[Fwd] The Spider of Doom (RISKS 24.22)
Dan Jacobson <[email protected]> Tue, 09 May 2006 21:58:26 +0800
| Newsgroups | gmane.network.wwwoffle.user |
|---|---|
| Message-ID | <[email protected]> |
news:comp.risks Risks Digest 24.22 "As it turns out, Google's spider doesn't use cookies, which means that it can easily bypass a check for the "isLoggedOn" cookie to be "false". It also doesn't pay attention to Javascript, which would normally prompt and redirect users who are not logged on. It does, however, follow every hyperlink on every page it finds, including those with "Delete Page" in the title. Whoops." Glad to hear the Delete item in the AddCacheInfo page is being phase out. Now all that remains is if Google or some other spider ever happened to get into one of those WWWOFFLE index pages with their delete options... Or at least where one has unset the password... Wait, /etc/wwwoffle/robots.txt (says version 2.7 here) will surely block it...