[support] excessive bandwith usage

J. Antas antas at e-healthexpert.org
Tue Jan 17 09:31:49 UTC 2006


Mark Shropshire wrote:
> Just curious. What is the reasoning for turning off the feedback module? Is
> it to reduce form spam?
> 

The Feedback module is a nice idea, badly coded.

As it is done now, The Feedback module is an open door to use it as a 
sand box to test not only spam, but any kind of code injection.

Each time that a new exploit (to attack PHP, database, Drupal, etc.) 
gets known, you will have at your site an open door ready to test it.

It would be much more secure if it had some kind of Captcha protecting 
it... but then again, captchas have problems of their own!


P.
-- 


More information about the support mailing list