https://buy-zithromax.online buy kamagra usa https://antibiotics.top buy stromectol online https://deutschland-doxycycline.com https://ivermectin-apotheke.com kaufen cialis https://2-pharmaceuticals.com buy antibiotics online Online Pharmacy vermectin apotheke buy stromectol europe buy zithromax online https://kaufen-cialis.com levitra usa https://stromectol-apotheke.com buy doxycycline online https://buy-ivermectin.online https://stromectol-europe.com stromectol apotheke https://buyamoxil24x7.online deutschland doxycycline https://buy-stromectol.online https://doxycycline365.online https://levitra-usa.com buy ivermectin online buy amoxil online https://buykamagrausa.net

Spam by any other name …

So, a somewhat disturbing evolution in the War on Comment Spam — the stealth URL. And it shows why blacklists will only ever be of limited use as time goes…

So, a somewhat disturbing evolution in the War on Comment Spam — the stealth URL. And it shows why blacklists will only ever be of limited use as time goes on (as Jay Allen himself is the first to admit).

I’ve seen an increasing amount of comment spam coming in pointing at domains that combinations of names and/or words. “Candicesmith.org” or “FredCorp.com.” Those are URLs that cannot be detected by any blacklist. And if the post text has either innocuous words (“girls!”) or else something munged with HTML entities that reads legibly to the eye but not to the computer, there’s no way to blacklist against it.

There was originally a sense that you could use URL strings to detect spam, because comment spammers’ customers would want you go see that their URL was for [illicit product] and click through on it. But if readers get the metadata they need from the comment text, and if the spammers can say, “Hey, look, I’ve generated 52,000 links and a high Google pagerank for FredCorp.com (which probably redirects to MyWhatNaughtyVixins.com),” then the spammers and their customers get what they want. That makes the trivial cost of a domain acceptable (and lets the spammers start using more legitimate domain salesfolk).

Feh.

Moderating everything would be an option, but that restricts a lot of the fun we have here. Right now, through MT-Blacklist, I force to moderation for comments on posts over a certain age that haven’t had comments on them in the last defined interval. During the most recent attack last night and into this morning, about 100 comments got put into the system, but only one got accepted because it was posted to a recently commented-upon post (and how soon before that info starts becoming cracked by the spammers scripts?). It just takes a while to clean out the garbage, which is moderately satisfying (“And stay out!”) but irksome at the same time.

I could require authentication (e.g., TypeKey). I’m not there yet, though. I really don’t want to require people to sign in first. But I’m getting closer.

It is a puzzlement.

UPDATE: And, in validation of the “broken windows” theory (broken windows in a neighborhood provokes more broken windows; uncleaned graffiti prompts more graffiti), some proof that uncleaned comment spam breeds more comment spam.

(via Jay)

29 view(s)  

One thought on “Spam by any other name …”

Leave a Reply

Your email address will not be published. Required fields are marked *