Some updates on the pollution spammers

Monday Sep 19 2005

Fuck spammersEarlier I wrote about a link spammer who seemed to be targeting me by sending out with links to my website (this particular article). After some emails between me and Ann Elisabeth, a.k.a. SpamHuntress it seems this spammer is not targeting me personally but engaging in a general attempt to pollute centralized anti spam blacklists. At least I can't think of any other purpose.

Dark Matter Pro: a premium photoblog template.

Affiliate program available

Affected sites


I've found at least two other sites that have been affected by this new type of :

Both posted a comment below this article on SpamHuntress.com which is how I found out about them. These sites and my site are completely unrelated which is why it led Ann Elisabeth to believe this is some sort of general attempt to pollute and disturb our tools to prevent comment spam.

What you can do to help


First of all, DON'T my site and/or the other sites affected by this idiot. The owners of these sites have nothing to do with the spam. Also, if people start blacklisting legitimate sites such as mine and the ones listed above the spammers will have won already and our lists will be polluted. Secondly, if you find any spam on your weblog that looks like it's part of this pollution run, let me know about the IP from which the spam originated. I will try to use this information to get behind the identity of this spammer and expose him (or them) to the world.

How to prevent this kind of spam


This new emerging kind of 'pollution spam' shows that centralized blacklists with domains to block are a dead end, simply because the spammers are starting to pullute them, rendering them useless. In my own anti-spam package for Pivot, Pivot-Blacklist, a centralized blacklist is used as a last resort. 99,9% of all spam attempts on my websites get blocked before the blacklist gets used at all. Automated spam can easily be blocked (for now) by applying one of the following techniques:
  • Hashcash: A javascript solution by Elliott Back. Available for WordPress and added to Pivot-Blacklist by me.
  • Use Captcha's (visual confirmation, plugins available for various blogs)
  • Use Owen's Spam Action (adds a special field to your comment form to fool automated spam bots. Available for various blogs)
  • Use other types of 'turing tests' to distinguish humans from spambots. The question you have to answer in my comment forms is an example of such a test

If you use one of these techniques you'll easily block automated commentspam even if it contains sites that aren't (and shouldn't be) blacklisted on any centralized blacklist.

Update


Things are getting worse. Remember when I found the first occurence of spam pointing to my site on matrixsynth.com? On this website I found the same type of spam linking to... matrixsynth.com! I posted a comment below this spam infected entry there telling them about the spam. At the moment of this writing the spam is still in place on the page.

There's a serious problem emerging in the blogosphere which is going to be here to stay as long as people don't install proper anti-spam tools that prevent ANY automated commentspam and not just commentspam that happens to be triggered by a (centralized) blacklist.

Some extra tags: , , .

Affected sites by this spam run identified by me so far




Some useful resources:

Also check out This article on SEOBlackhat.com.

small update: I just noticed this article is being linked from several link digests all of a sudden. Very nice! So while you're reading this anyway, take a look at my view on centralized blacklists and other current anti-spam techniques.
bookmarking

Commentary

Join the discussion! Leave a comment through the comment form below!

Got something to add to this?

Feel free to leave a comment on this site. You can use Textile and Emoticons. Your email address is only used to show a gravatar. Please stay on-topic and use common decency. Spammers will be shot in front of a live studio audience.

If you plan on posting code, use pastebin please and post a URL to the code. The comment processing doesn't deal very well with code. Sorry for the inconvenience.

Human comment spammers: don't bother posting your crap here. Comments are moderated and I won't let any of your shit through.

Remember personal info?
Yes
No

Trackbacks

If you have an interesting related post on your own site you can leave a trackback. As they say: 'a little AJAX a day keeps the spammers away' which is why you'll have to click below to generate a trackback key. The key will be valid for 15 minutes and can be used only once.

Pollution Spam unterwandert zentrale Anti-Spam-Listen
Vor ein paar Wochen hatte ich noch geschrieben, dass ich mit der Spam-Abwehr von b2evolution ganz zufrieden sei. Die zentrale Blacklist ersparte mir jede Menge Müll. Seit ein paar Tagen bekomme ich jedoch Kommentar-Spam, gegen den diese zentrale Blackl…Sent on 26 September '05 - 14:49 , via textformer Weblog
New version of spam
Oh joy, there’s a new version of blog spam that’s been hitting me lately: pollution spam. I deleted some spam and tracked it around legit looking blogs and found what Marco wrote and why they think this is happening. I…Sent on 08 October '05 - 04:36 , via Jim's Blog

 

  • Featured Links
RockySomewhere near the Orion NebulaBookalicio.usGolden Gate BridgeThames River BankJackie and mePimpin' it