Hello, I had this module, version 6.x-2.0-rc1 installed on my site a year or so ago. I have a webform that appears on every page so that people can contact me from anywhere on the site. The webform has a hidden field which basically just lets me know which page a visitor was on when they filled out the webform.
About 6 or 8 months ago I disabled and uninstalled the module but didn't delete it from the server. Periodically I get emails via the webform and it looks like people are still getting the page referring to being white listed. I've never actually seen the page so I'm not sure what it looks like. This morning I got an email with the same and the page URL was 'httpbl/whitelist'. I've attached a screen shot of what the value of the webform hidden field was so you can see.
Any ideas what might be causing this?
Thanks,
Tim
| Comment | File | Size | Author |
|---|---|---|---|
| Screenshot.png | 2.52 KB | twooten |
Comments
Comment #1
bryrock commentedMy short answer to your question is "no."
6.x-2.0-rc1 has not even been in existence for 8 months, so I don't know how you could have disabled it that long ago.
I have no idea how a disabled and uninstalled module could still do anything. If anyone else has a theory, I'm open minded.
Comment #2
twooten commentedbryrock - thanks for the reply. So the "6 or 8" months ago was a rough guesstimate, I simply remember that it's been months ago. I have no idea how a disabled and uninstalled module could do anything and that is why I was asking. I'll report back if I ever find anything.
Comment #3
bryrock commentedComment #4
twooten commentedbryrock, I just got another email from someone that can not access a particular page on my site due to being blocked. I'm completely at a loss and thought I'd reach out to you one more time.
This time I've got some screen shots to share. From the email I was able to find out which page the problem is coming from - http://www.wootenswebdesign.com/quick-and-easy-beauty-tips. I'm attaching a shot of what I see when going to that URL. I have no idea where that 46.17.96.64 IP address is coming from but it is not mine. Now for the strange part. I clicked on the link that says 'You may try whitelisting on ......' and it took me to the /httpbl/whitelist page as seen in the second screen shot. Again, I do not have the http:BL module installed. I downloaded version 6.x-2.0-rc1 and searched for 'Request whitelisting' which is the title of the form and see it is coming from the httpbl_menu() function.
This is the strangest thing I've seen, the only thing I can think of to possibly do is to blow the site away and rebuild it which seems pretty dramatic......any ideas??
Thanks for looking,
Tim
UPDATE: right before hitting the save button on this post, a light bulb came on and I wondered if the boost module had anything to do with this, I disabled it and checked the page again and sure enough...issue gone. I suppose this would be better taken up in the boost issue queue. Thanks again.
Comment #5
bryrock commentedI wish I'd read your comment from bottom to top. Yes. Viewing the source on those two pages indicates they were both cached by the Boost module, on Oct. 24, 2011 (and didn't expire when the comments said they would).
And, by the way, the IP address that was snagged back then was exactly one of the kind you want to keep off your site (threat score was 62 when I checked it today). Had it been that high last October, it would have been blacklisted immediately, without any whitelist challenge.
If you have drush access, you can verify once and for all whether httpbl is still enabled or installed on your site.
drush pml | grep httpbl