selenay: (bad day)
[personal profile] selenay
This weekend, on checking the referer logs for The Haven, I noticed that there was a sudden surge in hits and bandwidth on the site. I did a little digging and found that 75% of my referals were coming from a forum for a boy band. Er, I may have registered on it so that I could take a peek on exactly what was being linked to :-)

Somebody was direct linking to one of my Doctor Who icons to use as their avatar, which was why my stats when completely screwy. The thing that's worrying me is that the folder the icon was in had an .htaccess file that should have prevented that - it locks down direct links to my domain, my LJ and the LJ communities that I post to. Every other site that's attempted to hotlink to images protected by that file gets my rude anti-hotlinking image instead (and I've chortled over that a few times...).

Does anyone know how this little brat could have bypassed it? I've changed the file name of the affected icon and she's now getting served with the anti-hotlink image, but I'm a little concerned that this could happen again and I don't want to spend time tracking down these things every couple of weeks.

No, I didn't email the brat. She's apparently 14 years old and I figured that the odds were that if she's deliberated worked out how to bypass my .htaccess file then she'll probably not take my ticking her off well *sigh* My blood pressure and stress levels do not need a 14 year old going on a flame war kick on me.

Date: 2006-07-23 05:25 pm (UTC)
From: [identity profile] munchkinott.livejournal.com
I think this could be how she did it. I know there's a .htaccess vulnerability in older editions of IE too but the fix in the 'Description' should stop the little brat pulling the same stunt again.

Date: 2006-07-23 06:04 pm (UTC)
From: [identity profile] munchkinott.livejournal.com
I know they're using PHP to do it another way they could be getting in

Though, I've just had a thought - if you combine SSI to generate an icon gallery (i.e. point the SHTML at the relative folder), AND use .htaccess to scramble the direct route they theoretically won't have any URLs to follow.

Profile

selenay: (Default)
selenay

December 2025

S M T W T F S
 123456
78910111213
14151617181920
21222324252627
282930 31   

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Jan. 26th, 2026 09:45 pm
Powered by Dreamwidth Studios