<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Chinese Spam Mafia?</title>
	<atom:link href="http://www.in8sworld.net/blog/archives/337/feed" rel="self" type="application/rss+xml" />
	<link>http://www.in8sworld.net/blog/archives/337</link>
	<description>There&#039;s no place like 127.0.0.1</description>
	<lastBuildDate>Fri, 03 Sep 2010 10:59:22 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: in8sworld</title>
		<link>http://www.in8sworld.net/blog/archives/337/comment-page-1#comment-5656</link>
		<dc:creator>in8sworld</dc:creator>
		<pubDate>Fri, 28 Dec 2007 21:56:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.in8sworld.net/blog/index.php/archive/chinese-spam-mafia/#comment-5656</guid>
		<description>Added an image / math challenge to commenting care of &lt;a href=&quot;http://www.theblog.ca/math-anti-spam&quot; rel=&quot;nofollow&quot;&gt;Peter&#039;s Math Anti-spam plugin&lt;/a&gt;.  Along with the otherwise very impressive Akismet plugin, this should make it a lot safer to enable anonymous commenting.</description>
		<content:encoded><![CDATA[<p>Added an image / math challenge to commenting care of <a href="http://www.theblog.ca/math-anti-spam" rel="nofollow">Peter&#8217;s Math Anti-spam plugin</a>.  Along with the otherwise very impressive Akismet plugin, this should make it a lot safer to enable anonymous commenting.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: in8sworld</title>
		<link>http://www.in8sworld.net/blog/archives/337/comment-page-1#comment-5655</link>
		<dc:creator>in8sworld</dc:creator>
		<pubDate>Fri, 28 Dec 2007 21:38:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.in8sworld.net/blog/index.php/archive/chinese-spam-mafia/#comment-5655</guid>
		<description>I&#039;ve decided to re-enable anonymous commenting.  This is just a test to make sure it&#039;s working again.  I may need to install some more anti-spammer tests, but the coast seems to have cleared a bit.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve decided to re-enable anonymous commenting.  This is just a test to make sure it&#8217;s working again.  I may need to install some more anti-spammer tests, but the coast seems to have cleared a bit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nate</title>
		<link>http://www.in8sworld.net/blog/archives/337/comment-page-1#comment-538</link>
		<dc:creator>Nate</dc:creator>
		<pubDate>Mon, 08 Jan 2007 02:31:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.in8sworld.net/blog/index.php/archive/chinese-spam-mafia/#comment-538</guid>
		<description>A similar thing was happening at work, and we called in a security friend of mine who traced a couple of the IPs back to compromised Linksys routers to which they had supposedly uploaded some hacked firmware.  He was able to read the logs on one of the routers which had other IPs (supposedly the real criminals).  On those machines he found links to an IRC channel which he turned me on to.  I was stunned - they apparently had broken into a bank someplace and were processing stolen credit cards through some scripts that were running there.  Something about an eGold account which I didn&#039;t quite understand...  Seems like the US is going to need to start training an army of counter insurgent hackers soon - they haven&#039;t been doing too good of a job so far.</description>
		<content:encoded><![CDATA[<p>A similar thing was happening at work, and we called in a security friend of mine who traced a couple of the IPs back to compromised Linksys routers to which they had supposedly uploaded some hacked firmware.  He was able to read the logs on one of the routers which had other IPs (supposedly the real criminals).  On those machines he found links to an IRC channel which he turned me on to.  I was stunned &#8211; they apparently had broken into a bank someplace and were processing stolen credit cards through some scripts that were running there.  Something about an eGold account which I didn&#8217;t quite understand&#8230;  Seems like the US is going to need to start training an army of counter insurgent hackers soon &#8211; they haven&#8217;t been doing too good of a job so far.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ironmax</title>
		<link>http://www.in8sworld.net/blog/archives/337/comment-page-1#comment-537</link>
		<dc:creator>Ironmax</dc:creator>
		<pubDate>Mon, 08 Jan 2007 02:23:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.in8sworld.net/blog/index.php/archive/chinese-spam-mafia/#comment-537</guid>
		<description>Nate,

I know where they are coming from initially.  I found that they are cruising the search engines to find these links and thats why I ended up moving my mail signup form for email.  Then putting a fake one in its place.  Those spammers in Nigeria were saying anything just to try and get a free email account.  Unbenounced to them it was a booby trap, and they got caught in the act.  So I wont be seeing them for some time.

As far as finding or seeing the referer, try changing your script around juat a little to throw them off, theey&#039;ll have to change theirs to keep up.

Ironmax</description>
		<content:encoded><![CDATA[<p>Nate,</p>
<p>I know where they are coming from initially.  I found that they are cruising the search engines to find these links and thats why I ended up moving my mail signup form for email.  Then putting a fake one in its place.  Those spammers in Nigeria were saying anything just to try and get a free email account.  Unbenounced to them it was a booby trap, and they got caught in the act.  So I wont be seeing them for some time.</p>
<p>As far as finding or seeing the referer, try changing your script around juat a little to throw them off, theey&#8217;ll have to change theirs to keep up.</p>
<p>Ironmax</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ironmax</title>
		<link>http://www.in8sworld.net/blog/archives/337/comment-page-1#comment-536</link>
		<dc:creator>Ironmax</dc:creator>
		<pubDate>Mon, 08 Jan 2007 02:11:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.in8sworld.net/blog/index.php/archive/chinese-spam-mafia/#comment-536</guid>
		<description>For those that run windows based mail servers, I recommend using Spamfilter ISP in front of their mail server.  You can get to the link on our site at www.spacequad.com and download a free evaluation copy.  As far as the comment spam or any other spam on our site, I haven&#039;t seen any as of lately.  They&#039;ve tried to post but the captcha has stpped them cold in their tracks for now.  The only way someone can post on our system is to manually post by hand...bots are not welcomed.

Ironmax</description>
		<content:encoded><![CDATA[<p>For those that run windows based mail servers, I recommend using Spamfilter ISP in front of their mail server.  You can get to the link on our site at <a href="http://www.spacequad.com" rel="nofollow">http://www.spacequad.com</a> and download a free evaluation copy.  As far as the comment spam or any other spam on our site, I haven&#8217;t seen any as of lately.  They&#8217;ve tried to post but the captcha has stpped them cold in their tracks for now.  The only way someone can post on our system is to manually post by hand&#8230;bots are not welcomed.</p>
<p>Ironmax</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nate</title>
		<link>http://www.in8sworld.net/blog/archives/337/comment-page-1#comment-535</link>
		<dc:creator>Nate</dc:creator>
		<pubDate>Sun, 07 Jan 2007 14:57:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.in8sworld.net/blog/index.php/archive/chinese-spam-mafia/#comment-535</guid>
		<description>OK - so, in hopes of stopping the endless stream of emails generated by this situation, I found a &lt;a href=&quot;http://www.macmerc.com/articles/Power_User_Monday_Tip_of_the_Week/302&quot; rel=&quot;nofollow&quot;&gt;helpful page on macmerc.com&lt;/a&gt; that described how to add a couple lines to my .htaccess file which looks at the referrer and marks those that match as &#039;spammer&#039;.  Of course, if the spammers speak english and read this, they will just change their scripts, but they have to change the scripts anyways if they want to post some comment spam.  So far, its working - the emails have stopped for now.

That gained me all of about 5 hours of peace.  Apparently the spammers script was broken and I was seeing something that I wasn&#039;t supposed to see.  Now that he&#039;s fixed it, he is spoofing the &#039;Referer&#039; - what this means is that his script replaces the part of the transaction where the server sees what page he clicked on to get to the page he wants to spam on with my own domain name, so I can&#039;t use the htaccess trick to deny him.  In other words, it looks like this now:

&lt;blockquote&gt;
A user tried to go to 
http://www.in8sworld.net/blog/article.php?story=20050425062300738 
and received a 404 (page not found) error. It wasn&#039;t their fault, so try fixing it.  
        They came from 
http://in8sworld.net/article.php?story=20050425062300738
&lt;/blockquote&gt;
You see, he didn&#039;t come from where it says he&#039;s coming from &#039;cuz it doesn&#039;t exist anymore!  I moved the whole site to a subdirectory (and changed the whole site code) so there is no article.php in there.  I&#039;m thinking I might be able to use that fact to block him again. More on this later. </description>
		<content:encoded><![CDATA[<p>OK &#8211; so, in hopes of stopping the endless stream of emails generated by this situation, I found a <a href="http://www.macmerc.com/articles/Power_User_Monday_Tip_of_the_Week/302" rel="nofollow">helpful page on macmerc.com</a> that described how to add a couple lines to my .htaccess file which looks at the referrer and marks those that match as &#8216;spammer&#8217;.  Of course, if the spammers speak english and read this, they will just change their scripts, but they have to change the scripts anyways if they want to post some comment spam.  So far, its working &#8211; the emails have stopped for now.</p>
<p>That gained me all of about 5 hours of peace.  Apparently the spammers script was broken and I was seeing something that I wasn&#8217;t supposed to see.  Now that he&#8217;s fixed it, he is spoofing the &#8216;Referer&#8217; &#8211; what this means is that his script replaces the part of the transaction where the server sees what page he clicked on to get to the page he wants to spam on with my own domain name, so I can&#8217;t use the htaccess trick to deny him.  In other words, it looks like this now:</p>
<blockquote><p>
A user tried to go to<br />
<a href="http://www.in8sworld.net/blog/article.php?story=20050425062300738" rel="nofollow">http://www.in8sworld.net/blog/article.php?story=20050425062300738</a><br />
and received a 404 (page not found) error. It wasn&#8217;t their fault, so try fixing it.<br />
        They came from<br />
<a href="http://in8sworld.net/article.php?story=20050425062300738" rel="nofollow">http://in8sworld.net/article.php?story=20050425062300738</a>
</p></blockquote>
<p>You see, he didn&#8217;t come from where it says he&#8217;s coming from &#8216;cuz it doesn&#8217;t exist anymore!  I moved the whole site to a subdirectory (and changed the whole site code) so there is no article.php in there.  I&#8217;m thinking I might be able to use that fact to block him again. More on this later.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
