February 1, 2005

trackback spam

zzzmkbhvg05.jpg
Aaaargh… just when I had com­ment spam pretty much bea­ten, along comes TRACKBACK SPAM.
This Royally Sucks!!!
Loic, is Six Apart doing anything about it? [Six Apart is the com­pany that makes Mova­ble Type, my current blog soft­ware.]
[UPDATE:] Damn, just got whac­ked again by the “Online Poker” boys… At this rate it’ll be a cou­ple of hun­dred whacks every 24 hours.
At least with MT 3.121 it’s easy to remove spam. Back when I had MT 2.65 it took fore­ver. God, it was awful. Almost switched to another plat­form (and I’m a uber-loyal MT user!). Sheesh.
I just hope in the long-term, spam doesn’t become MT’s “Kryp­to­nite Factor”.

23 Responses to “trackback spam”

  1. david says:

    it’s been hap­pe­ning on Word­Press blogs for a cou­ple of weeks now. Now cure in sight yet but I’m cros­sing my fingers.

  2. Unlike Ale­xan­der made some alte­ra­tions since the spam run in the begin­ning of January, it’s pos­si­ble to block him. Check your raw logs, and I’m sure you’ll spot how.

  3. hugh macleod says:

    Who is “Unlike Alexander”?

  4. jeff says:

    Hugh,
    Same thing just hap­pend to me, the same spam­mer switched from com­ment spam to track­back spam.
    I won­der if its the same online casino hit­ting you. And if so, I won­der if it’s more than just coin­cin­dince that we’re both in the mar­ke­ting space?

  5. hugh macleod says:

    Jeff, yeah, it was the “Online Poker” guys…

  6. Darryl says:

    Track­back spam is ugly. Basi­cally you can’t pro­tect from it other than con­tent fil­ters. That being said the con­tent fil­ters I’m using with word­press have been very effec­tive. There’s likely an equi­va­lent for mt I just don’t know what it is…

  7. Chris says:

    I’ve tur­ned off track­backs and am rel­ying on Tech­no­rati to find those folks lin­king back to me. You can use MTClose2 to close your old track­backs.
    It’s easy to hide email addres­ses. Just go through your tem­pla­tes and remove the MT author email address tags. The email will still be sent to you with the com­ment, but it won’t appear on your site. I did that a year ago, it’s a 10 minute pro­ject.
    Bet­ween clo­sing com­ments after 7 days and now clo­sing track­backs com­ple­tely I manage to avoid 99% of the problems.

  8. hugh macleod says:

    Yeah, Tech­no­rati works just as good as Track­backs, not to men­tion Blo­gli­nes for RSS… you really don’t need Track­backs, when you think about it.
    Yeah, maybe turin­ging off track­backs would be the ebst solution…

  9. Then there’s refe­rral spam, which only appears if you parse your logs, or dis­play raw refe­rrals.
    See http://idunno.org/misc/referralSpammers.aspx for a list of who has hit me.
    What I’ve noti­ced in only the past week is the learnhowtoplay.com and tecrep-inc.net spam­mers who set up nume­rous sub domains under their main sites, then hit me with all the sub domains in about an hour.
    Hos­ted in china, so not much use in com­plai­ning. I’m just going to have to rew­rite my fil­te­ring code to check wildcards.

  10. Robert Paterson says:

    I have got XXXXXXXXX and japa­nese XXXXXXX track­back spam. Apo­lo­gies to those who find it before I do

  11. Brian Eder says:

    I highly recom­mend upgra­ding to MT 3.15. Ins­tall Blac­klist 2.0 and the NoFo­llow plu­gin. I haven’t seen anything make it past this setup on 3 of my sites since I ins­ta­lled it a few weeks ago. This inc­lu­des Track­backs (ping attacks) and refe­rral spam (links in the emails). The Blac­klist log shows it’s the same spam dea­lin’ boys you’re spea­king of trying to get through daily, but no luck.
    Doesn’t seem right to com­pare MT and the Kryp­to­nite expe­rience in my hum­ble opi­nion. There’s infor­ma­tion pos­ted on MT’s site about how to fight this and they take a very proac­tive approach to making this the best tool avai­la­ble for all of us. The Nofo­llow plu­gin even crea­ted an ini­tia­tive with the big guns (Goo­gle, Yahoo and MSN) to ignore links with the nofo­llow attri­bute in order to help do away with refe­rral spam alto­gether.
    Kryp­to­nite igno­red the situa­tion. They kept trying to tell us all that their pro­duct was flaw­less even though we (the users) told them something’s wrong. They thought the pro­blem would just go away because they pre­ten­ded it didn’t exist. Ins­tead the users went away.
    MT see­med to jump on it pretty quick. I saw post after post coming through the Pro­Net list. They also put out a guide to figh­ting spam on their web­site — see news from January 04, 2005. Just feel the need to defend them. Their tools get me clo­ser to where I want to be… today.
    I hope you find this use­ful. I’m just a user, but a very happy one.
    Peace.
    Brian

  12. More track­back spam.

    It isn’t just me either. Hugh and Lau­ren Weins­tein are suf­fe­ring through it too. I use MTC­lo­se­Com­ments in con­junc­tion with MTBlac­klist on Mova­bleType to con­trol com­ment spam. While MTBlac­klist does an admi­ra­ble job with track­backs, I would love to be…

  13. hugh macleod says:

    Yes Brian, I agree with most of what you say.
    MT has been very good about com­ment spam… and cer­tainly, having Jay Allen now on board their team makes me feel a whole lot bet­ter.
    I sup­pose the main pro­blem I have with my curent MT pro­gram is you can only ban one IP at a time. So if your friendly neigh­borhood spam­mer posts a spam with a dif­fe­rent IP every time…
    567.56.789.121
    567.56.789.122
    567.56.789.123
    567.56.789.124
    567.56.789.125…
    It’s a nui­sance.
    That being said, if some­body wants to take away MT’s mar­ket share, all they have to do is build a bet­ter mou­se­trap, and it’ll be a disas­ter for the com­pany.
    Also, MT’s two big­gest com­pe­ti­tors are Goo­gle and Mic­ro­soft. MT doesn’t have the money to trhow at the pro­blem like the other two.
    I’m not saying MT is doing anything wrong… I’m just poin­ting out pote­ten­tial land mines.

  14. DJ Coffman says:

    On my word­press blog, it has the fil­ters that hold cer­tain words— when I check to see who’s pos­ting mass spams to my blog, they always use a ran­dom IP and a ran­dom e-mail, but MORE times than not, the first ini­tials in their fake e-mail will be the same… for ins­tance.. there was byob@eerbs then the second part would change. So I pop­ped byob in the fil­ter– and it finished him.
    These guys are in some sort of call cen­ter in the phi­lli­pi­nes by the way. I actually live trac­ked them while they were ente­ring my site using IPs from all over the world, but I could see exactly where their source was coming from. Dum­mies… So by matching the first entry into my site before the spam­ming hits, I can tell at least where they’re coming from. Find their key word intials that they most likely use to get paid and prove they spam­med– and you’ve bes­ted them.
    Its these call cen­ter type pla­ces that are REALLY doing damage in this regard. It’s not just one guy sit­ting around doing it automatically.

  15. Brian Eder says:

    Hugh, I unders­tand the desire for a bet­ter mou­se­trap… or at least one with self-loading cheese. I can’t ima­gine MT not just buil­ding in Jay Allen’s Blac­klist plu­gin from the start in the future. But for now, we’re gonna have to put the cheese in our­sel­ves. If you need a hand let me know. God knows we get so much from you.

  16. Anil Dash says:

    Hugh, thanks for the feed­back. We’re keenly aware of the Track­Back and com­ment spam issue, and I think we’re not facing a Kryp­to­nite issue because we’re com­mu­ni­ca­ting honestly and openly about it. And, to put things in pers­pec­tive, we’ve got the most expe­rien­ced and dedi­ca­ted folks in the com­ment spam fight on our team, which I think makes us world-class con­ten­ders in the battle. (Most Type­Pad users really don’t feel they have any spam issues at all with their blogs.)
    It might help to check out the post we put up about figh­ting Track­Back spam yes­ter­day:
    http://www.sixapart.com/pronet/2005/02/mod_security_fo.html
    Or to check out our Com­ment Spam Guide, which is almost 25 pages. We published it last month:
    http://sixapart.com/pronet/comment_spam.html
    I hope that addres­ses your con­cerns, and feel free to email if you’re still having problems.

  17. Thank God you brought this up. I’m get­ting the most dis­gus­ting, awful track­back spam. I use Type­pad (I’m not as advan­ced as most of the rest of you), and I have no idea how to deal with this! Who the hell are these rude bastards?

  18. Brian Eder says:

    Why am I sud­denly remin­ded of the Jack in the Box com­mer­cial where Jack counts the days until McDonald’s start making their bur­gers fresh?

  19. Nice blog ! This is my blogs urls las vegas hotels Direct url is http://las-vegas-hotel.idlcrutop.com/las_vegas_hotel_new_york.html or las vegas hotels Direct url is http://las-vegas-hotel.idlcrutop.com/cheap_hotel_vegas.html or las vegas hotels Direct url is http://las-vegas-hotel.zidl.com/hotel_rates_for_las_vegas.html or las vegas hotels Direct url is http://las-vegas-hotel.cigarette-cigarette-cheap.com/ventian_hotel_las_vegas.html or las vegas hotels Direct url is http://las-vegas-hotel.idlcrutop.com/hotel_in_las_vegas_nevada.html or las vegas hotels Direct url is http://las-vegas-hotel.zidl.com/las_vegas_hotel_discount.html or las vegas hotels Direct url is http://lasvegashotels.esmartdesign.com/rio_all_suites_hotel_las_vegas.html or las vegas hotels Direct url is http://las-vegas-hotel.idlcrutop.com/the_rio_hotel_in_las_vegas.html or las vegas hotels Direct url is http://las-vegas-hotel.zidl.com/suncoast_hotel_las_vegas.html or las vegas hotels Direct url is http://las-vegas-hotel.zidl.com/las_vegas_hotel_room.html or Nice blog ! This is my blogs urls las vegas hotels Direct url is http://las-vegas-hotel.zidl.com/rio_hotel_in_vegas.html or las vegas hotels Direct url is http://las-vegas-hotel.zidl.com/las_vegas_hotel_accomodations.html or las vegas hotels Direct url is http://lasvegashotels.esmartdesign.com/hotel_in_las_vegas_nevada.html or las vegas hotels Direct url is http://las-vegas-hotel.cigarette-cigarette-cheap.com/hard_rock_hotel_las_vegas.html or las vegas hotels Direct url is http://lasvegashotels.esmartdesign.com/orleans_hotel_and_casino_las_vegas.html or las vegas hotels Direct url is http://las-vegas-hotel.idlcrutop.com/excaliber_hotel_las_vegas.html or las vegas hotels Direct url is http://las-vegas-hotel.cigarette-cigarette-cheap.com/circus_hotel_las_vegas.html or las vegas hotels Direct url is http://las-vegas-hotel.idlcrutop.com/las_vegas_paris_hotel.html or las vegas hotels Direct url is http://lasvegashotels.esmartdesign.com/hotel_las_vegas_nv.html or las vegas hotels Direct url is http://las-vegas-hotels.newmail.ru/the_aladdin_hotel_las_vegas.html or.Thanks.