[Modsecurity] Spamming thru forms

David Obando david at cryptix.de
Tue Dec 12 09:37:39 EST 2006


Dear Johan,

why don't you use a CAPTCHA (http://en.wikipedia.org/wiki/Captcha)?

Regards,
David

Johan Segernäs schrieb am 12.12.2006 15:35:
> Can someone build a mod_security rule based on following:
> http://f6design.com/journal/2006/12/09/securing-php-contact-forms/
>
> Maybe?
>
>
> tis 2006-12-12 klockan 09:50 +0100 skrev Johan Segernäs:
>   
>> I have huge problems with people spamming thru our customers forms. Not
>> only to our own customers but they also inject shit load of addresses.
>> Mostly it looks like it's osCommerce contact form but I dont think it's
>> only that one.
>>
>> Anyone have a nice rule against this? Or will it block too many legal
>> forms as well?
>>
>> I'm using latest rules.conf, jitp.conf and rootkits.conf.
>>
>> _______________________________________________
>> Modsecurity mailing list
>> Modsecurity at gotroot.com
>> http://lists.gotroot.com/mailman/listinfo/modsecurity
>>     
>
> _______________________________________________
> Modsecurity mailing list
> Modsecurity at gotroot.com
> http://lists.gotroot.com/mailman/listinfo/modsecurity
>   


-- 
The day microsoft makes something that doesn't suck is the day they start making vacuum cleaners.
gpg --keyserver pgp.mit.edu --recv-keys 1920BD87
Key fingerprint = 3326 32CE 888B DFF1 DED3  B8D2 105F 29CB 1920 BD87



More information about the Modsecurity mailing list