[Fwd] The Spider of Doom (RISKS 24.22)

Dan Jacobson <[email protected]> Tue, 09 May 2006 21:58:26 +0800
Newsgroups gmane.network.wwwoffle.user
Message-ID <[email protected]>
news:comp.risks Risks Digest 24.22
  "As it turns out, Google's spider doesn't use cookies, which means that it
  can easily bypass a check for the "isLoggedOn" cookie to be "false". It also
  doesn't pay attention to Javascript, which would normally prompt and
  redirect users who are not logged on. It does, however, follow every
  hyperlink on every page it finds, including those with "Delete Page" in the
  title. Whoops."
Glad to hear the Delete item in the AddCacheInfo page is being phase
out.  Now all that remains is if Google or some other spider ever
happened to get into one of those WWWOFFLE index pages with their
delete options... Or at least where one has unset the password...
Wait, /etc/wwwoffle/robots.txt (says version 2.7 here) will surely block it...