Burnt Orange Report


News, Politics, and Fun From Deep in the Heart of Texas







Support the TDP!





June 11, 2004

Spammer Alert

By Byron LaMasters

Upon checking the blog this morning, I realized that BOR just suffered the worst Spam attack ever. We had several hundred spam messages (246 to be exact) from this IP Address: 216.79.8.162

So, add that to your banned list. Making things more difficult was the number of websites that this spammer linked to. Usually they'll just plug in a few different links, so it's easy to kill them off by adding them into MT-Blacklist, but this guy was good. I got spam this morning from the following addresses:

allergyrelief.buy-rx-usa.com, sleepaids.buy-rx-usa.com, stomach-heartburn.buy-rx-usa.com, anti-anxiety.buy-rx-usa.com, anti-depression.buy-rx-usa.com, cholesterol.buy-rx-usa.com, musclerelaxers.buy-rx-usa.com, skincare.buy-rx-usa.com, antibiotic.buy-rx-usa.com, antiviral-herpes.buy-rx-usa.com, quitsmoking.buy-rx-usa.com, painremedies.buy-rx-usa.com, womenshealth.buy-rx-usa.com, menshealth.buy-rx-usa.com, weightloss.buy-rx-usa.com, zithromax.buy-rx-usa.com, zovirax.buy-rx-usa.com, zanaflex.buy-rx-usa.com, wellbutrinsr.buy-rx-usa.com, bupropion.buy-rx-usa.com, wellbutrin.buy-rx-usa.com, vaniqa.buy-rx-usa.com, sonata.buy-rx-usa.com, soma.buy-rx-usa.com, skelaxin.buy-rx-usa.com, fluoxetine.buy-rx-usa.com, propecia.buy-rx-usa.com, prilosec.buy-rx-usa.com, ortho-evra.buy-rx-usa.com, nasonex.buy-rx-usa.com, nasacort.buy-rx-usa.com, lipitor.buy-rx-usa.com, lexapro.buy-rx-usa.com, imitrex.buy-rx-usa.com, fosamax.buy-rx-usa.com, flexeril.buy-rx-usa.com, famvir.buy-rx-usa.com, butabitol.buy-rx-usa.com, fioricet.buy-rx-usa.com, cyclobenzaprine.buy-rx-usa.com, cipro.buy-rx-usa.com, celexa.buy-rx-usa.com, celebrex.buy-rx-usa.com, buspirone.buy-rx-usa.com, buspar.buy-rx-usa.com, aldara.buy-rx-usa.com, aciphex.buy-rx-usa.com, acyclovir.buy-rx-usa.com

Posted by Byron LaMasters at June 11, 2004 03:20 PM | TrackBack

Comments

I don't understand how this spamming blog thing works. I've read about it in the paper, but I didn't quite get it. Do they spam your site stats? Comments? I don't think myne blog has been hit--knock on wood. I hope it doesn't.

Beep!

Posted by: Ed at June 11, 2004 09:42 PM

Thanks for the lowdown. I updated my ban list just to be on the safe side.

Peace.

Posted by: James at June 12, 2004 01:29 AM

Comments.

Posted by: Byron L at June 12, 2004 01:57 AM

Ok, thanks. That makes sense.

Posted by: Byron L at June 12, 2004 01:29 PM

The ip addr approach is doomed, we're seeing mostly ad inserts from a few dsl-or-ip/cdn hosts featuring a few properties in bursts. Eventually we'll be seeing smooth rates of inserts for a variety of properties and from a variety of compromised throw-away attack nodes -- the same technical trajectory as spam-over-smtp as we're seeing for spam-over-http.

Shutting down the left-open entry upon some expiry timer (a feature MT lacks) limits another vulnerability.

more later.

Posted by: Eric at June 14, 2004 08:33 PM
Post a comment









Remember personal info?








June 2005
Sun Mon Tue Wed Thu Fri Sat
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30    


About Us
About/Contact
Advertising Policies

Donate

Tip Jar!



Archives
Recent Entries
Categories
BOR Edu.
BOR News
BOR Politics
Linked to BOR!
Polling
Texas Stuff
A Little Pollyana
Austin Bloggers
DFW Bogs
DMN Blog
In the Pink Texas
Inside the Texas Capitol
The Lasso
Pol State TX Archives
Quorum Report Daily Buzz
George Strong Political Analysis
Texas Law Blog
Texas Monthly
Texas Observer
TX Dem Blogs
TX GOP Blogs
Daily Reads
College Blogs
GLBT Blogs
More Reads
BOR Webrings
Election Returns
Texas Media
World News



Powered by
Movable Type 3.15