Go to main content

Textpattern CMS support forum

You are not logged in. Register | Login | Help

#13 2005-12-05 21:35:03

zem
Developer Emeritus
From: Melbourne, Australia
Registered: 2004-04-08
Posts: 2,579

Re: Textile formatted comment spam

The ban feature has been there as long as I remember. content > comments, then click on one.


Alex

Offline

#14 2005-12-05 21:37:47

thebombsite
Archived Plugin Author
From: Exmouth, England
Registered: 2004-08-24
Posts: 3,251
Website

Re: Textile formatted comment spam

It’s funny but it’s a place you don’t visit very often. ;)


Stuart

In a Time of Universal Deceit
Telling the Truth is Revolutionary.

Offline

#15 2005-12-22 11:58:58

davidm
Member
From: Paris, France
Registered: 2004-04-27
Posts: 719

Re: Textile formatted comment spam

<blockquote> hakjoon wrote: In the last 3 days I’m suddenly getting hit by a lot of comment spam (first time so far). And to top it all the spam is textiled. Anyone else seeing this? Are the spam free TXP days of yore gone? I’m still on 4.0.1 if that could have any co-relation..</blockquote>

Yeah I concur, I’ve been hit (running 4.0.1 too) and it has never happened before.
Banning is useless, this seems to be some kind of robot with a different IP each time…

I’ll update to 4.0.2…


.: Retired :.

Offline

#16 2005-12-22 16:20:45

Daragh
Member
From: Toronto Canada
Registered: 2004-05-26
Posts: 60
Website

Re: Textile formatted comment spam

I’ve been getting the same thing, every few hours in batches of 10 or so from different IPs. Would upgrading to 4.0.2 help at all?

Offline

#17 2005-12-23 00:16:50

goncourt
Member
From: Dortmund/Germany
Registered: 2005-03-27
Posts: 24
Website

Re: Textile formatted comment spam

I am at 4.0.2 and I’ve got the same problem (I posted it in the german forum ). In a period of more or less four hours I got over 200 spam comments, even 20 of them in two minutes &mdash; with different IPs

I made the following observation:
since I stopped the comment possibility, the attack is still going on. Strange enough the referrers don’t start from where the comments would start – from the articles. They neither start from the weblog’s root but from my site root (goncourt.net instead of goncourt.net/Blog). Or they use some javascript function to reset the history variables (I don’t know if that is possible) or they use url-manipulations to jump via the “goncourt.net/Blog”-link at the homepage (which is only the link to enter the main page of the blog) into deeper links.

for e.g.:
date host url referrer
12/23 1:35 am ip68-10-101-26.hr.hr.cox.net Blog/article/820/nixon-you-dress-pretty-wild-dont-you goncourt.net
12/23 1:35 am 12-208-204-210.client.insightBB.com Blog/article/777/ein-sonntagskind-formerly-known-a…
s-prinz
goncourt.net
12/23 1:35 am ip70-177-33-3.br.br.cox.net Blog/article/741/i-said-i-didnt-believe-in-nature goncourt.net

(etc.)

Last edited by goncourt (2005-12-23 00:19:06)

Offline

#18 2005-12-23 07:47:20

davidm
Member
From: Paris, France
Registered: 2004-04-27
Posts: 719

Re: Textile formatted comment spam

It would seem someone has taken some time to circumvent the “preview” security feature in textpattern, too bad since it was a strong suit of textpattern compared to other systems, not having comment spam…

The spam I got was focused on one article only, I see yours was on multiple articles…

One thing comes to mind : maybe there is a plugin I missed, but the spam I get could easily be prevented with a word filter / censoring. Maybe we’ll need something like this in the near future :(


.: Retired :.

Offline

#19 2005-12-23 09:31:50

Sencer
Archived Developer
From: cgn, de
Registered: 2004-03-23
Posts: 1,803
Website

Re: Textile formatted comment spam

Well, I’ve mentioned it in another thread, but it may have gotten lost. We are aware of the problem and are taking steps to improve on the situation. And while it is possible to write/port spam plugins from other systems already, we are looking at ways to make writing anti-spam plugins easier as well.

Offline

#20 2005-12-23 10:30:05

RenJonsin
Member
From: Tarpon Springs, FL USA
Registered: 2005-02-06
Posts: 103
Website

Re: Textile formatted comment spam

I setup a friend’s blog to use textpattern and it is receiving tons of referrer spam from the host ns1.imagehop.com. It previously used Word Press to post the articles. My site, Frontstretch.com never gets any comment or referrer spam. Both sites are served from the same machine so that’s about the only difference.

Just thinking that maybe the problem is that they know the site was able to show spam prior and are still attempting to use that resource while not attacking areas that didn’t have the capability to accept spam in the past.

She doesn’t have anything new enough to accept comments so I went ahead and threw a PR report on their just now to see if anything would show up. Her site is www.cawsnjaws.com.

Offline

#21 2005-12-23 15:04:10

reid
Member
From: Atlanta, Ga.
Registered: 2004-04-04
Posts: 224
Website

Re: Textile formatted comment spam

I got more spam on my site yesterday than I have the entire calendar year. Looking over the logs, it seems clear someone has attempted to automate spam posting on Txp sites. The hits come fast and from multiple IP’s, give a false referrer of my home page on pages that are no longer linked from there, and keep hitting pages until it finds one where comments are still open.

Once it posts successfully (even if you immediately delete it), it comes back to that URL once an hour, every hour, and tries to post another one.

Somehow, the drug terms in this spam were skipping by server level protection at TextDrive, but can be blocked in my local .htaccess. Between that and going to comment moderation, I’ve at least been able to keep it off my site since late yesterday afternoon.

Looking forward to version 4.0.3…


TextPattern user since 04/04/04

Offline

#22 2005-12-23 15:52:21

kriskhaira
Member
From: Malaysia
Registered: 2005-02-22
Posts: 16
Website

Re: Textile formatted comment spam

I’ve been having the same problem at http://kriskhaira.com/blog/. I’m on 4.0.2. Over 30 comment spams today!

Looking forward to a better security feature. :)

Offline

#23 2005-12-23 16:00:40

sewm
New Member
From: Toronto, Canada
Registered: 2004-05-08
Posts: 9
Website

Re: Textile formatted comment spam

You guys seem to be on top of things so I won’t post my logs just yet. I seem to get multiple comments at the same time from different IPs. I would ban them except they don’t seem to use the same one twice so there doesn’t seem to be much point.

None of the comment spam that I have received yet have Textile formatted text, just BBCode or plain URIs.

Offline

#24 2005-12-23 16:13:27

Sencer
Archived Developer
From: cgn, de
Registered: 2004-03-23
Posts: 1,803
Website

Re: Textile formatted comment spam

As I said one of the interesting things will be an API for people to write spam-plugins.

If there are developers that want to write and/or port over (from other publishing software) anti-spam-plugins, please subscribe to the txp-dev or txp-plugins list:
http://lists.textpattern.com/mailman/listinfo

Offline

Board footer

Powered by FluxBB