001 - Drupal core - Multiple vulnerabilities
  • SA-CORE-2009-009 - Drupal Core - Cross site scripting
more

Contrib security advisories

  • SA-CONTRIB-2010-029: Keys - Cross-site Request Forgery
  • SA-CONTRIB-2010-028 - Tag Order - Cross Site Scripting
  • SA-CONTRIB-2010-027: Email Input Filter - Arbitrary code execution
  • SA-CONTRIB-2010-026 - Monthly Archive by Node Type - Access Bypass
  • SA-CONTRIB-2010-025 - TinyMCE - Cross Site Scripting (XSS)
more

Drupal.org jobs feed

  • Drupal Expert | sound ideas
  • Freelancer Drupal Module and Theme Developers at Noida | OSSCube
  • WebLex | Drupal Web Project Development
  • Drupal web programmer & user interface integrator | National Renewable Energy Laboratory (contract)
  • Drupal, PHP, MySQL, AJAX developer | Brillient Corporation
more

Visit our client's websites

  • http://bridle-creek.com
  • http://demo.mydllurth.com
  • http://downtowngalax.com
  • http://drupal.ls.net
  • http://crossleft.org/
  • http://cuttingedgelaw.com/
  • http://new-river.dixongarner.com/
  • http://import.mydllurth.com
  • http://lyceum.mydllurth.com
  • http://mtvaleumc.org
  • http://news.mydllurth.com
  • http://oldcranks.com
  • http://psychguides.com
  • http://starbuck.net
  • http://stewartfurniture.com
  • http://tarvid.org
  • http://ubercart.ls.net
  • http://wolfeservices.net

Events

« March 2010 »
SunMonTueWedThuFriSat
123456
78910111213
14151617181920
21222324252627
28293031

Moderation

Submitted by webmaster on Fri, 01/29/2010 - 11:31

One of the hazards of making registration easy is that you get spammers as well as the people you really want to connect to. Once moderation is set up, your site is a "honey pot". Sooner or later someone will post something objectionable.

You can easily check Content management - Moderated content (admin/content/modr8) and click on the user name then Track and Track page visits. Pick one and then click "details".  The "hostname" is the IP address of your spammer.

You can chase the IP address at https://ws.arin.net/whois and if it is not an "American" IP, find the "whois" server for the region associated with the IP. One recent case was IP 59.108.91.148 and I found the network information at http://wq.apnic.net/apnic-bin/whois.pl - Beijing Capital Telecom.

Now it is time for a judgment call. I can block the individual IP or the entire "Class B" block. I will choose the later even though that will poke the eyes out of potentially 65,535 IP addresses. This is a local site and I don't really expect Bejing Capitol Users will have much purpose in visiting to I opt for the latter.

User management - Access rules - Add rule (admin/user/rules/add), choose Hostname and enter 59.108.%, Add rule. Now it is time to clean up the post. Back to Content management - Moderated content (admin/content/modr8)  and choose Delete - Save. Then back to the user, Edit and Delete..

Tomorrow we can go after another spammer.

  • webmaster's blog
  • Login or register to post comments
  • Printer-friendly version
  • Send to friend
  • PDF version
  • Delicious
  • Digg
  • StumbleUpon
  • Facebook
  • Google
  • Technorati

User login

What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Powered by Drupal, an open source content management system
RoopleTheme