[wp-hackers] More anti-spam ideas

Kitty kitty at mookitty.co.uk
Sun Sep 26 07:55:54 UTC 2004


On Sun, 2004-09-26 at 00:31, Mark Jaquith wrote:
> A hash based on the file hash of index.php and the list of activated 
> plugins wouldn't change all that often.  If you never edit your 
> index.php or change your plugins, this could stay constant and once a 
> spammer learns it, he can just hard code it into his spam script for 
> your site.

yeah, hence the call for ideas :)

> This solution came up in #wordpress and it might be better to just 
> combine the admin password's hash with the day of the year (really, you 
> could choose any number of things for your "static" part of the hash, 
> just so long as you have something in there that changes once in a while.)

Admin PW hash + date could work, or even a random hash that was created
and stored for a fixed period. Could even be for a week, then combined
with a dynamic value.
-- 
Cheers!
Kitty
http://blog.mookitty.co.uk/
http://mookitty.co.uk/devblog/

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url : /pipermail/hackers_wordpress.org/attachments/20040926/0ec92a23/attachment.bin


More information about the hackers mailing list