Tue, 01 Feb 2005

Another SPAM Attack

What a way to wake up! One thousand and thirty five new comments, all of them pushing a site called 'learntoplay.com' and selling everything from penis enlargements to poker chips and cheats. The bastards had figured out a way around my clever little entry hack.

Luckily (for me) I actually got to watch the attack in progress, and so discovered the hole in the script: it was trackbacks.

Blosxom treats trackbacks exactly like writebacks, only from a remote location. There is no chance to validate against anything in this situation, and if the spammer is clever and rotates (spoofs) his IP's, even blacklisting won't work. So, trackbacks are gone.

And just for good measure, I've changed the ID code necessary to enter a writeback - from seventeen seventy six to seventeen ninety three (from the Declaration of Independence to the start of the Reign of Terror in France). So be alert!

All I can say is that these spammers are bastards, and they're killing the Internet. They must be stopped: in email, on forums, in blogs, feeds and chatrooms. If we, the "good" users of the 'Net fail to stifle this proliferation of crap, then the whole net will devolve into a series of closely guarded private networks, and we'll have lost the best opportunity yet for reaching a truely global communication portal.

/Home | 2 writebacks | permanent link


On
Dave H wrote

Testing


On
orangeguru wrote


comment...

 
Notes: If you put a <mailto:> link in the URL field your address will not be mangled: this could be a bad idea as your email address could be easily harvested by bots designed for SPAM. The comments field should now format correctly for line feeds and carriage returns: when you hit the 'Enter' or 'Return' keys in your comment it should break to a new line. The text should wrap cleanly. Please let me know if it doesn't. No HTML tags will pass through - entering links seems to be the main cause of comment SPAM. Also, please be sure that Javascript is enabled in your browser before attempting to post a writeback. Sorry for any inconvenience, but this really helps cut down on the amount of comment SPAM I have to deal with.
 
 Name:
 URL:(optional)
 Title: (optional)
 Comments:  
Save my Name and URL/Email for next time