Going through the spam comments on one of the sites I found the following:
Yes that’s right… 3 comments on the SAME post from the SAME IP address… how could that not be spam?
Scribblings from Steve
Going through the spam comments on one of the sites I found the following:
Yes that’s right… 3 comments on the SAME post from the SAME IP address… how could that not be spam?
Yet more stupid spam arrived in my inbox today.
Lets just take two examples from the small tsunami that arrived.
What spammers forget is that sending TWO emails from different people to the SAME address with similar messages in it really does give the game away.
Then why on earth should someone send Security alert emails from an Ipad? They’d be system generated.
Finally why would Rentokil Initial be sending email from a personal address at smile-sumai.jp.
Really guys – are you really so thick you can’t even realise that the junk you are sending out is complete and utter shit?
I got a lot of hits with a referrer of keywords-monitoring-your-success . com
Lots of different IP addresses – all in Brazil… And guess what : yes its the scum at Semalt up to their old tricks again.
Why can’t they just fuck off and stop pissing people off.
Re-write rules added to block them in future:
# Block access from semalt - its a rogue and serves no purpose
RewriteCond %{HTTP_REFERER} semalt\.com [NC]
RewriteRule .* - [F]
# Semalt under another name
RewriteCond %{HTTP_REFERER} keywords-monitoring-your-success.com [NC,OR]
RewriteCond %{HTTP_REFERER} keywords-monitoring-your-success.com
RewriteRule .* - [F]
Oh and they’re also running free-video-tool . com
It’s pretty obvious that spammers (i.e. the people controlling the compromised machines that are doing the work) are a bunch of stupid fuckwits…
This site gets between 10 and 20 spam comments a day… None of them have appeared because I use Askimet :
But they obviously never check that its working – mind you I guess they don’t give a shit, they’ve taken the money off the people selling fake NFL jerseys and fake pharmaceuticals so for them its money for old rope (hey – that’s an idea : lets sell Old Rope to people!!)
But the morons pushing out email spam are as bad:
Come on…. sending email to an address called spambucket is obviously destined for just one location : my spam bucket followed by SpamCop. The attachment was a rogue program – not that I use Windows so it wasn’t going anywhere anyway.
Sometimes they almost get it right – apparently PC world have an order for me :
All I needed to do was log into my PC world account and confirm details .. yeah right…. I’m just like everyone in that I order over £600 worth of computer without remembering… how anyone could fall for this I do not know.
Then there is the downright stupid and useless:
Lets make up a totally stupid email address and then use the first part of it in the body of the message..
The craziest thing is that THIS post (along with all the other ones I’ve posted about spammers in the past) will attract more spam comments than my other posts…
Or are they simply paying the people who spam such shit money that they can’t even run a script properly?
Look at this pile of crap that I found as a blocked comment today :
That’s only about 1/5th of the post….
This site, along with others I run, was swamped by traffic from Semalt in the past . Today the following article came to my attention which just confirms what I think myself and many other people had realised – that Semalt really are rogue and should be avoided and blocked at all costs. Here is the opening paragraph.
The software known as Semalt, which claims to be an ‘SEO tool,’ has been found to be using Soundfrost malware to hijack hundreds of thousands of computers. In the last 30 days, it has organized a huge spambot that is originating from more than 290,000 different IP addresses around the globe, with a concentration in South America.
Info Security Magazine
Also there is a very detailed blog entry over on nabble which gives a lot more detail and makes for pretty scary reading.
Well my scripts automatically add the IP address to the .htaccess file if it works out they are spamming.
Blocking a couple of domains in URLS got rid of a lot of crap. Block jo.pl and it will take out a lot of your spam as thats all they seem to host!