Richy’s Random Ramblings

Random ramblings and ravings of Richy C

Blogging: Comment Spam

Like practically everybody else in the blogsphere at the moment, I’m suffering quite a bit of comment spam: I had to block my first IP address yesterday - and now I’m blocking the following 7 IP addresses:
209.210.176.19
209.210.176.20
209.210.176.21
209.210.176.22
209.210.176.23
80.50.117.113
64.109.143.166

What sort of spam have I been getting? Well, 80.50.117.113 from “klaus” was a Cheap Viagra, Vicodin, Xanax, Prescription Drugs, and Penis Enlargement Pills spam and 64.109.143.166 from “Alex Dolbayov” was for “Great Site Folks! I have another [?] big t-ts site for you which is really the #1 big t-ts site” (and that’s after I’ve implemented Neil’s change the comment cgi-bin script filename patch type thing) and all the rest were over a variety of posts advertising the same pedo orientated porn site which a number of others have been unfortunately hit with.

Patches I’m going to try include URLs including zipcode are prohibited, Avoid Comment Spam, Comment Spam Quick Fix and I’m certainly going to try Jay Allen’s MT-BlackList once it’s released (I’ve in fact had an email from Kadyellebee of MT-Plugins to let me that it’ll be included in the MT Plugins Manager as soon as it’s released!)

(I may also include the Avoid Duplicate Comments and use some of the advice from Seven quick tips for a spam-free blog) and Comment Queue Script/MT Hack).

Expect a few minor things to change around here once it’s all been implemented (oh, I’ve also installed the Trickle thingy so I can schedule “future blog entries”).

6 Responses to “Blogging: Comment Spam”

  1. David Says:

    Hey that psammer from 209.210.176.19 through 23 hit me hard yesterday too, despite the things I’d tried. Good to see that the same IPs hit you too, because that means that a shared blacklist for bloggers may actually work.

  2. Richy C. (of Richy's Random Ramblings) Says:

    A bit more information:

    Spammer 80.50.117.113 found my site on 11/Oct/2003 12:27:19GMT via the url http://www.buka.pl/linki2/index.php?show=urls using the browser “Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; Win 9x 4.90)” (probably faked) and landed on entry 118, but they did download a few graphics so it didn’t “look” like a bot - although it only took them 39 seconds from first visit to hitting the “Submit” button.

    Spammer 64.109.143.166 came directly to entry 91 at 12/Oct/2003 12:14:32 GMT without any referring information using the “Mozilla/4.0(compatible; MSIE 6.0; Windows NT 5.1)” browser and took just 7 seconds to hit the “Submit” button!

    The other comment spammer, however, came straight in via the IP address 209.210.176.33 and started hitting the submit button (with no browser information or referer information ) on 10/Oct/2003 09:08:42 GMT, then again from 209.210.176.21 on 11/Oct/2003 13:04:27 and 13:04:30 and then from 209.210.176.20 at 13:03:59 and 13:05:01 and again and again…

  3. Reflective Reality Says:

    Automated Comment SPAM Solution

    I now have a working captcha thanks to James Seng. I really don’t care how much of a pain it is on the accessibility front, the spammers have driven me to finding a working solution. The don’t allow comments from google searches hack also makes first t…

  4. jinjur.com -- Dear Diary Says:

    double grr

    The porn spam is apparently hitting almost everyone who runs

  5. Richy C. (of Richy's Random Ramblings) Says:

    It looks like Scott, Tim and Dave also got hit by the same spammers - but different IP ranges :(

  6. D Brown Says:

    I tried a different approach… the site is indeed blocked.

    From :
    “Svit Online Customer Services”
    To :
    “D Brown” <>
    Subject :
    Re: abuse of svitonline/ spam/ pron
    Date :
    Mon, 13 Oct 2003 08:54:08 +0300

    Site is blocked.

    Original Message
    From: “D Brown” <>
    To: ; ;
    Sent: Monday, October 13, 2003 3:34 AM
    Subject: abuse of svitonline/ spam/ pron

    > Dear Svitonline / Golden Telecom,
    >
    > A user of your service has been spamming ads for child pornography. This
    is
    > the website in question:
    >
    > http://www.is.svitonline.com/bagran/preteen/preteen.html
    > also
    > http://www.is.svitonline.com/bagran/lolita/lolita.html
    >
    > Please make this user stop spamming his porn site. I imagine it is a
    > violation of your Terms of Service. It is also very rude.
    >
    >
    > thanks,
    > David
    >
    > _________________________________________________________________
    > High-speed Internet access as low as $29.95/month (depending on the local
    > service providers in your area). Click here. https://broadband.msn.com
    >