Funny About Spammers


I have a relatively minor spam problem on my MT blog. I'm having fun sharpening my claws on my spammers.


I recently did something that, although it may hinder some legitimate users, should at least frustrate my spammers.


My most prolific comment spammers has tried a few times, but his frequency isn't too often.


But one of the other comment spammers must have gotten tired of my musical chairs approach to frustrating him, and moved to trackback spam. Could be because the latest MT enables moderation of comments by default. Probably more likely than my actions alone influencing him.


Anyway, trackbacks are not yet possible to moderate as far as I know. I'd LOVE to learn how, if anyone knows?


But, I blocked this one too, and he's currently going crazy, trying IP numbers, trying to get through...


All but the top two are desperate attempts to get through during a period of 15 minutes. The top thwo did get through, and were entered quite far apart. Might have been tests, and since it took me a few hours to remove the first one, he may have stepped up the pace, I don't know.


Anyway, the IP numbers look like normal dynamic IP numbers to me. I wonder how that's done? I mean, just minutes apart?




More IP numbers:

Generally, that's done by using computers they managed to infect or compromise to later use for this type of spamming. So those numerous dynamic IP addresses you are seeing are likely people's home computers who aren't even aware their computer is being used for this purpose.


Most are relatively automated and rather persistant. I had one spammer this weekend attempt to spam my blog over 3,000 times from all kinds of IP's even though none of them ever made it to my blog.


The trackback's are starting to be used more for precisely the reason that it's harder to moderate them.

A bunch of us using EE got spam last night, I'd link to the entry on my site but it's mean. *winks* The spams all had random letter combos for title, body and URL, and all came froma different IP right to the first octet. I'm not sure if this is what you've got (trackback spam has been a problem for atleast a year, really) - but it appears to be a prelude to an attack on some sites: a testing of their script.


Hard to block too, since it's totally random. I turned off trackbacks on my site for the meantime. :dance:

It's Alexander, no doubt about it. I got the same pre-attack last night.


He's still going full tilt at my scripts. I wonder if it's his zombies that are out of control, since they don't understand what's happening when they try trackbacking to my site?


But I also got those same nonsense things a while ago, as comment spam, if I remember correctly.


Oh, and WTF?


I got an access to my log from server85.totalchoicehosting.com with the user agent MovableType/3.14. That site isn't even on here, my other site is. So I'm kinda curious now...

Of course there's a way to turn off trackbacks!


Just rename the trackback file until the attack is over. Not saying if that's what I did, but here's the file to rename:




BTW, either he's stopped for now, or my webhost filtered out the error message. He's done that before, so I wouldn't be surprised...

