Quote:
Originally Posted by Eric
Alfa1, I do apologize, but I have no idea right now what the issue is with the Accept header. There are a few possibilities, however, such as if the user is using a proxy/VPN... or if they are running the browser in "private" mode - there is also some PC software that could cause the problem. I'm going to talk with Michael (error10) about this, and see if he has any ideas.
|
Until there is a solution for 'Required header 'Accept' missing', is there a way to not block users for this reason? Its blocking about 50 valid users every 24 hours. I have no doubt that its caused by registered members with security software. I do not want to block these real users. Talking to all these users or whitelisting all their IPs is not possible.
Quote:
Originally Posted by error10
Most of the time, these are actual spambots.
|
In the logs of my limited testing these have been 100% real users.
Quote:
Originally Posted by error10
PayPal has a long history of sending their IPN notifications without a User-Agent. There's nothing I've been able to do to convince them to send a User-Agent except to advise affected people to complain to PayPal. In the meantime you can whitelist their IP addresses.
|
I would be highly surprised if anyone would be able to convince paypal about anything. I have whitelisted the script.
New feature request:
Alert staff if registered member performs SQL injection or other attacks
One thing that I find missing in this addon is a way to feed bad bot data to the blacklist. Please consider to add such functionality. Either as part of this addon or as Projecthoneypot integration. Added to tracker:
Feed data to blacklist