Thank you Gizmo. I implemented these rules in the .htaccess file.

Code
RewriteEngine On

# A. changeprefs with a what= that is not style or lang
RewriteCond %{REQUEST_URI} ^/ubbthreads/ubbthreads\.php$ [NC]
RewriteCond %{QUERY_STRING} (^|&)ubb=changeprefs(&|$) [NC]
RewriteCond %{QUERY_STRING} (^|&)what= [NC]
RewriteCond %{QUERY_STRING} !(&|^)what=(style|lang)(&|$) [NC]
RewriteRule ^ - [G,L]

# B. curl= with fake https:// or http:// encoding
RewriteCond %{REQUEST_URI} ^/ubbthreads/ubbthreads\.php$ [NC]
RewriteCond %{QUERY_STRING} curl=https?3A2F2F [NC]
RewriteRule ^ - [G,L]

# C. curl= is an absolute http(s) URL that is not stovebolt.com
RewriteCond %{REQUEST_URI} ^/ubbthreads/ubbthreads\.php$ [NC]
RewriteCond %{QUERY_STRING} curl=https?:// [NC]
RewriteCond %{QUERY_STRING} !curl=https?://(www\.)?stovebolt\.com [NC]
RewriteRule ^ - [G,L]

# D. curl= starts with a hostname and no scheme
RewriteCond %{REQUEST_URI} ^/ubbthreads/ubbthreads\.php$ [NC]
RewriteCond %{QUERY_STRING} (^|&)curl=([a-z0-9-]+\.)+[a-z]{2,} [NC]
RewriteCond %{QUERY_STRING} !curl=(https?://)?(www\.)?stovebolt\.com [NC]
RewriteRule ^ - [G,L]

# E. curl=// not pointing at this host
RewriteCond %{REQUEST_URI} ^/ubbthreads/ubbthreads\.php$ [NC]
RewriteCond %{QUERY_STRING} (^|&)curl=// [NC]
RewriteCond %{QUERY_STRING} !curl=//(www\.)?stovebolt\.com(/|&|$) [NC]
RewriteRule ^ - [G,L]

Hopefully, this will stop some of the attacks. At a minimum it will remove these urls from Google.


The Stovebolt Geek
https://www.stovebolt.com/ubbthreads/ubbthreads.php

Server Information
UBB.threads Version 8.0.0
Release 20240826
Server OS Linux
Server Load 0.11
Web Server Apache/2.4.37
PHP Version 8.3.11
MYSQL Version 8.0.39
Database Size 1.82 GB