stargeek
PHP news website logo.
home    PHP scripts    articles    seo tools    links    search    contact    shop    realtors


HTTP Referer Protection via Firewall







HTTP Referer Protection via Firewall

HTTP Referer Protection via Firewall 09/06/2004 11:15 PM

Outpost Firewall: This personal firewall blocks outgoing HTTP referrers, which we've discussed before as being a potential security hole. Webmasters just see this in their referrer logs:

Field blocked by Outpost (http://www.agnitum.com)

It must have to parse the text of the HTTP request and manually modify the line which includes the HTTP Referer header. Interesting.

Is this common for firewalls? This is the only "hacked" referrer I remember seeing in my logs.

Click here to comment on this entry




This is a GrokNews Entry: (what is grok?)





Similar Items

HTTP Referer Protection via Firewall

Grok Headline matches for HTTP Referer Protection via Firewall

IE 5.22 on Mac Transmitting HTTP Referer
from Secure Page


IE 5.22 on Mac Transmitting HTTP Referer
from Secure Page
12/26/2003 05:26 PM
deane_at_deanebarker.net (Dec 24 2003)

RE: IE 5.22 on Mac Transmitting HTTP
Referer from Secure Page


RE: IE 5.22 on Mac Transmitting HTTP
Referer from Secure Page
12/30/2003 06:32 PM
tlarholm_at_pivx.com (Dec 30 2003)

Mac Tip: Turn on Firewall Protection


Mac Tip: Turn on Firewall Protection 07/18/2004 12:50 AM
G4 Tech TV Jul 18 2004 5:09AM GMT

Don't put your app protection on your
firewall, Mr Jones


Don't put your app protection on your
firewall, Mr Jones
11/13/2003 10:07 AM
Top Layer touts standalone IPS appliance

Firewall offers best protection from
infestation


Firewall offers best protection from
infestation
09/18/2004 09:17 AM
Chicago Tribune Sep 18 2004 12:13PM GMT

Don't need virus, spyware, or firewall
protection?


Don't need virus, spyware, or firewall
protection?
05/04/2004 09:16 AM
Think again because bugs like "Blaster" simply need an Internet connection! Gone are the days when you could be cautious...

Kerio Personal Firewall Program
Execution Protection Feature Bypass


Kerio Personal Firewall Program
Execution Protection Feature Bypass
09/07/2004 01:32 AM

Dire ct and Related Links for 'Kerio Personal Firewall Program Execution Protection Feature Bypass'

“Tan Chew Keong has reported a vulnerability in Kerio Personal Firewall, which can be exploited certain malicious processes to bypass certain security features provided by the product. Kerio Personal Firewall includes an program execution protection feature, which allows users to restrict execution of programs on the system. However, it is possible for a malicious program to bypass this feature by restoring the running kernel’s SDT (Service Descriptor Table) ServiceTable by writing directly to the “\Device\PhysicalMemory”…

" http://tatugirl sjuliaelena.com
>... http://tatugirlsjuliaelena.com
>> entre e comente se quiser"


" http://tatugirl sjuliaelena.com
>... http://tatugirlsjuliaelena.com
>> entre e comente se quiser"
06/05/2005 11:45 PM

Happy belated Personal Firewall day -
SRT2004-01-17-0628 - Agnitum Optpost
firewall allows Local SYSTEM access


Happy belated Personal Firewall day -
SRT2004-01-17-0628 - Agnitum Optpost
firewall allows Local SYSTEM access
01/19/2004 01:58 PM
KF (Jan 17 2004)

weird referer


weird referer 01/07/2004 04:31 PM

Recently (but I just noticed it today) I started getting HTTP referers that are a variation of the following: "XXXX:+++++++++++++++++++++++" (the number of plus signs varies). A google search with appropriate terms quickly turned up discussions like this one that suggest that the referer is someone using an anonymizer or internet security product of some kind. Without that information it smells like an attempt at an exploit of some kind... but of what kind (and if so, I've never heard of it)?

Anyone knows about this? Has anyone else seen it? I'm curious. :)


Referer tarpit


Referer tarpit 03/14/2005 05:27 PM
Referer Tarpit is a solution for slowing down referer spammers, so you can save others from spam.

ING launches new broker-dealer platform
http://biz.yahoo.com/prnews/050321/clm04
5_2.html http://www.finextra.c


ING launches new broker-dealer platform
http://biz.yahoo.com/prnews/050321/clm04
5_2.html http://www.finextra.c
03/23/2005 02:34 AM
Datamonitor Mar 23 2005 5:39AM GMT

Lieberman Referer Spam


Lieberman Referer Spam 01/03/2004 05:39 PM
Lieberman Campaign Referer Spamming? So Says Me Via Doc Searls I originally sent this item to Doc because I don't blog about national things anymore and didn't have a place to write it up. Of course, today I remember MeFi. As Doc passes along, the following appeared in my referer logs yesterday: aca3cc09.ipt.aol.com - - [02/Jan/2004:18:50:27 -0800] "HEAD / HTTP/1.1" 200 0 "http://joe2004.com/?starprose" "StarProse Referrer Advertising System 2004" Of course, Lieberman's joe2004.com website has no links to my weblog, and obviously, given the user-agent, it's StarProse's business to spam via false referers. I suspect it's targeting weblogs, since many include scripts which display recent referers. Since I don't have any such publicly-accessible referer list, it was only by chance that I happened to spot it at all. There is no way to know for certain, barring comment from the Lieberman camp, if this is their campaign or some random Lieberman supporter engaging in this practice. But it's slime regardless of the responsible party. Anyone spot any other presidential campaigns hijacking people's referer logs to advertise?

Spamming Referer Logs


Spamming Referer Logs 01/04/2004 12:03 PM

Spammers have sunk to a new low: spamming HTTP referer logs. Now that a lot of bloggers display referrer hits, and a lot of bloggers monitor them to see where they're getting links from, spammers have started sending HTTP requests with their site as the referer, just to get people to follow the links out of curiosity.

Doc Searls noted this phenomenon with Joe Leiberman's comapaign site. The URL "http://www.joe2004.com?starprose" appeared in his referer logs. Since Doc has no link from Leiberman's campaign site, and the lone querystrign arguments indicates that someone is trying to track a clickthrough, it seems that this was inserted there just so a webmaster would follow the link. Looking through my logs, I have this referer too.

Also, just like Doc, I have a referer in my logs to a blog solely about the Paris Hilton sex video. Needless to say, there is no link on that site to Gadgetopia. And here's one to a porn site in Germany. And, yes, I followed both these links because I was trying to figure out why, how, and in what context they linked to my site.

I don't know if I'm more irritated that spammers are pushing their way into every last piece of Internet life, or if I'm more irritated that I fell for it. Before I saw the think on Doc's site and put two and two together, I was blitely following these refer links, trying to figure them out. Score one for the spammers, I suppose.

Click here to comment on this entry


Referer lists are back on my posts


Referer lists are back on my posts 02/26/2003 02:44 AM
Some of you might have read kasia's post about displaying referer links in blogs and wondered where that came from. It was me. I admit it. The "another blog" she mentions? You're reading it. Anyway, that cause a bit of...

Chris Shiflett's Blog: Referer Buys You
Nothing


Chris Shiflett's Blog: Referer Buys You
Nothing
02/05/2005 09:07 PM
In a quick reminder for the community from Chris Shiflett, he mentions the fact that the "Referer Buys You Nothing".

S. G. Hart & Associates is Interviewed
by Brand Protection News on
Sarbanes-Oxley Compliance, Risk
Management and Brand Protection
Strategies.


S. G. Hart & Associates is Interviewed
by Brand Protection News on
Sarbanes-Oxley Compliance, Risk
Management and Brand Protection
Strategies.
04/18/2005 03:54 AM
S. G. Hart & Associates, LLC, The Brand Equity Protection Company TM, is featured in the April 6th edition of Brand Protection News, a PIRA International Publication. In the article, S. G. Hart & Associates discusses its thought leadership pertaining to brand protection and the need for an overall risk management posture that is required of public companies under the auspicious of The Sarbanes-Oxley Act of 2002 (SOX). The article further highlights S. G. Hart & Associates’ newest educational offerings targeted to key decision makers, including board of directors and senior managers, who are seeking further information on how SOX effects brand owners’ responsibilities in combating counterfeiting and product diversion in order to protect stakeholder value. [PRWEB Apr 18, 2005]

Referer spammers are comment spammers
too


Referer spammers are comment spammers
too
02/01/2005 10:08 PM
Is there a connection between referer spamming tools such as Reffy, and mass comment spamming in Movable Type?

CD-ROM Firewall


CD-ROM Firewall 06/21/2004 05:07 PM
version 0.15-3 out

PCX Firewall


PCX Firewall 04/12/2004 02:13 PM
Firewall Frontend 1.0 Available!

Firewall FAQ


Firewall FAQ 08/01/2004 03:31 AM

Direct and Related Links for 'Firewall FAQ'

“Firewalls are one of the most basic security measures that you must have in place to protect your systems. We’ve gathered some of the most frequently asked questions regarding firewalls here and invited our expert, David M. Davis, to answer them and provide some additional resources. The FAQ list will be constantly evolving, so you’re invited to send us other questions you may have. Just e-mail them to us or post them in the discussion…

HTTP-OAI-3.08


HTTP-OAI-3.08 04/14/2005 06:56 AM

HTTP-OAI-3.07


HTTP-OAI-3.07 04/08/2005 12:29 PM

Alfandega Firewall


Alfandega Firewall 01/25/2004 12:48 AM
Alfandega Firewall development is Back!

Open-Firewall


Open-Firewall 05/19/2004 07:39 AM
Open Firewall core 0.1.0 released

Firewall Builder


Firewall Builder 01/22/2004 06:11 PM
Firewall Builder v1.1.2 has been released

Blogging behind the firewall


Blogging behind the firewall 05/26/2004 09:06 AM

InfoWorld provides a look at how they use internal weblogs.


Exploring The Mac OS X Firewall


Exploring The Mac OS X Firewall 03/17/2005 03:09 AM

By Peter Hickman, O'Reilly Network


Shoreline Firewall


Shoreline Firewall 05/14/2004 10:51 AM
Shorewall 2.0.2

Automatic Firewall 0.2


Automatic Firewall 0.2 05/03/2004 08:55 PM
An automatically configuring firewall.

"Personal Firewall Day"


"Personal Firewall Day" 01/16/2004 10:58 AM

Personal Firewall Day


Personal Firewall Day 01/16/2004 01:04 PM
Today is Personal Firewall Day! .. .. (new window) .. Seite

personalfirewallday.org
track this site | 17 links


Automatic Firewall 0.1


Automatic Firewall 0.1 04/29/2004 03:16 AM
An automatically configuring firewall.

VisNetic Firewall v2.1.2


VisNetic Firewall v2.1.2 11/01/2003 08:42 PM
VisNetic Firewall is the perfect firewall software solution for small to medium businesses who utilize Windows-based Servers, stand alone PCs, and/or LAN workstations that do not currently run behind a firewall solution. VisNetic Firewall provides protection against internal and external threats through its strong, secure packet-level Stateful Inspection. VisNetic Firewall is comprehensive intrusion protection. [Shareware $49.95 30 Days 2.43 MB]

Endian Firewall


Endian Firewall 06/17/2005 03:37 PM

redWall Firewall 0.5.3


redWall Firewall 0.5.3 05/05/2004 09:36 AM
A bootable CD-ROM firewall with IDS, IPS, proxy, reporting, and spam filtering.

Shoreline Firewall 1.4.7c


Shoreline Firewall 1.4.7c 11/02/2003 11:57 AM
An iptables-based firewall for Linux systems.

PCX Firewall 1.3 (CGI Web Frontend)


PCX Firewall 1.3 (CGI Web Frontend) 05/06/2004 05:40 PM
An IPTables firewalling solution.

PCX Firewall 1.2 (CGI Web Frontend)


PCX Firewall 1.2 (CGI Web Frontend) 04/28/2004 12:15 AM
An IPTables firewalling solution.
Grok Description matches for HTTP Referer Protection via Firewall
GrokA matches for HTTP Referer Protection via Firewall

HTTP Referer Protection via Firewall

The following phrases have been identified by the grok system as matching this entry:

















Also check out:


Grok

Ipod Porn on the
Rise

Brief Abstract of
Wikipedia's
Mesothelioma Cancer
page

Get first aid
instructions in your
cell phone

IE is crap
JSPWiki gains
podcasting support

Elevator:2010
iTunes Music Alarm
Clock 5.3

Israel.pm September
2004 Meeting
Announcement

September 06, 2004
New LED Technology
to Boost Colors in
Flat-Panel Displays

Teachers 'need
citizenship help'

Maradona 'can be
treated abroad'

'Amazing' Viking
cemetary found

'Too few' early
years workers

Lib Dems promise
pensions boost

Netflix + Tivo = Yum
merlin's 43 folders
Clinton's Heart
Bypass Surgery
Called A Success
(washingtonpost.com)

7 Marines Killed in
Blast Near Fallujah
(washingtonpost.com)

Bush, Kerry Clash on
Iraq in Labor Day
Rallies (Reuters)

Singh Takes Woods'
Spot As Top Golfer
(AP)

©„Œ†ͺˆ† †ˆ ‚Œ‚‡ ¬§†
©Œ § †Œͺ ©›
†ŒˆŒˆ©€Œͺ§Œ…

Election 2004
Chechnyan Madness
Comment Spamming
Compiling away my
weekends

Do good on the web
9/11 Proposals Lead
the Agenda Facing
Congress

China Ex-President
May Be Set to Yield
Last Powerful Post

Storm Lands Again as
Floridians Start to
Assess Damage

Bush and Kerry Clash
Over Iraq and a
Timetable

Prepare to install
Windows XP SP2

Fine-tune your
software to drive
efficiency in IT

Beware of spies in
the machine

Work stress at
record high

The vital role of
managing the
outsourcer

BP switches from
intranet to internet

Microsoft to drop
storage system from
Longhorn to meet
2006 date

SuSE Linux users get
free e-mail engine

Cisco warns of
lock-up flaw for IOS
and telnet

BP turns its back on
traditional IT
security with
internet access to
company systems

Network and support
costs will be cut

Countdown starts for
HP switch to Itanium

Mainframe costs
worry IT managers,
says survey

Israel Loses Spy
Satellite

Maths holy grail
brings disaster for
internet

MyHelpdesk
Morath MMORPG Engine
Fortified mailboxes,
part 2

New airplane hailed
as "the fourth great
breakthrough in
aeronautical
science"

Pulp wallpaper
Daily Show RNC clips
Airplane's Toilet
Ice Crashes Garden
Party (AP)

[ GLSA 200409-10 ]
multi-gnome-terminal
: Information leak

then get treated
like cattle and
criminals

what is grok?