<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
   <channel>
      <title>Making Light :: Smokin&apos; spam :: comments</title>
      <link>http://nielsenhayden.com/makinglight/archives/005920.html#comments </link>
      <description>Language, fraud, folly, truth, history, and knitting. Et cetera.</description>
      <language>en</language>
      <lastBuildDate>Tue, 08 Jan 2008 20:22:43 -0500</lastBuildDate>
      <generator>http://www.sixapart.com/movabletype/?v=4.261</generator>
      
      <item>
      <title>Smokin' spam</title>
      <description>We've been hit hard by comment spam this weekend. I'm talking 480 spams in ten minutes on Saturday morning. None...</description>
      <content:encoded>We've been hit hard by comment spam this weekend. I'm talking 480 spams in ten minutes on Saturday morning. None...</content:encoded>
      <link>http://nielsenhayden.com/makinglight/archives/005920.html</link>
      </item>

      
      <item>
         <title>Smokin&apos; spam -- comment #1 from iJames</title>
         <description>comment from iJames on 12.Dec.04</description>
         <content:encoded><![CDATA[<p>Hi.  Long-time listener, first-time caller.</p>

<p>I'm curious, in the context of "consider upgrading to these fine, fine software products," does anyone have any thoughts or experiences on the relative spam-killing merits of Movable Type vs. WordPress?  I have <i>got</i> to get off of Blogspot, but have not yet made up my mind on which tool to use.  </p>

<p>Advance thanks for thoughts, rants, &tc.<br />
</p>]]>
	 &lt;p&gt;Posted December 12, 2004 11:52 PM by iJames&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70532</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70532</guid>
         <pubDate>Sun, 12 Dec 2004 23:52:35 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #2 from pericat</title>
         <description>comment from pericat on 12.Dec.04</description>
         <content:encoded><![CDATA[<p>My latest comment spam hit was the week before last, and involved a whole lot of tacky URLs with no attempt at content. The wave before that one, perhaps two weeks prior, included content that would have been flattering had it been genuine, and attempted to munge its gambling promo URL info by using numeric HTML entities.</p>

<p>I think that since MT Blacklist uses regex matching, that sort of thing would be transparent to you as it would spot such a comment as spam without your doing anything special.</p>

<p>From my logs, it seems like waves of comment spam are preceded by a day or so's logjam of dubious referrers and robot-like leafing through all possible URLs at my site. I set up an .htaccess file to deny access to any request where the referrer (not the actual user's PC's name) was a .info or .biz domain. This has eased my worries, but YMMV.</p>]]>
	 &lt;p&gt;Posted December 12, 2004 11:58 PM by pericat&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70533</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70533</guid>
         <pubDate>Sun, 12 Dec 2004 23:58:54 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #3 from pericat</title>
         <description>comment from pericat on 13.Dec.04</description>
         <content:encoded><![CDATA[<p>iJames, both MT and Wordpress can be configured to handle spam; if you use MT, MT Blacklist is da bomb, if you use WP, there are several plugin options that you can use, depending on how you want to approach the problem. They're both fine blogging systems.</p>]]>
	 &lt;p&gt;Posted December 13, 2004 12:12 AM by pericat&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70536</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70536</guid>
         <pubDate>Mon, 13 Dec 2004 00:12:19 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #4 from Steve</title>
         <description>comment from Steve on 13.Dec.04</description>
         <content:encoded><![CDATA[<p>Yep, I left town Friday night and was offline until Sunday morning when I opened my mail reader to the relatively slow grind of almost 1300 Blacklist holds...all from the same spammer.</p>

<p>It was fairly painless to get clean up while making a couple phone calls.</p>]]>
	 &lt;p&gt;Posted December 13, 2004  1:15 AM by Steve&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70546</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70546</guid>
         <pubDate>Mon, 13 Dec 2004 01:15:53 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #5 from Linkmeister</title>
         <description>comment from Linkmeister on 13.Dec.04</description>
         <content:encoded><![CDATA[<p>I got hammered on 12/5 but have only had about 25 on the 11th and 12th.  The Hawai'i Metroblogging site has had a few get through this weekend.</p>]]>
	 &lt;p&gt;Posted December 13, 2004  1:26 AM by Linkmeister&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70548</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70548</guid>
         <pubDate>Mon, 13 Dec 2004 01:26:12 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #6 from Richard Cobbett</title>
         <description>comment from Richard Cobbett on 13.Dec.04</description>
         <content:encoded><![CDATA[<p>I'm getting hammered on my Drupal powered site at the moment, along with a lot of other people. I've got the spam filter eating almost all of it automatically, but it's a real pain - my referrals list is unusable due to hundreds of fake links, while I often get more comment spams in a single day than my site's ever had comments.</p>

<p>What really annoys me is that it's quite blatantly the SAME GUY every time, cycling through random IP addresses in an attempt to use a bottom-feeding advertising method that my site blocks at the door anyway. Ngggh!</p>]]>
	 &lt;p&gt;Posted December 13, 2004  4:52 AM by Richard Cobbett&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70556</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70556</guid>
         <pubDate>Mon, 13 Dec 2004 04:52:20 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #7 from David Weman</title>
         <description>comment from David Weman on 13.Dec.04</description>
         <content:encoded><![CDATA[<p>Sadly, No! is down because of a massive spam attack. </p>]]>
	 &lt;p&gt;Posted December 13, 2004  6:39 AM by David Weman&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70559</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70559</guid>
         <pubDate>Mon, 13 Dec 2004 06:39:46 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #8 from John Scalzi</title>
         <description>comment from John Scalzi on 13.Dec.04</description>
         <content:encoded><![CDATA[<p>Lots of spam this weekend, easily expunged, however. I need up fire up the blacklist on my MT, but that requires begging from my techie friend who set up my MT in the first place.<br />
</p>]]>
	 &lt;p&gt;Posted December 13, 2004  8:46 AM by John Scalzi&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70565</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70565</guid>
         <pubDate>Mon, 13 Dec 2004 08:46:13 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #9 from Zed</title>
         <description>comment from Zed on 13.Dec.04</description>
         <content:encoded><![CDATA[<p>I'm still on MT 2.661. MT-Blacklist blocked seven pieces of comment spam last night; six got through. Between MT-Blacklist and having a <a href="http://web.archive.org/web/20040202085839/http://cheerleader.yoz.com/archives/000849.html" rel="nofollow">heavily modified comments configuration</a>, that's more than I've seen in a long time.</p>

<p>But it's still too many... if the spammers have bots that are smart enough to have anticipated all my mods and figure out how to automate spamming me, that leaves MT-Blacklist as my only defense, and my protection is only as good as my latest blacklist.</p>

<p>Time for more complications...<br />
</p>]]>
	 &lt;p&gt;Posted December 13, 2004  1:50 PM by Zed&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70583</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70583</guid>
         <pubDate>Mon, 13 Dec 2004 13:50:20 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #10 from Mitch Wagner</title>
         <description>comment from Mitch Wagner on 13.Dec.04</description>
         <content:encoded><![CDATA[<p>No unusual spam traffic here over the weekend. </p>

<p>I get a dozen to a hundred spam attempts every day. Since I installed MT 3.1x/MT-Blackist 2.x about six weeks ago, the software has only failed to block one (1) comment spam attempt, out of all the hundreds or thousands I've received. And it's blocked no legitimate comments. </p>]]>
	 &lt;p&gt;Posted December 13, 2004  2:32 PM by Mitch Wagner&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70585</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70585</guid>
         <pubDate>Mon, 13 Dec 2004 14:32:03 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #11 from Daniel H. Alvarez</title>
         <description>comment from Daniel H. Alvarez on 13.Dec.04</description>
         <content:encoded><![CDATA[<p>Is it just me, or is the comment/site spammer methodology counterproductive?  Really, what is the point?  When I have seen the spam get through on various sites that I visit, all it has done to me is annoy the hell out of me while I scroll past the spam as quickly as possible, looking for the real comments. </p>

<p>Or is that the point?</p>]]>
	 &lt;p&gt;Posted December 13, 2004  7:14 PM by Daniel H. Alvarez&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70599</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70599</guid>
         <pubDate>Mon, 13 Dec 2004 19:14:47 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #12 from Steve Taylor</title>
         <description>comment from Steve Taylor on 13.Dec.04</description>
         <content:encoded><![CDATA[<p>Daniel Alvarez writes:</p>

<p>> Is it just me, or is the comment/site spammer methodology counterproductive? Really, what is the point? </p>

<p>I've been told that the spam is not for humans, but for Google. Google builds it's page ranking system partly by seeing how many different sites point to a given page, on the theory that the more sites that have a link to a page, the more interesting the page must be.</p>

<p>This theory used to be reasonably true, before people started playing games like this to artificially boost their page rankings.</p>]]>
	 &lt;p&gt;Posted December 13, 2004  8:02 PM by Steve Taylor&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70601</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70601</guid>
         <pubDate>Mon, 13 Dec 2004 20:02:27 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #13 from katster</title>
         <description>comment from katster on 14.Dec.04</description>
         <content:encoded><![CDATA[<p>I've been rather impressed at what closing all but the last ten days or so of posts has done.  Between that and changing the comments link so it isn't mt-comment.cgi anymore, I haven't seen a spam for days.  This is, as you can imagine, is nice, especially since I'm the one doing all the spam deletions.</p>

<p>Of course, I'm still on MT 2.64 because I don't have the money to upgrade to the newer version.  Mebbe when I'm no longer a student, I'll do that, since people seem to like MT3.</p>

<p>Zed: I'm going to keep your list of tips around so that if I have to do more than renaming the comment script, I've got a URL handy with tips for implementing them.</p>

<p>-kat</p>]]>
	 &lt;p&gt;Posted December 14, 2004 12:41 AM by katster&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70611</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70611</guid>
         <pubDate>Tue, 14 Dec 2004 00:41:26 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #14 from Chloe</title>
         <description>comment from Chloe on 14.Dec.04</description>
         <content:encoded><![CDATA[<p>My question may be veering off the post question...<br />
But has anyone else noticed on their blogs that spam tends to hit certain posts particularly, repeatedly?</p>

<p>For example, when the spam got to be at its worst, I noticed that it was the same few posts, in 2 different blogs, that were always getting hit. <br />
And I have been unable to determine a common denominator between those posts.</p>

<p>No one has seemed to have an answer as to why those particular posts were the targets all the time. </p>

<p>Or is it really just a coincidence that they always hit those posts?</p>]]>
	 &lt;p&gt;Posted December 14, 2004 11:00 AM by Chloe&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70647</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70647</guid>
         <pubDate>Tue, 14 Dec 2004 11:00:55 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #15 from iJames</title>
         <description>comment from iJames on 14.Dec.04</description>
         <content:encoded><![CDATA[<p>Much thanks to those who responded to my question, both here and on my blog.  (Yes, it's a work of fiction.  But the dilemma between WP and MT is not.)</p>

<p>Another question, hopefully only marginally more annoying than the first one: I notice that, in talking about spam solutions here, the universal consensus seems to be blacklisting and moderating comment attempts.  I'm impressed that it's so effective, but as a way to reduce moderation work, has anyone considered placing hurdles <b>before</b> the comment posting?  Are there sound practical reasons against it?</p>

<p>I'm not talking about requiring user logins or authenticating via e-mail.  Those sound like too much work for the casual commenter.  But what about one of those "read this non-OCR-able swirly text and type in what it says" challenges?  Would something like that turn off an average reader from commenting?  Or putting a time interval between allowed comments?</p>

<p>I know that such plug-ins exist for WordPress, because I stumbled across them, and I'm sure they must exist for Movable Type.  Do people not use them primarily because MT-Blacklist does the job?  Or because they're perceived as too much hassle for the user?</p>]]>
	 &lt;p&gt;Posted December 14, 2004 12:40 PM by iJames&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70668</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70668</guid>
         <pubDate>Tue, 14 Dec 2004 12:40:37 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #16 from Chloe</title>
         <description>comment from Chloe on 14.Dec.04</description>
         <content:encoded><![CDATA[<p>iJames:  </p>

<p>I don't know about those swirly graphics things...  But for me that would be a last resort implementation, because quite frankly, I find them very annoying on other people's comments.  I don't want to make it harder for real people to post real comments.  </p>

<p>However, on my own blog, I did implement some kind of "pre-posting" kind of thing.  I really can't explain what it is, except it involves a hidden field.  A friend directed me to some blog where the instructions for adding it to the form/cgi was in a post.  </p>

<p>Immediately after adding this hidden field, I stopped getting spam comments.  But I was warned it could be a coincidence.</p>

<p>Then, less than a week later, I installed mt-blacklist.</p>

<p>For some months, I used to get spam comments every week, usually about 5-10 in a week, usually over the course of 1-2 days, across 2 blogs and about 5 blog posts.</p>

<p>After installing those 2 protection measures a few weeks ago, I've gotten a grand total of ONE spam comment that slipped through mt-blacklist.  And also, a grand total of ONE spam comment that mt-blacklist took care of & prevented from posting, according to my activity log.</p>

<p>That's 2 spam comments that I know of over about 3 weeks, when I normally would've gotten about 30 in that time.</p>

<p>So I'm convinced now that the hidden field thing is what's fending off the bulk of spam comments.</p>

<p>But I'm no expert.  And of course it could be a coincidence that maybe it just so happens in the past 3 weeks, I would've only gotten 2 spam comments without either of those measures.</p>

<p>(I'm sorry, but I didn't keep the URL to the blog/post that explained that hidden field thing - but I can ask the person who gave me the link, if someone can't find it - I believe the blog is a popular one if that helps.)</p>]]>
	 &lt;p&gt;Posted December 14, 2004  3:59 PM by Chloe&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70701</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70701</guid>
         <pubDate>Tue, 14 Dec 2004 15:59:04 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #17 from OG</title>
         <description>comment from OG on 14.Dec.04</description>
         <content:encoded><![CDATA[<p>Chloe:</p>

<p>Sounds like recommendation #1 on Blogspam.</p>

<p>It's fairly simple to circumvent, but comment spammers don't seem to have gone to the trouble yet.</p>]]>
	 &lt;p&gt;Posted December 14, 2004  4:25 PM by OG&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70704</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70704</guid>
         <pubDate>Tue, 14 Dec 2004 16:25:02 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #18 from Chloe</title>
         <description>comment from Chloe on 14.Dec.04</description>
         <content:encoded><![CDATA[<p>Yes, I went & looked... and Blogspam got it from where I was sent for it:</p>

<p><a href="http://weblog.burningbird.net/archives/2002/10/29/comment-spam-quick-fix" rel="nofollow">burningbird</a></p>

<p>The first time I went there I just quick got the info and left...  Didn't realize the info was that old.  2 years.</p>

<p>If spammers haven't gone through the trouble yet, after 2 years, one wonders why...  ?  </p>

<p>I've never gotten hit with hundreds of spam at once.  Even the days I would get hit, it would be 3-4 within a few hours, but not all exactly at the same time.</p>

<p>What I thought was interesting is this..<br />
My friend just transferred his blog to WordPress, and he had 1,000 posts...  Hadn't linked the new blog anywhere yet.  And in one day, he got comment spam on every post.<br />
Now how does something like that happen?</p>

<p>When I asked people why certain posts of mine, in particular, were getting hit, and others not...  Some people suggested it was the way the spammers were finding those posts.  <br />
But if someone hadn't even linked their blog yet and they got hit...  I'm wondering how.  I'm assuming that the bots scan for WordPress comments file name on the system.<br />
But I know that's not the problem with my MT - because I don't have specific comments pages - my comments are ONLY listed in the individual archive page.  So there's nothing with the comments.cgi file in the URL for bots to find.</p>

<p>So how do they find me?  It doesn't seem to explain that anywhere.</p>]]>
	 &lt;p&gt;Posted December 14, 2004  7:02 PM by Chloe&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70723</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70723</guid>
         <pubDate>Tue, 14 Dec 2004 19:02:38 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #19 from antukin</title>
         <description>comment from antukin on 15.Dec.04</description>
         <content:encoded><![CDATA[<p>Steve Taylor writes:<br />
<i><blockquote>I've been told that the spam is not for humans, but for Google. Google builds it's page ranking system partly by seeing how many different sites point to a given page, on the theory that the more sites that have a link to a page, the more interesting the page must be.</blockquote></i></p>

<p>However, a quick look at <a href="http://www.google.com/technology/" rel="nofollow">Google</a> explains that 'But, Google looks at more than the sheer volume of votes, or links a page receives; it also analyzes the page that casts the vote. Votes cast by pages that are themselves "important" weigh more heavily and help to make other pages "important."'</p>

<p>So in short, spam is doubly useless. Grrrrr.</p>]]>
	 &lt;p&gt;Posted December 15, 2004 12:52 AM by antukin&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70737</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70737</guid>
         <pubDate>Wed, 15 Dec 2004 00:52:54 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #20 from John Emerson</title>
         <description>comment from John Emerson on 15.Dec.04</description>
         <content:encoded><![CDATA[<p>Comment spam is a sign that you're popular. Sort of like being a movie star. Suck it up and deal with it, guys. On my sites we're begging for that kind of attention.</p>]]>
	 &lt;p&gt;Posted December 15, 2004  8:07 AM by John Emerson&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70757</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70757</guid>
         <pubDate>Wed, 15 Dec 2004 08:07:11 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #21 from Teresa Nielsen Hayden</title>
         <description>comment from Teresa Nielsen Hayden on 15.Dec.04</description>
         <content:encoded><![CDATA[<p>Beg to differ, John. Moribund sites get spammed too.</p>]]>
	 &lt;p&gt;Posted December 15, 2004  8:50 AM by Teresa Nielsen Hayden&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70758</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70758</guid>
         <pubDate>Wed, 15 Dec 2004 08:50:30 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #22 from Chloe</title>
         <description>comment from Chloe on 15.Dec.04</description>
         <content:encoded><![CDATA[<p>Well, in light of Google's ranking system...  Then I should be getting hammered with spam.  I show up ridiculously high in google-ranking.  I say ridiculously high because my site's not actually particularly popular or anything - but I come up on the first page for a lot of what I'd consider rather common search terms.<br />
And my friend with the WordPress blog who got hammered in one day...  he's not an a-list blogger, the victim blog wasn't even linked yet never mind not in google's index.</p>

<p>So that's not an adequate argument, I think.</p>

<p>Just like e-mail spam doesn't specifically target people, I don't think comment spam is particularly targeted either.  It's all about the numbers.  More bait, more bites.  That's all.</p>]]>
	 &lt;p&gt;Posted December 15, 2004  1:04 PM by Chloe&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70779</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70779</guid>
         <pubDate>Wed, 15 Dec 2004 13:04:29 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #23 from John Emerson</title>
         <description>comment from John Emerson on 15.Dec.04</description>
         <content:encoded><![CDATA[<p>Hmph. Well, they're boycotting me.</p>]]>
	 &lt;p&gt;Posted December 15, 2004  6:20 PM by John Emerson&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70800</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70800</guid>
         <pubDate>Wed, 15 Dec 2004 18:20:40 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #24 from Richard Cobbett</title>
         <description>comment from Richard Cobbett on 16.Dec.04</description>
         <content:encoded><![CDATA[<p>"Just like e-mail spam doesn't specifically target people, I don't think comment spam is particularly targeted either. It's all about the numbers."</p>

<p>It just looks for the comment posting scripts, it doesn't care who you are. Once the idiots have found yours, they keep bombarding it - I get loads of folks trying to post spam to my WordPress powered blog, despite the fact that I deleted all the files and replaced it with Drupal aeons ago.</p>]]>
	 &lt;p&gt;Posted December 16, 2004  4:54 AM by Richard Cobbett&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70825</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70825</guid>
         <pubDate>Thu, 16 Dec 2004 04:54:37 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #25 from Dorothea Salo</title>
         <description>comment from Dorothea Salo on 16.Dec.04</description>
         <content:encoded><![CDATA[<p>Chloe, the WordPress problem happens because spammers bypass the comment forms and insert their spam directly into the database underlying the weblog, including to post numbers for posts that haven't been written yet! When the post *is* written, the spam poofs into existence.</p>

<p>Security hole in the program, basically. The easiest (and I say this with some trepidation) fix is going into the database via phpmyadmin (a web-based MySQL database manager) and doing a mass comment delete from there.</p>

<p>I'm not sure whether the just-released WP 1.2.2 fixes this issue. It very well might.</p>

<p>Anyway, I don't even enable comments on my weblog and I still get spam -- referer spam. (Misspelling not of my making.) The Reffy boys are particularly good at trying to suck my bandwidth for no reason; check your server logs for adminshop or xopy.</p>]]>
	 &lt;p&gt;Posted December 16, 2004 12:48 PM by Dorothea Salo&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70852</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70852</guid>
         <pubDate>Thu, 16 Dec 2004 12:48:42 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #26 from Seth Breidbart</title>
         <description>comment from Seth Breidbart on 16.Dec.04</description>
         <content:encoded><![CDATA[<p>I'm getting some really interesting ideas about what to do when I finally get around to setting up a blog.</p>

<p>It helps that I have a colo box that's currently sitting on an otherwise-abandoned 100Mbps line, with no bandwidth charges.</p>

<p>(Insert updated version of the Mark Twain line about not picking fights with people who buy ink by the barrel.)</p>

<p>Technical point: the comment spammers look for files with a particular name (the script used for posting comments).  If they find it, they feed it a "POST" command with their spam.  Now if somebody were to write a script that took whatever it was sent, and forwarded that along with some explanation ("This was generated by an unlinked script, apparently by a comment spammer, running from IP address XXX") to the appropriate abuse address for the spammer's ISP, and give it a name the spammers look for, . . .<br />
</p>]]>
	 &lt;p&gt;Posted December 16, 2004  4:15 PM by Seth Breidbart&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70865</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70865</guid>
         <pubDate>Thu, 16 Dec 2004 16:15:49 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #27 from Chloe</title>
         <description>comment from Chloe on 17.Dec.04</description>
         <content:encoded><![CDATA[<p>Well, I did get hit today with the massive spam thing.<br />
Started with the very first post.  I think it's going to try to spam every post.</p>

<p>I was on-line at the time and get e-mail notification, so I was able to blacklist & purge it after only 13 spams got posted.</p>

<p>I checked the MT-Blacklist master list, and the URL wasn't on there.  (I have updated my list from the master list a couple of times.)<br />
I sent the URL to be added, though I'm not sure if I did it right.  </p>

<p>I'm still curious as to the file name thing of the comment script.  My comment script is not available with that file name in it anywhere...  But can they get to it anyway?</p>]]>
	 &lt;p&gt;Posted December 17, 2004 12:09 AM by Chloe&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70881</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70881</guid>
         <pubDate>Fri, 17 Dec 2004 00:09:34 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #28 from Steve Eley</title>
         <description>comment from Steve Eley on 17.Dec.04</description>
         <content:encoded><![CDATA[<p>Seth Breidbart wrote:<br />
<i>Technical point: the comment spammers look for files with a particular name (the script used for posting comments). If they find it, they feed it a "POST" command with their spam.</i></p>

<p>Possibly stupid idea: if one were to rename that script file to something random, as well as a search-and-replace across the rest of the source code, might one be able to stop all comment spam at the head?</p>

<p>It might make upgrades and plug-ins a pain.  And I'm aware, of course, that anyone would be able to find the new script name anyway by looking at the HTML.  But if spammers go after the low-hanging fruit, this could possibly raise one's blog entirely above their heads.<br />
</p>]]>
	 &lt;p&gt;Posted December 17, 2004  9:37 AM by Steve Eley&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70896</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70896</guid>
         <pubDate>Fri, 17 Dec 2004 09:37:40 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #29 from pericat</title>
         <description>comment from pericat on 17.Dec.04</description>
         <content:encoded><![CDATA[<p><i>Possibly stupid idea: if one were to rename that script file to something random, as well as a search-and-replace across the rest of the source code, might one be able to stop all comment spam at the head?</i></p>

<p>Doing so helps, to a degree. It was one of Yoz's famous suggestions last year. But most of the spam bots look, not only for a given file name, but for the presence of certain fields and actions within any of the cgi or php files at a site. Some look also for the default phrases that appear just before the comment entry section (ex: "leave a comment", "html allowed", etc) to help them target a comment-enabled post.</p>]]>
	 &lt;p&gt;Posted December 17, 2004  1:38 PM by pericat&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70910</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70910</guid>
         <pubDate>Fri, 17 Dec 2004 13:38:00 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #30 from Seth Breidbart</title>
         <description>comment from Seth Breidbart on 17.Dec.04</description>
         <content:encoded><![CDATA[<p>If you really want to fight effectively, the thing to do would be to examine your logs to see what was requested "strangely": not following a link from your site (or a reasonable link from elsewhere).  The IP address requesting might also prove interesting; I don't know if comment spammers are using zombies the way email spammers are (yet).</p>

<p>Changing all the names around would make it a lot harder to find that you allow comments and figure out how to spam them.  If the changes were applied with a script, that could also be run against upgrades and plugins before applying them.</p>]]>
	 &lt;p&gt;Posted December 17, 2004  4:03 PM by Seth Breidbart&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#70924</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#70924</guid>
         <pubDate>Fri, 17 Dec 2004 16:03:57 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #31 from Paul</title>
         <description>comment from Paul on 18.Dec.04</description>
         <content:encoded><![CDATA[<p>Just posting to say that <a href="http://it.slashdot.org/article.pl?sid=04/12/18/1827225&from=rss" rel="nofollow">Slashdot has a story</a> running on MT comment spams at the moment. Various links, including to Six Apart recommendations for config changes.</p>

<p>ijames: the "captchas" - swirly text - are annoying for most people, particularly since the spammers seem to have solved the 'easier' ones (going from the fact Yahoo switched from the clear-ish ones to the current ones). I'm told they're also a right bugger if you've got sight problems.</p>]]>
	 &lt;p&gt;Posted December 18, 2004  9:26 PM by Paul&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#71022</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#71022</guid>
         <pubDate>Sat, 18 Dec 2004 21:26:12 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #32 from abi spots comment spam</title>
         <description>comment from abi spots comment spam on  2.Jan.07</description>
         <content:encoded><![CDATA[<p>Higgledy-piggledy,<br />
Mexico pharmacy<br />
Haplessly cluttering<br />
Comment threads here.</p>

<p>Hammedy-spammedy<br />
Certainly time for it<br />
Incontrovertibly<br />
To disappear.</p>]]>
	 &lt;p&gt;Posted January  2, 2007  4:20 PM by abi spots comment spam&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#163840</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#163840</guid>
         <pubDate>Tue, 02 Jan 2007 16:20:18 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #33 from David Goldfarb notes more spam</title>
         <description>comment from David Goldfarb notes more spam on  8.Jan.07</description>
         <content:encoded><![CDATA[<p>The URL doesn't even take you straight to gambling, just to a google search.  Sheesh.</p>]]>
	 &lt;p&gt;Posted January  8, 2007  3:11 AM by David Goldfarb notes more spam&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#164617</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#164617</guid>
         <pubDate>Mon, 08 Jan 2007 03:11:56 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #34 from Teresa Nielsen Hayden</title>
         <description>comment from Teresa Nielsen Hayden on  8.Jan.07</description>
         <content:encoded><![CDATA[<p>Thank you, thank you. Spams all gone. Bad spams!</p>]]>
	 &lt;p&gt;Posted January  8, 2007  7:25 AM by Teresa Nielsen Hayden&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#164628</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#164628</guid>
         <pubDate>Mon, 08 Jan 2007 07:25:51 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #35 from abi</title>
         <description>comment from abi on 13.Feb.07</description>
         <content:encoded><![CDATA[<p>Turning beyond right<br />
Angles, the message sits at<br />
Ninety eight degrees.</p>

<p>Or does it mean heat<br />
Just below the boiling point<br />
Time to make our teas?</p>

<p>But education<br />
Shouldn't be from comment spam<br />
So kill it off, please.<br />
</p>]]>
	 &lt;p&gt;Posted February 13, 2007  5:11 PM by abi&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#171686</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#171686</guid>
         <pubDate>Tue, 13 Feb 2007 17:11:05 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #36 from abi spots comment spam</title>
         <description>comment from abi spots comment spam on 13.Feb.07</description>
         <content:encoded><![CDATA[<p>Forgot to change my name to draw attention to the thread.</p>

<p>Kill kill kill the spam<br />
Delete Delete Delete it<br />
You know you want to.</p>]]>
	 &lt;p&gt;Posted February 13, 2007  5:23 PM by abi spots comment spam&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#171690</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#171690</guid>
         <pubDate>Tue, 13 Feb 2007 17:23:03 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #37 from ethan sees a spammy spammer leaving spam</title>
         <description>comment from ethan sees a spammy spammer leaving spam on 26.Mar.07</description>
         <content:encoded><![CDATA[<p>They sure do like this thread. Do they think they'll blend in?</p>]]>
	 &lt;p&gt;Posted March 26, 2007  2:27 AM by ethan sees a spammy spammer leaving spam&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#177846</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#177846</guid>
         <pubDate>Mon, 26 Mar 2007 02:27:51 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #38 from abi sees comment spam</title>
         <description>comment from abi sees comment spam on 24.May.07</description>
         <content:encoded><![CDATA[<p>Ironic how many times this thread gets spammed, isn't it?</p>]]>
	 &lt;p&gt;Posted May 24, 2007  5:29 AM by abi sees comment spam&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#188957</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#188957</guid>
         <pubDate>Thu, 24 May 2007 05:29:48 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #39 from .</title>
         <description>comment from . on 24.May.07</description>
         <content:encoded><![CDATA[<p>.</p>]]>
	 &lt;p&gt;Posted May 24, 2007  8:39 PM by .&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#189235</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#189235</guid>
         <pubDate>Thu, 24 May 2007 20:39:55 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #40 from .</title>
         <description>comment from . on 24.May.07</description>
         <content:encoded><![CDATA[<p>.</p>]]>
	 &lt;p&gt;Posted May 24, 2007  8:40 PM by .&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#189239</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#189239</guid>
         <pubDate>Thu, 24 May 2007 20:40:57 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #41 from Dawno sees double comment spam!</title>
         <description>comment from Dawno sees double comment spam! on 24.May.07</description>
         <content:encoded><![CDATA[<p>I hope I don't need new glasses.</p>]]>
	 &lt;p&gt;Posted May 24, 2007  8:51 PM by Dawno sees double comment spam!&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#189241</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#189241</guid>
         <pubDate>Thu, 24 May 2007 20:51:48 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #42 from Bill Higgins-- Beam Jockey spots another one to smoke</title>
         <description>comment from Bill Higgins-- Beam Jockey spots another one to smoke on 24.May.07</description>
         <content:encoded><![CDATA[<p>They just keep coming back for more, don't they?</p>]]>
	 &lt;p&gt;Posted May 24, 2007  8:52 PM by Bill Higgins-- Beam Jockey spots another one to smoke&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#189242</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#189242</guid>
         <pubDate>Thu, 24 May 2007 20:52:15 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #43 from .</title>
         <description>comment from . on  3.Jan.08</description>
         <content:encoded><![CDATA[<p>.</p>]]>
	 &lt;p&gt;Posted January  3, 2008  9:02 PM by .&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#240360</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#240360</guid>
         <pubDate>Thu, 03 Jan 2008 21:02:23 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #44 from ethan sees spam, new and old</title>
         <description>comment from ethan sees spam, new and old on  3.Jan.08</description>
         <content:encoded><![CDATA[<p>New spam currently at #43, old spam still at #39 and 40.</p>]]>
	 &lt;p&gt;Posted January  3, 2008  9:09 PM by ethan sees spam, new and old&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#240362</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#240362</guid>
         <pubDate>Thu, 03 Jan 2008 21:09:08 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #45 from .</title>
         <description>comment from . on  8.Jan.08</description>
         <content:encoded><![CDATA[<p>.</p>]]>
	 &lt;p&gt;Posted January  8, 2008  7:27 PM by .&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#241410</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#241410</guid>
         <pubDate>Tue, 08 Jan 2008 19:27:12 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #46 from Fragano Ledgister observes spam</title>
         <description>comment from Fragano Ledgister observes spam on  8.Jan.08</description>
         <content:encoded><![CDATA[<p>Nonsense.</p>]]>
	 &lt;p&gt;Posted January  8, 2008  7:29 PM by Fragano Ledgister observes spam&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#241411</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#241411</guid>
         <pubDate>Tue, 08 Jan 2008 19:29:22 -0500</pubDate>
      </item>
      
      <item>
         <title>Smokin&apos; spam -- comment #47 from Teresa Nielsen Hayden</title>
         <description>comment from Teresa Nielsen Hayden on  8.Jan.08</description>
         <content:encoded><![CDATA[<p>I think I'm going to put an end to this thread's usefulness to them as a known location.</p>]]>
	 &lt;p&gt;Posted January  8, 2008  8:22 PM by Teresa Nielsen Hayden&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/005920.html#241417</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/005920.html#241417</guid>
         <pubDate>Tue, 08 Jan 2008 20:22:43 -0500</pubDate>
      </item>
      
   </channel>
</rss>