https://buy-zithromax.online buy kamagra usa https://antibiotics.top buy stromectol online https://deutschland-doxycycline.com https://ivermectin-apotheke.com kaufen cialis https://2-pharmaceuticals.com buy antibiotics online Online Pharmacy vermectin apotheke buy stromectol europe buy zithromax online https://kaufen-cialis.com levitra usa https://stromectol-apotheke.com buy doxycycline online https://buy-ivermectin.online https://stromectol-europe.com stromectol apotheke https://buyamoxil24x7.online deutschland doxycycline https://buy-stromectol.online https://doxycycline365.online https://levitra-usa.com buy ivermectin online buy amoxil online https://buykamagrausa.net

Moving right along …

Is it my imagination, or has blog comment spam dropped way off? I certainly haven’t received any at my sites for a couple of weeks. Weeellll … now that I…

Is it my imagination, or has blog comment spam dropped way off?

I certainly haven’t received any at my sites for a couple of weeks.

Weeellll … now that I look at my Activity Log, I can see two or three hits a day that ran up against MT-Blacklist. So maybe the answer is that my blacklist is pretty effective right now. Huzzah!

Phases

I always find it interesting how spam comes in subject waves. I don’t know if it’s separate scam artists moving along in a pack from one rip-off to another, or…

I always find it interesting how spam comes in subject waves. I don’t know if it’s separate scam artists moving along in a pack from one rip-off to another, or if it’s a sign of a single scammer using multiple spam routes to get his/her message out.

Anyway, I suddenly have a ton of message from different sources offering me Tylenol 3 with Codeine (or “Codeine Tylenol3,” as they all say, increasnig the likelihood of it being the second alternative above). It’s enough to give me a head-ache, I’ll tell you …

Our company finally put in a new spam filter, CipherTrust’s IronMail. It’s cut the first-thing-in-the-morning spam count from 80 to about 10, so that’s good.

A sign things aren’t quite right

When I have a message in my inbox from “anna” at hill-kleerup.org, sent to “ted” at hill-kleerup.org … and I’m pretty darned certain there aren’t any folk here by either…

When I have a message in my inbox from “anna” at hill-kleerup.org, sent to “ted” at hill-kleerup.org … and I’m pretty darned certain there aren’t any folk here by either name.

In the Blacklist

As inspired by ScriptyGoddess (who gets lots of comment spam), I’m offering access to my own blacklist that I use with MT-Blacklist; it includes both the canonical list, ones I’ve…

As inspired by ScriptyGoddess (who gets lots of comment spam), I’m offering access to my own blacklist that I use with MT-Blacklist; it includes both the canonical list, ones I’ve added (I always report to the official list, but I don’t track which ones are accepted in), and ScriptyGoddess’s as well.

I’ve also put a link in the sidebar, up toward the top.

Have fun.

Infectious

In case you’ve been under a rock, there’s a new computer virus in town, the MyDoom or Novarg virus. The virus–known as MyDoom, Novarg and as a variant of the…

In case you’ve been under a rock, there’s a new computer virus in town, the MyDoom or Novarg virus.

The virus–known as MyDoom, Novarg and as a variant of the Mimail virus by different antivirus companies–arrives in an in-box with one of several different random subject lines, such as “Mail Delivery System,” “Test” or “Mail Transaction Failed.” The body of the e-mail contains an executable file and a statement such as: “The message contains Unicode characters and has been sent as a binary attachment.”
“It’s huge,” said Vincent Gullotto, vice president of security software maker Network Associates’ antivirus emergency response team. “We have it as a high-risk outbreak.”
In one hour, Network Associates itself received 19,500 e-mails bearing the virus from 3,400 unique Internet addresses, Gullotto said. One large telecommunications company has already shut down its e-mail gateway to stop the virus.
Once the virus infects a Windows-running PC, it installs a program that allows the computer to be controlled remotely. The program primes the PC to send data to the SCO Group’s Web server, starting Feb. 1, a virus researcher said on the condition of anonymity.

As always, update your AV software; if it hasn’t been automatically updated yet, then manually go out and grab the current signature file and engine. Etc.

UPDATE: The following is from the NAI AV site:

This is a mass-mailing and peer-to-peer file-sharing worm that arrives in an email message as follows:
From: (spoofed email sender)
Subject: (Varies, such as)
– The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.
– The message contains Unicode characters and has been sent as a binary attachment.
– Mail transaction failed. Partial message is available.
– Error
– Status
– Server Report
– Mail Transaction Failed
– Mail Delivery System
– hello
– hi

More info is also available at Symantec’s site.

Brothers under the sig line

I’d like you to meet my sons, Andrew. Oh, and Matt, too. Matt, say hi to the folks. Ah, and there’s Steve and George, playing backgammon in the corner. Cool….

I’d like you to meet my sons, Andrew. Oh, and Matt, too. Matt, say hi to the folks. Ah, and there’s Steve and George, playing backgammon in the corner. Cool. Good to see you guys, are your rooms cleaned up.

At least, I assume they’re my sons, since they’re using the hill-kleerup.org domain for their e-mail addresses. At least that’s what some spammers think, based on what’s showing up in my in-box, i.e., mail to andrew, matt, steve, and george at hill-kleerup.org.

Heh.

Moo

Given that I walked in the door this morning and found I had 360-odd spams in my in-box, this looks increasingly probable. UPDATE: Hey, maybe if I put in the…

Given that I walked in the door this morning and found I had 360-odd spams in my in-box, this looks increasingly probable.

UPDATE: Hey, maybe if I put in the link to the cartoon page, not the banner ad thereon, people would actually think it’s funny! (Thanks, Julia.)

Spam strategies

I’ve been having pretty good success with MT-Blacklist in blocking (or removing) comment spam. The approach it takes is interesting. Rather than trying to track IP addresses (which can be…

I’ve been having pretty good success with MT-Blacklist in blocking (or removing) comment spam.

The approach it takes is interesting. Rather than trying to track IP addresses (which can be spoofed) or e-mail addresses (which can be spoofed even more easily), it looks at URLs, links in the comment. If they are on the blacklist, it gets blocked.

(You can also use that to block certain text, but that’s not the way it’s designed to work.)

So, why not take that approach with e-mail spam? Aside from viruses and Trojan Horses and the like, what really sets e-mail spam is the links to the commercial sites. The verbiage its all wrapped up in makes no difference to a large degree (as seen in some recent efforts to spoof Bayesian filters). If the link isn’t usable and visible, the e-mail has done no good. And since URLs must be established to do any good, and that costs money and takes effort, it seems like a better way to strike back at spammers.

Are there any mail spam products that focus just on URLs? It really seems to me that would be a superior approach. Unless I’m missing something.

Usenet Thread of the Beast

Fascinating November Usenet (alt.internet.search-engines) discussion thread here on blog comment spam — from the perspective of the spammers. What’s more your sexy lingerie site would be a pr8 right now…

Fascinating November Usenet (alt.internet.search-engines) discussion thread here on blog comment spam — from the perspective of the spammers.

What’s more your sexy lingerie site would be a pr8 right now if you also did guestbook, memberlist, and blog posts instead of dropping to a pr6 as it has. (it was a pr7 last month). You’re becoming too ethical and that is stopping you from doing better than you can.

Well, we can’t have that, now, can we? The other person responds, no doubt with accuracy:

You assume too much, when it comes to making money I lower my ethics considerably.

All sorts of fun (as in “like watching bugs under a lifted rock”) discussion of guest books, pageranks, dummy websites, and other ways to game Google for fun and profit.

(via Les)

Petard

You don’t mean to tell me that companies that pander to spammers — most of whom redolent frauds — might themselves be frauds? Say it ain’t so, Joe! This site…

You don’t mean to tell me that companies that pander to spammers — most of whom redolent frauds — might themselves be frauds? Say it ain’t so, Joe!

This site purchased a couple of those CDs you get spam for, the ones that say they have zillions of legit e-mail addresses that you can then use for your own spamming operation. The result of the analysis:

  • Over half the addresses are duplicates (triplicates, or more, up to 14x).
  • A large number of spam abuse addresses for various ISPs and organizations show up. Yeah, that’ll sell those enlargers all right.
  • A large number of invalid addresses (like “wu.html” as a domain).
  • Lots of other useful addresses for hawking viagra, like embassies, airports, and other spammers.

You get what you pay for. Or what you deserve, in this case.

(via BoingBoing)

What have you got in your in-box?

An Open Letter to Businesses Sending Out E-Mail, Capital One in Particular: Given the wide array of Internet e-mail scams and spoofs and phishing expeditions, if you send out an…

An Open Letter to Businesses Sending Out E-Mail, Capital One in Particular:

Given the wide array of Internet e-mail scams and spoofs and phishing expeditions, if you send out an e-mail suggesting people go to a web site, or call a phone number, to update their account information, I strongly suggest:

1. You make sure the website links in the e-mail are on your primary domain.

2. You make mention of the e-mailing or initiative that prompted it somewhere prominently on your main page.

and/or

3. You make sure the phone number you suggest people call is prominently displayed on your website, perhaps in conjunction with #2.

Otherwise, you’ll have irritating people like me sending you annoying e-mail messages asking if this is a hoax or not, then, when informed it is not, writing snarky blog entries about how you should go about doing such mailings.

Thanks. And Happy Holidays.

*** Dave

Tricksy little devils

My old Thursday Thumb-Twiddler meme blog is being left up as something of a honey-pot for comment bloggers. I get a number of posts each day left there, most of…

My old Thursday Thumb-Twiddler meme blog is being left up as something of a honey-pot for comment bloggers. I get a number of posts each day left there, most of which are of the standard type (laundry lists of pr0n sites).

Over the past few days, I’ve noticed something a bit sneakier — site name that look normal, but which are, in fact, self-forwarding sites or gateways to pr0n sites of various sorts. If I didn’t know that the posts going there are likely spam, if they weren’t clustered together, and I didn’t actually check some of them out, I might pass them by. Especially since they are embedding the URL in the URL field, and posting with an innocuous “Mine are up!” body.

As it is, they get sighted, reported, and zapped. Huzzah!

Zapped

MT-Blacklist and comment spam on my blogs. Twenty-two automatically blocked since 12/1. Another two-three dozen semi-automatically removed (and reported to the central blacklist). Sweet….

MT-Blacklist and comment spam on my blogs.

Twenty-two automatically blocked since 12/1.

Another two-three dozen semi-automatically removed (and reported to the central blacklist).

Sweet.

Zap

Two instances of comment spam this morning, and a couple of others over the past few days. These tend to be of two types: 1. Gosh! I love your page….

Two instances of comment spam this morning, and a couple of others over the past few days. These tend to be of two types:

1. Gosh! I love your page. Here’s a long list of links to various pr0n and gambling sites you may enjoy.

These are easy to spot. They may not even include the “Gosh! I love your page” part.

2. Good insight. Here’s what I got on the test. Interesting article.

These are a lot less easy to spot, on the surface. I get a number of relatively innocuous postings like this, too. They don’t have long lists of links — but they do include a link to a commercial site in the poster’s URL. They may not be pr0n sites; they could be hosting sites, or book sites, or others; I’ve seen several instances of this.

That means they get through the initial MT-Blacklist screen — but are still visible to Google (hence their worth to the spammer) and to me (hence my ability to quickly swat them before they give a Google boost).

And I do spot them, folks. I read pretty much every comment that goes up here (the number is not that staggering, and a list is kept up at the top of the blog — you may have noticed it). And I get mail copies of all blog comments, too, which makes such sins even easier to spot.

(I could, I suppose, mask the URL of commenters just as I do the e-mail. But I find it a useful identifier. So I won’t.)

In any case … just don’t try it. Okay? Because I spot them, and yank them, and screen against them in the future. And because I report these things to the MT-Blacklist clearinghouse, too, and they put them on the mast list of Nasty URLs, and that means even folks who aren’t a diligent about screening their blog comments will be protected.

Beware of Dog. Keep Out. No Soliciting. Trespassers Will Be Prosecuted.

UPDATE: Note that this applies to (a) unsought solicitations and (b) hijacking my blog to boost the Google ranking of your commercial site, legit or not. It does not apply to people posting inane or contrary or dissenting or goofy comments. Those I leave, unless they are simply a personal insult. Even then I’m likely to leave them as examples of the idiocy of the commentator, since they are almost inevitably riddled with errors grammatical, orthographical, semantic, and logical.

Shep! Bad dog!

In the movie Airplane!, a visitor to a suburban house is progressively mauled by the resident dog. The lady of the house repeatedly, but rather absently, scolds the dog, even…

In the movie Airplane!, a visitor to a suburban house is progressively mauled by the resident dog. The lady of the house repeatedly, but rather absently, scolds the dog, even as it continues its attack. “Shep! Bad dog!”

Congress, responding to the loud bone-crunching sounds coming from constituents overwhelmed by spam, is busy doing its own ineffectual scolding, having finally passed the CAN-SPAM Act. The bill, which Dubya says he will sign, stands for “Controlling the Assault of Non-Solicited Pornography and Marketing” — even though it does little of either.

Basically under the law, e-mailers are prevented from forging e-mail headers, and sending unsoliced porographic ads. Marketers need to include a return e-mail address or link to a web form to allow unsubscribes from the list.

How is this pointless? Let me count the ways …

First off, it only has an impact on US spammers. The answer will be that those who are not hosting their spam servers inside the US (or who are not US companies) will be effectively immune.

The most egregious spammers, the ones already peddling porn and quack medicines, are already subject to existing laws. If they’re not worried about being prosecuted for selling bogus erection medicine and dangly-bit enlargers, they’re not going to worry about being prosecuted for forging mail headers — especially since that will make it harder to get hold of them, with a maximum penalty of, in the most egregious circumstances, 5 years in prison if they are caught, and assuming anything but the most desultory enforcement takes place.

The law requires an “opt-out,” which means that the vendor — not the spammer — must give you an opportunity to tell them you no longer want to receive their e-mails … for a given product, or, maybe vendor. Well, la-de-dah. Legit vendors already do this (since they definitely don’t want to irritate their potential customers). Spammers don’t do it now, and even if they decide to comply, creating an infinite number of mailing lists is trivial.

“You’ve chosen to opt out of the Manly Man Eyebrow Plucker v1.3 (SKU 134965) Mailing List. Thank you for verifying this is a legitimate address. You will begin to receive multiple e-mails from us for our other 95,000 products (constantly being renamed and reidentified), as well as from this spammer for other vendors’ goods. Have a nice day!”

And, finally, the law preempts stricter state laws. Not that those laws have been any more effective (see above), but California’s opt-in legal requirement is now null and void. Direct Marketers really like that.

In other words, don’t deinstall that anti-spam software any time soon.

Spam – smiles and irks

On the bright side, there was this little subject line treasure today: Prized Davehill !!! Truly Free admittance and 60 $ reachable in the present day dear friend and associate!…

On the bright side, there was this little subject line treasure today:

Prized Davehill !!! Truly Free admittance and 60 $ reachable in the present day dear friend and associate! !!!

I mean, is that cool, or what?

On the other hand, there was an e-mail from “EarthLink Mail Watch” with the subject Important information about your email account. But if you look at the properties for the mail, the underlying mail address is MailWatch@extra.hu.

Somehow I suspect that Earthlink’s legitimate mailings do not come from Hungarian mail addresses.

The address gives a warning that your e-mail account is getting close to 10Mb (and is phrased very plausibly). It ends with: For instructions on how to do this, as well as on how to avoid exceeding the 10MB limit in the future, please visit: and the inevitable link turns into a fascinating little program that I choose not to try out.

So … careful what you open. Or click on.

Spam, spam, spam, spam …

Yet another installment of particularly noteworthy subject lines … Join the well hung men club, we will show you how! – I just keep imagining their monthly meetings … do…

Yet another installment of particularly noteworthy subject lines …

  • Join the well hung men club, we will show you how! – I just keep imagining their monthly meetings …
  • do you like boobs? – Is the Pope Catholic?
  • Free – Best Golf Wedge – This was, without a doubt, the first golf spam I got. Amazingly enough, it’s not the last.
  • Make Insane Money… Own ATM machines – You’d have to be crazy!
  • Your message delivery has been failed. – It will have to repeat second grade.
  • Hi! Striking adolescents – It’s tempting, I know, particularly when you’re the parent of one.
  • SHE WILL WANT TO LICK YOU LIKE A LOLLIPOP. – As long as she doesn’t try (and fail) to find out how many licks it takes to get to the center of a Tootsie-Pop …
  • porn leecher – You mean it will suck all the porn from my inbox? Huzzah!
  • ~ How do you do! straight away open this site or your Free of charge access will be crossed out! ~ – Egads!
  • Don’t let Spam get You! – Don’t worry, I won’t.
  • =?GB2312?B?sbG+qdeovNK3rdLrzfggIL3fs8/OqsT6zOG5qbet0uu3/s7x?= – This subject line, from the Beijing Chinese Translation Co., Ltd., lost something in the, well, you know …

Frell

Looks like comment spam is beginning to seep in here. Over the last week, I’ve had four or five comments pop up that were innocuous “Hey, nice post” types of…

Looks like comment spam is beginning to seep in here. Over the last week, I’ve had four or five comments pop up that were innocuous “Hey, nice post” types of things. Problem is, what they’re really here to do is put their URL in the comments, which then bumps up their Google pagerank, which makes their site more successful.

Feh.

In other words, we’re not talking about harvesting e-mail addresses here, or getting people to click through to their sites. It’s all about Google pageranks.

Hrm.

Let’s see if I can do some selective stamping out, before wheeling out the MT-Blacklist big guns …

UPDATE: Went ahead with MT-Blacklist, for a variety of reasons. Instalation was as close to painless as humanly possible. Turned it on, started inspecting past comments …

Holy crap.

I’ve mentioned I’d not been paying much attention to the Thursday Thumb-Twiddler before I shut it down. Evidently I’m the only one who wasn’t, because there were at least a hundred or more Evil Spam Comments — of the list-a-bunch-of-porn-site types — lurking in there. Jeez!

Well, that’ll larn me.

I’ll see how the blacklist works for the nonce. I’m not sure if I need or want to put a little warning by the comments about it. Hopefully anyone who gets incorrectly blocked will give me a holler.

The keen thing about MT-Blacklist and the approach it takes is that it’s not focused on content per se. That means that you can talk about all sorts of nasty stuff in the comments and not have it blocked (for those occasions where such subjects come up). It’s blocking, for the most part, evil URLs, because that’s the key to comment spam.

Though here’s an interesting one I ran across today — comments that lead you to something that looks like it’s a normal blog (it’s often ripped off from one) — but whose comment links, etc., all go to evil URLs. It’s an attempt to fight against this sort of blacklisting, since it still uses the Google PageRanks (a site removed) to promote evil sites, but it’s subject to the same kind of detection and blacklisting. This has been known to come up in e-mails, too, hoping to get you to blogroll a faux blog that way.

Evil.

UPDATE 2: All seems to be working well. I’ve reinstalled the hacks for no duplicate comments and no duplicate trackbacks, and those seem to be working well, too.

Monoculture and spam

As previously noted, monocultures are dangerous in horticulture. While they maximize the favorable traits, they also make a species vulnerable to attack by disease. So, too, is monoculture in anti-spam….

As previously noted, monocultures are dangerous in horticulture. While they maximize the favorable traits, they also make a species vulnerable to attack by disease.

So, too, is monoculture in anti-spam. If enough folks use the same anti-spam technique, then it behooves spammers to find a way around that technique, getting the maximum bang for the buck.

MT has a very simple anti-spam feature in it for e-mail addresses. For any tag that might include an e-mail address, you can specify ‘spam_protect=”1″‘ and MT will trivially obfuscate the e-mail address, using HTML entities in place of the “@” and “.” characters. It reads, visibly, correct, and can even be clicked on as a mailto: link, but simple spambots reading it will not detect an e-mail address.

Unless enough people use it, in which case, boom, it’s worthwhile breaking the (as I said, trivial) code. Which, evidently, has been done, as at least one correspondent (who didn’t have a web address, and thus had her e-mail address semi-displayed) found when someone sent her an offer to “monitor her web site,” based on her (e-mail address-labelled) comment on one of my pages.

(Sorry, Amanda.)

So I’m going to modify the comment code to not show e-mail addresses, regardless. I’ll still get them internally in the system, so I can contact you if need be (bwah-ha-ha!), but others will not be able to; linked-to web pages will, however, still show up as a link on the author’s name.

(Mutter mutter mutter mutter)

Spam, spam, spam, spam …

I had 374 in my in-box this a.m. This is insane. Of course, I also had these blogfodder gems: The Holidays are Coming – Email 3,000,000 People — Uh, no…

I had 374 in my in-box this a.m. This is insane.

Of course, I also had these blogfodder gems:

  • The Holidays are Coming – Email 3,000,000 People — Uh, no thanks. I’ll settle for sending cards to about 75.
  • Dreaming of working at home? — No, dreaming of sleeping at home.
  • B.reak Walls A.part With Your Hum.ungous Knob — You know, this just doesn’t sound appealing to me.
  • Be more fulfilled, and make women scream! — “Get that thing away from me! It’s breaking my walls apart!”
  • Effectively Spam Detecting — Why, look, it detects one right now …
  • What is GEN.E.R-I-C V.IA.G.R.A? — Probably the same rip-off as the G.E.N.ERIC VI.A.G.R.A I was offered in an adjoining spam.
  • Italian-crafted Rolex – only $65 – $140 — And worth every 35 cents!

Since I have such a large sample (ack!), some distribution, based on subject lines:

  • 34%, over 1/3, were for online meds/pharmacies/etc., almost all of them flogging Vicodin, Xanax, and Viagra.
  • 11% were for size increase meds/patches/techniques/secrets. Only 3 of those were for women.
  • 9% were for debt reduction, mortgage rates, money earning schemes, etc.
  • Only 5% was for pr0n, remarkably enough.
  • Other big draw were spam/virus protection and e-mail distribution lists, inkjet ink, cable descramblers, cheap insurance, and weight loss methods. Oddball repeats included cheap gasoline, electric scooters, RC cars, and diploma mills. Amazingly, only one Nigeria 409 add.
  • 16% could not be figured out from the subject line — either because it was too vague what was being sold (“A great deal!”), it was a deceptive draw (“I waited for you Friday”), or a random string of misspelled words (“dimond sufix vondle”).

Interesting.

Note that we do actually have a filtering gateway, that supposedly strips pr0n from the mix, which probably leads to that category being underrepresented. Though given some of the subject lines, there’s a good reason why it’s being replaced.