Path: csiph.com!usenet.pasdenom.info!weretis.net!feeder4.news.weretis.net!news.musoftware.de!wum.musoftware.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail From: "Mel Smith" Newsgroups: comp.lang.javascript Subject: Re: Thwarting DoS attacks Date: Wed, 3 Oct 2012 18:20:25 -0600 Lines: 44 Message-ID: References: X-Trace: individual.net bDTYHf4rxIOdq1ohmYawHARVaSD9PjmTFK2CMkLqxWBv/rTYOG Cancel-Lock: sha1:gh4yeZaYxNhBfxGGx1eWhcxKB48= X-Priority: 3 X-MSMail-Priority: Normal X-Newsreader: Microsoft Outlook Express 6.00.2900.5931 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.6157 X-RFC2646: Format=Flowed; Original Xref: csiph.com comp.lang.javascript:16371 Denis said: > Another technique: > > Ask them for an email addr. Email a unique link to each addr that is > submitted. Something like: > > "Hi > > You (or someone pretending to be you) submitted a request for a download > link for [name of software]. > > To confirm that you want this link, click the following url: > > http://host/confirm1?x=some_hash_here > > Otherwise, please ignore this email. > > Best Wishes > > Mel Smith, blah blah blah" > > When they click on the confirm link, email a unique (using a different > hash) download link to the email addy for that hash. In your download > handler, check for valid second stage hashes. > > A bit more fiddly to program and use, but possibly less fiddly to the > user than a captcha, and if / once the attacker catches up with the new > system, you may over time be able to identify email providers that are > being used in the attacks. Denis: This is another good idea ! I'll investigate it. Thanks, -Mel