Skip to content

关于泄露邮箱,ip的安全问题 #55

Answered by lizheming
yiyungent asked this question in Q&A
Discussion options

You must be logged in to vote

另外前段时间发生了 Valine 大量垃圾评论灌入的事件(灌入的垃圾广告是用来“宣传” Waline 的,但不是我做的哈),主要也是由于:

  1. Valine 可以直接对数据入库,所有的数据都可以伪造
  2. 没有服务端所以没办法对行为进行限制,只要开放了任意用户写库的权限,那基本上就等着库被刷爆吧 😢

Waline 的话因为有服务端,虽然因为匿名的原因大部分数据还是可以伪造的,不过 IP 的获取是相对真实的(这个伪造比较难)。后期还会加入登录评论相关的策略。另外 Waline 因为有服务端,所以可以对用户行为进行限制,包括:

  1. Akimset 垃圾评论过滤
  2. IP 频率控制(默认60秒)
  3. IP 黑名单策略自定义
  4. 关键词策略自定义
  5. 重复内容过滤

Replies: 4 comments 4 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
4 replies
@ghost
Comment options

@lizheming
Comment options

@ghost
Comment options

@lizheming
Comment options

Answer selected by Mister-Hope
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants
Converted from issue

This discussion was converted from issue #55 on December 11, 2020 07:13.