Comment Spam II
No, I haven’t (yet) received any more since I took action.
But, as predicted, the spammers have become more diversified in their techniques, so it’s time to bring other webloggers up to date.
The spammers appear to be using two techniques currently:
- Find the URL of a comment-entry script (e.g.
mt-comments.cgi
) on Google and post a comment directly to that script. - Find a weblog entry by following a link from blogdex or daypop or technorati or wherever. Look for a comment-entry form on that page, and submit the form.
My previous article dealt with defeating the first technique. Since writing it, 40 spambots have gotten their URL’s added to my ban-list. At first, they were coming at a rate of 3 or 4 per day, but that has dropped off as my (former) comment-entry script URL’s have slowly disappeared from Google’s index.
The second technique has proven a problem for others. But it hasn’t affected me. I have no idea whether spambots using it have attempted to access my comment form. Why? Because I don’t have a comment-entry form on my individual archive page. You need to follow a link to get to the comment-entry form.
While easy for humans, figuring out which link to follow to reach the comment form adds an extra layer of complexity to the spambots. And it makes them susceptible to “honeypot” forms (“To get your IP Address permanently banned from this site, enter a comment below…”), among other devious things.
I haven’t bothered setting up a honeypot yet. And there are several other tricky techniques I could yet deploy. But those are for a future post. Remember my motto:
Posted by distler at November 17, 2003 10:29 AMKeep your powder dry!
Re: Comment Spam II
last month I was visited by a human spammer.