Tuesday, October 2, 2012

What Should I Put on My 403 Page?

Your 403 page (Forbidden) should be reserved for bad actors trying to hack your web site or spambots. I suggest sending them to harvester hells around the web, as in the code below. Any spambot that goes to those places may absorb bogus email addresses, get identified by honeypots, or waste time spinning their wheels.
The above is a harsh message to display to humans, so you had better be sure that it is not possible for an innocent user to accidentally trigger the 403 page. I soften the text for most of my web sites and make it civil, because there is a chance that some kind of unforeseen event could trigger a 403. However, if your web site has received a lot of hacker abuse in the past, then this wad of sputum may very well be what you want. I composed the message after one of my sites got hacked, an event which also caused me to devote many hours to learning about web site security.Post a Comment
by igor 04:20 4 replies by igor 09:32

No comments:

techlorebyigor is my personal journal for ideas & opinions