Skip to content

Python job board may need a submission throttle control #852

Open
@malemburg

Description

@malemburg

On Thanksgiving (2015-11-26), we were hit by an obviously scripted attack to submit lots of junk job postings. Here's an example:

Title:    3
Company:  */netsparker(0x005D0D);/*

Posted:   26 November 2015
Category: Administrator
Contact:  3 <netsparker@example.com>

Description:

We may want to prevent such attacks by e.g. not allowing more than one posting per minute, or only allow postings by logged in users. A captcha may also help.

Metadata

Metadata

Assignees

No one assigned

    Labels

    app/jobsRelates to the jobs app

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions