• Jonah (unregistered) in reply to kipthegreat
    kipthegreat:
    Alex Papadimoulis:
    As it turns out, Google's spider doesn't use cookies, which means that it can easily bypass a check for the "isLoggedOn" cookie to be "false".
    So the logic something like:if (getCookie(isLoggedOn) != "false")    CongratulationsYouAreLoggedIn()Why would anyone do that??  (and yes I realize the point of this site is to make you wonder things like that).Someone needs to replace it with this clearly superior code:if (getCookie(isLoggedOn) != false && getCookie(isLoggedOn) != FILE_NOT_FOUND)     CongratulationsYouAreLoggedIn()

    :)

    OMG! How can people be so stupid? Don't you know ANYONE can edit their browser cookies? The only way to be truly secure would be to store the PASSWORD and USERNAME in a cookie, and then to CHECK IT to a database EVERY TIME THE PAGE RUNS. And I mean everytime.

  • Wesley (unregistered) in reply to Anon
    Anon:

    I had something happen like that once - it was a calendar that went backwards and forward over events. It would go pretty far into the past and future if you just kept on clicking on "Previous Month" and "Next Month". These were simple links, like "calendar.php?y=2006;m=3".

    I too had this problem when I used a plugin for mambo which had dynamic calendar dates.

    I disabled it in the end as it was already indexed and they kept doing a freshness check. Thinking back the proper solution is to only allow a limited number of dates in the future.

    This was not a problem when search engines used to not spider anything with a query string.

Leave a comment on “The Spider of Doom”

Log In or post as a guest

Replying to comment #:

« Return to Article