<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" > <channel><title>Comments on: New wave of Blogspot spam</title> <atom:link href="http://blog.wpkg.org/2008/04/12/new-wave-of-blogspot-spam/feed/" rel="self" type="application/rss+xml" /><link>http://blog.wpkg.org/2008/04/12/new-wave-of-blogspot-spam/</link> <description>a technical IT blog</description> <lastBuildDate>Fri, 13 Jan 2012 23:16:03 +0000</lastBuildDate> <generator>http://wordpress.org/?v=2.9.2</generator> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <item><title>By: Adam Random</title><link>http://blog.wpkg.org/2008/04/12/new-wave-of-blogspot-spam/comment-page-1/#comment-339</link> <dc:creator>Adam Random</dc:creator> <pubDate>Sun, 13 Apr 2008 02:34:29 +0000</pubDate> <guid isPermaLink="false">http://blog.wpkg.org/2008/04/12/new-wave-of-blogspot-spam/#comment-339</guid> <description>These emails have been turning up for quite a few months now and, for me, did originally include many geocities hosted pages.When the spams first turned up they also used a different method of redirecting you to another page. I can no longer remember what they did, but it was not obfuscated and I guess that the blogspot staff did a good job of blocking it because once a few thousand blogs were reported, the spam stopped for a good 10 days.Once the spam started again, I had lost my geocities spammer but the blogspot one was going strong. The URLs had an interesting property this time. The same URL was never sent to more than one email address and as a result there was speculation that they might be using unique URLs to detect spamtraps and normal humans reporting them to the URIBL. A massive data mining exercise. It certainly seemed to hold true for me as any time I reported 50 or so URI, I stopped getting blogspot spam for a number of days and also had a marked reduction in all other spam too.By watching what other people were submitting, I could tell that during the times I was getting no blogspot spam, lots of other people were still getting them. http://rss.uribl.com/hosters/ shows all the submitted and active free hosters in the last 5 days.This last batch of blogspot spam seem to have lost their uniqueness. Any blogspot URL I get now days are listed on the URIBL within minutes by others, and I&#039;m getting hundreds of them every day. It either debunks the idea they were spamtrap hunting, or proves that the spammers just don&#039;t give a hoot. An email getting through to anyone (or in my case, anything as it all gets processed by programs) is fine with them.Anyway, I have been investigating using the &quot;Flag as inappropriate&quot; feature on the loaded blog to a notify blogspot staff of the spam blog. Loading the blogspot page will give you the &quot;blogid&quot; in a meta tag at the top of the page - EditURI. Also included up there is the &quot;me&quot; meta info which is a link to the blogger/spammers blog account which can tell you which month and year they signed up (if it&#039;s the same month, you can assume pretty safely they are a spamming prick) Once that info has been pulled out, you can use the ID to create a URI to flag the blog as inappropriate and the blog will be reviewed by a human. The general hope here would be to poke them into action to fix their abuse problem. eg. ptfi3t9hf1ppmp.blogspot.com, the id is 4637393089326112718. The page contains the stupid unescape location rewrite code so build the following URI stolen from the navbar frame and load it. That should flag it for review :) http://www.blogger.com/flag-blog.g?nav=1&amp;toFlag=4637393089326112718</description> <content:encoded><![CDATA[<p>These emails have been turning up for quite a few months now and, for me, did originally include many geocities hosted pages.</p><p>When the spams first turned up they also used a different method of redirecting you to another page. I can no longer remember what they did, but it was not obfuscated and I guess that the blogspot staff did a good job of blocking it because once a few thousand blogs were reported, the spam stopped for a good 10 days.</p><p>Once the spam started again, I had lost my geocities spammer but the blogspot one was going strong. The URLs had an interesting property this time. The same URL was never sent to more than one email address and as a result there was speculation that they might be using unique URLs to detect spamtraps and normal humans reporting them to the URIBL. A massive data mining exercise. It certainly seemed to hold true for me as any time I reported 50 or so URI, I stopped getting blogspot spam for a number of days and also had a marked reduction in all other spam too.</p><p>By watching what other people were submitting, I could tell that during the times I was getting no blogspot spam, lots of other people were still getting them. <a href="http://rss.uribl.com/hosters/" rel="nofollow">http://rss.uribl.com/hosters/</a> shows all the submitted and active free hosters in the last 5 days.</p><p>This last batch of blogspot spam seem to have lost their uniqueness. Any blogspot URL I get now days are listed on the URIBL within minutes by others, and I&#8217;m getting hundreds of them every day. It either debunks the idea they were spamtrap hunting, or proves that the spammers just don&#8217;t give a hoot. An email getting through to anyone (or in my case, anything as it all gets processed by programs) is fine with them.</p><p>Anyway, I have been investigating using the &#8220;Flag as inappropriate&#8221; feature on the loaded blog to a notify blogspot staff of the spam blog. Loading the blogspot page will give you the &#8220;blogid&#8221; in a meta tag at the top of the page &#8211; EditURI. Also included up there is the &#8220;me&#8221; meta info which is a link to the blogger/spammers blog account which can tell you which month and year they signed up (if it&#8217;s the same month, you can assume pretty safely they are a spamming prick)<br /> Once that info has been pulled out, you can use the ID to create a URI to flag the blog as inappropriate and the blog will be reviewed by a human. The general hope here would be to poke them into action to fix their abuse problem.<br /> eg. ptfi3t9hf1ppmp.blogspot.com, the id is 4637393089326112718. The page contains the stupid unescape location rewrite code so build the following URI stolen from the navbar frame and load it. That should flag it for review <img src='http://blog.wpkg.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br /> <a href="http://www.blogger.com/flag-blog.g?nav=1&amp;toFlag=4637393089326112718" rel="nofollow">http://www.blogger.com/flag-blog.g?nav=1&amp;toFlag=4637393089326112718</a></p> ]]></content:encoded> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching using disk: basic
Object Caching 79/147 objects using disk: basic

Served from: blog.wpkg.org @ 2012-02-10 11:44:16 -->
