Log inskip to content

Easy Way to Stop Web Form, HTML and Comment Spam Injections

source: http://cospbbb.org/blog/category/7.aspx

Of late many automated spam bots have been attempting to inject scripts, spam URLS’s and such into forms, comments, etc. This also pollutes website log files.

According to Bots vs Browsers much of the script injections are taking place in the User Agent (UA) Browser field.

“The last couple of weeks have been pretty routine around here. In our logs, we’ve sifted through a growing number of script injection hacks via user agent, some if which are getting quite creative with their HTML markup and JavaScript technique. We’ve also seen some new bots, and some old bots that are very active as of late.” - from BotsVsBrowsers Website (see 2008.8.3)

The following strings seem to be the most often used (and shouldn’t appear in any normal UserAgent string).

*