Maybe a naive question, but in the original attack, couldn't the 'bad' requests have been identified using the referrer?
> The first round was cross-domain JavaScript, stopped with an "alert()". Second round was cross-domain <img>, stopped with referrer. Third was DDoS-ing GitHub Pages. Fourth is the ongoing TCP SYN Flood attack.
> Second round was cross-domain <img>, stopped with referrer.
It does not mention that the alert() used the referrer.
E.g.:
- This works: https://github.com/greatfire
- This doesn't: https://github.com/greatfire/
So far as I know, most links (external or internal) to a Github user's page do not use the trailing slash, so the effects would presumably be minimal.
[1] http://cbonte.github.io/haproxy-dconv/configuration-1.5.html...