One of the things ive noticed is that arsehats are filling my webserver access logs with
bogus referrers. That is seeding a whole lot of urls to sites by hittings
my website again and again with different referring urls. There are
obviously scripts out there to do this, and undoubtedly organisations that
sell you the service.
They arent that hard to spot yet, and even easier when they come from the
same ip, just punt that off to shorewall to blacklist. But its all a bit of
a PITA.
UPDATE 2004/09/05: Writing a script.
Ive decided to write a script that uses shorewall zones to blacklist these
spammers on the fly. Working on that now.