<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Spambastards</title>
	<atom:link href="http://hill-kleerup.org/blog/2006/03/21/spambastards.html/feed" rel="self" type="application/rss+xml" />
	<link>http://hill-kleerup.org/blog/2006/03/21/spambastards.html</link>
	<description>News and Nattering ... What will the children think?</description>
	<lastBuildDate>Tue, 07 Sep 2010 20:42:52 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
	<item>
		<title>By: ***Dave</title>
		<link>http://hill-kleerup.org/blog/2006/03/21/spambastards.html/comment-page-1#comment-16490</link>
		<dc:creator>***Dave</dc:creator>
		<pubDate>Thu, 30 Mar 2006 02:47:32 +0000</pubDate>
		<guid isPermaLink="false">http://hill-kleerup.org/blog/wp/2006/03/21/spambastards.html#comment-16490</guid>
		<description>&lt;p&gt;Well, among other things I&#039;ve discovered has been a lot of &lt;a href=&quot;http://www.hill-kleerup.org/blog/2006/03/28/protecting_your.html&quot; rel=&quot;nofollow&quot;&gt;bandwidth theft&lt;/a&gt;.  And I&#039;ve been seeing a huge amount of hits to mt-tb.cgi since I&#039;ve been tracking it (and since it&#039;s been blocked, thus creating an error message).  The Autoban plugin has helped me see that a lot better.  :-)&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Well, among other things I&#8217;ve discovered has been a lot of <a href="http://www.hill-kleerup.org/blog/2006/03/28/protecting_your.html" rel="nofollow">bandwidth theft</a>.  And I&#8217;ve been seeing a huge amount of hits to mt-tb.cgi since I&#8217;ve been tracking it (and since it&#8217;s been blocked, thus creating an error message).  The Autoban plugin has helped me see that a lot better.  :-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Annoying Old Guy</title>
		<link>http://hill-kleerup.org/blog/2006/03/21/spambastards.html/comment-page-1#comment-16489</link>
		<dc:creator>Annoying Old Guy</dc:creator>
		<pubDate>Thu, 30 Mar 2006 02:14:15 +0000</pubDate>
		<guid isPermaLink="false">http://hill-kleerup.org/blog/wp/2006/03/21/spambastards.html#comment-16489</guid>
		<description>&lt;p&gt;If you&#039;re only getting order of 10 junk trackbacks per day, that&#039;s undetectable from the hosting company point of view. I doubt it would be noticeable at anything less than 1000 / day, if those are all getting junked (during one rush I was getting around 2000 / day and it didn&#039;t impact the server). Is there something else you think would be burdening the server? Keep in mind that junking a trackback is about as expensive as plotting one page in the MT interface, i.e. you burden the server as much every time you hit a link in the MT interface as a junked trackback does.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>If you&#8217;re only getting order of 10 junk trackbacks per day, that&#8217;s undetectable from the hosting company point of view. I doubt it would be noticeable at anything less than 1000 / day, if those are all getting junked (during one rush I was getting around 2000 / day and it didn&#8217;t impact the server). Is there something else you think would be burdening the server? Keep in mind that junking a trackback is about as expensive as plotting one page in the MT interface, i.e. you burden the server as much every time you hit a link in the MT interface as a junked trackback does.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ***Dave</title>
		<link>http://hill-kleerup.org/blog/2006/03/21/spambastards.html/comment-page-1#comment-16488</link>
		<dc:creator>***Dave</dc:creator>
		<pubDate>Mon, 27 Mar 2006 17:17:09 +0000</pubDate>
		<guid isPermaLink="false">http://hill-kleerup.org/blog/wp/2006/03/21/spambastards.html#comment-16488</guid>
		<description>&lt;p&gt;Hrm. Having to rename the script every day or two.  Not good.&lt;/p&gt;
&lt;p&gt;I&#039;m not having problems with junk stuff getting through (I&#039;m ending up with 5-15 junk TBs showing up in &quot;junk&quot; each day), it&#039;s the server burden that worries me.  I.e., that my hosting company is eventually going to take action more drastic than disabling my trackback script.&lt;/p&gt;
&lt;p&gt;I really hate this.  I hate having folks abusing the system preventing me from using something &lt;em&gt;I&lt;/em&gt; find useful.&lt;/p&gt;
&lt;p&gt;There&#039;s an interesting approach here for &lt;a href=&quot;http://underscorebleach.net/jotsheet/2005/02/prevent-movable-type-trackback-spam&quot; rel=&quot;nofollow&quot;&gt;renaming the TB script to something random&lt;/a&gt; on a chron-job-based schedule.  Unfortunately, it&#039;s about a year old, and the config structure in MT has changes since then, and I don&#039;t know nearly enough to screw around with the proposed solution to make it work with my installation.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Hrm. Having to rename the script every day or two.  Not good.</p>
<p>I&#8217;m not having problems with junk stuff getting through (I&#8217;m ending up with 5-15 junk TBs showing up in &#8220;junk&#8221; each day), it&#8217;s the server burden that worries me.  I.e., that my hosting company is eventually going to take action more drastic than disabling my trackback script.</p>
<p>I really hate this.  I hate having folks abusing the system preventing me from using something <em>I</em> find useful.</p>
<p>There&#8217;s an interesting approach here for <a href="http://underscorebleach.net/jotsheet/2005/02/prevent-movable-type-trackback-spam" rel="nofollow">renaming the TB script to something random</a> on a chron-job-based schedule.  Unfortunately, it&#8217;s about a year old, and the config structure in MT has changes since then, and I don&#8217;t know nearly enough to screw around with the proposed solution to make it work with my installation.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ***Dave</title>
		<link>http://hill-kleerup.org/blog/2006/03/21/spambastards.html/comment-page-1#comment-16487</link>
		<dc:creator>***Dave</dc:creator>
		<pubDate>Sun, 26 Mar 2006 05:39:15 +0000</pubDate>
		<guid isPermaLink="false">http://hill-kleerup.org/blog/wp/2006/03/21/spambastards.html#comment-16487</guid>
		<description>&lt;p&gt;When I initially installed AutoBan, I set it to a threshold of 1 and ended up with 6000-odd IP addresses banned.&lt;/p&gt;
&lt;p&gt;As you note, zombie addresses are a significant problem in tackling this issue.&lt;/p&gt;
&lt;p&gt;I&#039;ll have to take a look at that code.  I&#039;m usually reluctant to screw around with actual MT modules, but ...&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>When I initially installed AutoBan, I set it to a threshold of 1 and ended up with 6000-odd IP addresses banned.</p>
<p>As you note, zombie addresses are a significant problem in tackling this issue.</p>
<p>I&#8217;ll have to take a look at that code.  I&#8217;m usually reluctant to screw around with actual MT modules, but &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Annoying Old Guy</title>
		<link>http://hill-kleerup.org/blog/2006/03/21/spambastards.html/comment-page-1#comment-16486</link>
		<dc:creator>Annoying Old Guy</dc:creator>
		<pubDate>Sun, 26 Mar 2006 04:58:18 +0000</pubDate>
		<guid isPermaLink="false">http://hill-kleerup.org/blog/wp/2006/03/21/spambastards.html#comment-16486</guid>
		<description>&lt;p&gt;Hey, let me know if it helps you out. Typical numbers I have from my various weblogs are from 2,000 to 12,000 junk entries (I use a 60 day setting for culling junk). The largest set of unique addresses I have seen is around 7200, although around 6000 is more typical. I ran with a threshold of 1 for a while, but I think the default of 2 is actually better. It reduces the number of banned addresses to the 1000~2000 range but seems to be just as effective in blocking repeat offenders. Based on these results, I do not believe that the junkers are spoofing IP addresses but instead have access to zombie networks.&lt;/p&gt;
&lt;p&gt;If you really want to live on the edge, you could try &lt;a href=&quot;http://blog.thought-mesh.net/solidwallofcode/movable_type/mt_32_patch_tra.php&quot; rel=&quot;nofollow&quot;&gt;this&lt;/a&gt;. It changes the trackback interface in a way that makes it much harder for the junkers to guess URLs without interfering with legimate trackbacks. Plus, if you have individual archives, you can set up human computable trackback URLs. Still a bit experimental, however.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Hey, let me know if it helps you out. Typical numbers I have from my various weblogs are from 2,000 to 12,000 junk entries (I use a 60 day setting for culling junk). The largest set of unique addresses I have seen is around 7200, although around 6000 is more typical. I ran with a threshold of 1 for a while, but I think the default of 2 is actually better. It reduces the number of banned addresses to the 1000~2000 range but seems to be just as effective in blocking repeat offenders. Based on these results, I do not believe that the junkers are spoofing IP addresses but instead have access to zombie networks.</p>
<p>If you really want to live on the edge, you could try <a href="http://blog.thought-mesh.net/solidwallofcode/movable_type/mt_32_patch_tra.php" rel="nofollow">this</a>. It changes the trackback interface in a way that makes it much harder for the junkers to guess URLs without interfering with legimate trackbacks. Plus, if you have individual archives, you can set up human computable trackback URLs. Still a bit experimental, however.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ***Dave</title>
		<link>http://hill-kleerup.org/blog/2006/03/21/spambastards.html/comment-page-1#comment-16485</link>
		<dc:creator>***Dave</dc:creator>
		<pubDate>Fri, 24 Mar 2006 23:35:58 +0000</pubDate>
		<guid isPermaLink="false">http://hill-kleerup.org/blog/wp/2006/03/21/spambastards.html#comment-16485</guid>
		<description>&lt;p&gt;Holy crap.  Looking at my error logs, someone is hitting mt-tb.cgi every 1-5 seconds -- and getting a &quot;does not have execute rights&quot; error.&lt;/p&gt;
&lt;p&gt;I wish I knew if it was cheaper for that error to feed back or if a 404 would be better.  Better yet, I wish there was a way to hold back the response for several seconds, to further tie up the bastards&#039; machines.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Holy crap.  Looking at my error logs, someone is hitting mt-tb.cgi every 1-5 seconds &#8212; and getting a &#8220;does not have execute rights&#8221; error.</p>
<p>I wish I knew if it was cheaper for that error to feed back or if a 404 would be better.  Better yet, I wish there was a way to hold back the response for several seconds, to further tie up the bastards&#8217; machines.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ***Dave</title>
		<link>http://hill-kleerup.org/blog/2006/03/21/spambastards.html/comment-page-1#comment-16484</link>
		<dc:creator>***Dave</dc:creator>
		<pubDate>Fri, 24 Mar 2006 17:16:21 +0000</pubDate>
		<guid isPermaLink="false">http://hill-kleerup.org/blog/wp/2006/03/21/spambastards.html#comment-16484</guid>
		<description>&lt;p&gt;Had to rename the TB script again, since I saw some clusters of submissions showing up in the Junk list.&lt;/p&gt;
&lt;p&gt;Ideally, stuff never gets to the Junk list.  If it&#039;s on the Junk list, it means that the MT process has had to do execute it and throw it into Junk, which is good because it never gets to my blog, but bad because it impacts the servers.&lt;/p&gt;
&lt;p&gt;My hope, with Autoban, was to keep folks from getting there in the first place.  Ditto with renaming the TB script.  I need to look at my system logs (can&#039;t do from the office, annoyingly) so that I can see if folks are failing to find the scripts (a good thing).  Other than that, I can only watch for clusters of Junked TBs.&lt;/p&gt;
&lt;p&gt;Looking at those junked ones, they are mostly coming from just one Bad Guy.  The sites they are pointing at are all in the same IP cluster, but the IPs they are &lt;em&gt;posted &lt;/em&gt;from are all over the map.  (Are they spoofing their IPs, or just have access to a wide array of IP addresses?).&lt;/p&gt;
&lt;p&gt;Indeed, it&#039;s that difference between the source link and the posting link is part of what&#039;s turning them into Junk, thanks to SpamFilter.&lt;/p&gt;
&lt;p&gt;In theory, someone could be harvesting the revised TB script name since it&#039;s posted on the comments pages (so that folks can manually submit them).  But, then, since I have the trackback discovery code inside the posts, it can be harvested from there, too.  &lt;/p&gt;
&lt;p&gt;Of course, I could resolve the problem by turning off TB ... but I decline to do that.  Rrg.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Had to rename the TB script again, since I saw some clusters of submissions showing up in the Junk list.</p>
<p>Ideally, stuff never gets to the Junk list.  If it&#8217;s on the Junk list, it means that the MT process has had to do execute it and throw it into Junk, which is good because it never gets to my blog, but bad because it impacts the servers.</p>
<p>My hope, with Autoban, was to keep folks from getting there in the first place.  Ditto with renaming the TB script.  I need to look at my system logs (can&#8217;t do from the office, annoyingly) so that I can see if folks are failing to find the scripts (a good thing).  Other than that, I can only watch for clusters of Junked TBs.</p>
<p>Looking at those junked ones, they are mostly coming from just one Bad Guy.  The sites they are pointing at are all in the same IP cluster, but the IPs they are <em>posted </em>from are all over the map.  (Are they spoofing their IPs, or just have access to a wide array of IP addresses?).</p>
<p>Indeed, it&#8217;s that difference between the source link and the posting link is part of what&#8217;s turning them into Junk, thanks to SpamFilter.</p>
<p>In theory, someone could be harvesting the revised TB script name since it&#8217;s posted on the comments pages (so that folks can manually submit them).  But, then, since I have the trackback discovery code inside the posts, it can be harvested from there, too.  </p>
<p>Of course, I could resolve the problem by turning off TB &#8230; but I decline to do that.  Rrg.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Percy</title>
		<link>http://hill-kleerup.org/blog/2006/03/21/spambastards.html/comment-page-1#comment-16483</link>
		<dc:creator>Percy</dc:creator>
		<pubDate>Wed, 22 Mar 2006 04:40:14 +0000</pubDate>
		<guid isPermaLink="false">http://hill-kleerup.org/blog/wp/2006/03/21/spambastards.html#comment-16483</guid>
		<description>&lt;p&gt;Although the specifics are no longer valid, due mostly to changes in OS security features, a friend of mine used to use a cool trackback that would send a variant of the CIH virus to spammers.  I know that on at least one occasion it was successful with pleasantly infuriating (to the spammer) results.  Ah, for the days of yore.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Although the specifics are no longer valid, due mostly to changes in OS security features, a friend of mine used to use a cool trackback that would send a variant of the CIH virus to spammers.  I know that on at least one occasion it was successful with pleasantly infuriating (to the spammer) results.  Ah, for the days of yore.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
