ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

News site hit by trackback spam

Tom Espiner ZDNet.co.uk

Published: 21 Mar 2007 15:10 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Companies have been warned of potential difficulties with trackbacks on their websites after an outbreak of trackback spam — which pointed to adult sites — hit a Filipino news site late last week.

The Newsbreak.com.ph site was targeted on Friday, prompting staff to disable the site for nine hours. "The spammers used the trackback feature to flood our site with links to various porn sites," said a Newsbreak.com article. "We found over 27,000 trackbacks."

A Trackback is a form of link used on news sites and blogs to identify referrer sites. Trackbacks allow website administrators to see who has linked to their sites, and also allow readers to find related links. To track back, the site needs a referrer — the URL that an http look-up is supposed to be coming from — and a user agent — an identifier for a piece of software that connects to a network, usually a web browser.

The problem is that both referrer and identifier are easy to fake. Faking is achieved by writing a small piece of software that sends false information in the header as a request to the server.

Spammers can use trackbacks to hyperlink postings on legitimate sites to sites of their choice. Some spammers link to phishing sites, or overwhelm a blog server with trackback spam in a distributed denial of service (DDoS) attack.

Trackback spam is difficult to deal with, because trackback is not necessarily tied to registration on a site, and even if it is, spammers need only to register to spam the site. It's possible to have trackback spam filters, but they operate by looking for common terms, which can generate a lot of false positives and negatives.

Graham Cluley, senior technology consultant for Sophos, warned that trackbacks are increasingly being exploited. "It's a shame that an innovative technology like trackback should be so widely abused," said Cluley.

Newsbreak has now suspended the trackback feature of its site, and users are being asked to log in before posting any comments. Newsbreak added that it is raising the level of its site security.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
6 out of 6 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

IT Audit Manager - SAP

You will identify areas for business process and controls improvements utilising SAP knowledge and audit skills and ACL tools. You will co-ordinate, ...

PHP-Hot! Are you? 35000-40000 North West

Joining a great team environment in fantastic offices you will be involved in the design and launch of a number of e-commerce websites. Use the link ...

Web Analyst/Developer - North Yorkshire

Experience maintaining and developing links between websites and intranet content. Excellent opportunity for a web analyst. This fantastic role will ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment