Great – just as I found these new HTML entity spammers today Jay Allen released a new verion of his
MT-Blacklist v1.64 – Just wonder if this would already be the cure?
Version 1.64 is essentially a one-line change from v1.63 to fix the _sanitizeInput() function in Blacklist.pm. This function, included since the first release of MT-Blacklist, decodes all comment information before comparison with the blacklist.
Unfortunately, the order of the lines in the function prevented MT-Blacklist from actually decoding encoded URLs correctly meaning that even a brain-dead spammer who had even the most basic familiarity with HTML could spam as if MT-Blacklist didn’t even exist. [YOOO!!!]
What’s crazy is that I don’t think I’ve touched that function since the first version, meaning that this hole has been present for over six months!
Recent comments
13 weeks 6 days ago
14 weeks 16 hours ago
16 weeks 3 hours ago
16 weeks 5 days ago
17 weeks 9 hours ago
25 weeks 6 days ago
25 weeks 6 days ago
26 weeks 1 day ago
26 weeks 2 days ago
27 weeks 1 day ago