Don't shoot me if I'm wrong, but as far as I know you can post "something" (a comment or so) with more URLs than defined with the 'Maximum allowed URLs'-setting, and your message will bypass the spam-filter as long as:

  • you don't put http:// or https:// or ftp:// or mailto: in front of your URL or email address (for example: www.example.com)
  • AND the 'URL filter' (which turns web and e-mail addresses into clickable links) is enabled for the input format that is used for a (visitor's) user role

As far as I understand the spam module('s code), the "second pass" (grab urls from unsanitized string) of the spam_tokenize function should/could be extended by using more code from Drupal's built in URL filter method.

Doing so will catch more potential spam links, I think.
Any feedback is welcome.

CommentFileSizeAuthor
#4 betterurldetection_spamfilter.patch1.71 KBpieterdc

Comments

jeremy’s picture

Patches to improve the spam module's detection of URLs is certainly welcome.

jeremy’s picture

Version: 5.x-1.0 » 5.x-3.x-dev

Efforts to improve the URL filter will happen in the 5.x-3.x development branch of the module.

jeremy’s picture

Status: Active » Postponed

Postponing issue. I would like to see the url filtering improved, but this is not a show stopper at this time. Postponing until after we are in beta, or until someone comes along with a patch.

pieterdc’s picture

Version: 5.x-3.x-dev » 6.x-1.x-dev
Status: Postponed » Needs review
StatusFileSize
new1.71 KB

Patch created against 6.x-1.x-dev (as Drupal 5 is almost unsupported).
But I guess this patch could easily be backported.

Ready for testing because.. as far as I tested it, it works ;-)

gnassar’s picture

There probably is a good reason for this that I just haven't come up with yet -- but why wouldn't we just run the text through _filter_url() and then test that, instead of duping its internals here?

pieterdc’s picture

Because _filter_url() changes the text, but the Spam module needs to know how many and which links were found in that piece of text.

gnassar’s picture

Category: bug » feature
Status: Needs review » Fixed

Committed. Thank you for the great patch.

jeremy’s picture

@gnasser, please include a link to the CVS commit message when you commit patches for future reference.

gnassar’s picture

Crud. I did forget to do it on this one, didn't I? And I'd been so good about it on all the others... :)

http://drupal.org/cvs?commit=469868

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.