## January 21, 2004

### One Down

So I finally did get visited by one of the Crapflooders. Phil was visited by the same fellow earlier in the evening and I guess that, by the time he got to me, he was all tuckered-out. The attack on my blog was as brief (10 minutes) as it was ineffective.

I did, however, amass some most excellent forensics on our friend. I’ll let y’all know what comes of the matter.

Posted by distler at January 21, 2004 10:40 PM

### Re: One Down

Quit linking to my domain or I will use mod_rewrite to redirect everyone with your site in the referer to a VERY NASTY SITE.

Posted by: Dv on January 22, 2004 3:21 AM | Permalink | Reply to this

What’s the matter, Dv? Your site can’t handle the traffic?

That would be rich, indeed!

Hey everyone! Please bookmark http://terrato.org/index.pl?FloodMT . And be sure to visit it often to check out the latest “developments” in Crapflooding technology.

Please be considerate, however. Dv’s software is not exactly the most resilient. We don’t want it to buckle under the load.

(Linking to Dv’s site is also an option. But Dv might retaliate by attempting to crapflood you. Best to install some protection first.)

Posted by: Jacques Distler on January 22, 2004 7:39 AM | Permalink | Reply to this

### Re: Crushed by the load?

RewriteCond %{HTTP_REFERER} ^http://.*golem.ph.utexas.edu/ [NC]
RewriteRule .* http://hick.org/goat/hello.jpg [L]

Posted by: Dv on January 22, 2004 2:07 PM | Permalink | Reply to this

### Re: Crushed by the load?

I thought Stavros covered that from our perspective pretty well.

Heh. Goatse and Tubgirl are like old friends by now…they’re ugly, but it just doesn’t feel right if they’re not around.

Sorry, you aren’t shocking or scary or anything else but a nuisance.

Posted by: Phil Ringnalda on January 22, 2004 4:43 PM | Permalink | Reply to this

### Re: Crushed by the load?

He enjoys being a nuisance. Responding to him is just acknowledgement and encouragement.

Posted by: k on January 22, 2004 5:01 PM | Permalink | Reply to this

### Thanks, that helps

If you want to help out Dv and test his re-write rules, make sure to spoof your referrer to golem.ph.utexas.edu.

But remember, kids, mod-rewrite adds additional server load. So don’t create a bot that automatically tests his rules every few seconds. That wouldn’t be very nice. Especially if you were to use a big list of anonymous proxies to make it difficult for him to block the traffic.

But if you were to want to do such a thing, Dv hosts some code that will help you hop across proxies. Isn’t that nice of him?

### Be nice

While I appreciate the “Live by the sword, die by the sword” ethos, crapflooding is not a sport intelligent people engage in.

And besides, the net effect would simply be to teach these dullards some new tricks to use when they resurface elsewhere.

Posted by: Jacques Distler on January 23, 2004 6:36 AM | Permalink | Reply to this
### Re: One Down

Woops sorry about those trackbacks, I have a problem with someone installing a transparent proxy and it times out before MT gets in gear.

The shame of it!

Posted by: Chris on January 22, 2004 4:56 AM | Permalink | Reply to this

### Re: One Down

No problem Chris!

One thing you, and all the other MTers in the audience might want to do is go into mt.cfg and uncomment the line

PingTimeout 30

The default value of 15 seconds is way too short. 30 seconds is more like it, and will reduce the number of duplicate pings (not, perhaps, in this case, but in general).

Posted by: Jacques Distler on January 22, 2004 7:53 AM | Permalink | Reply to this

### Re: One Down

Cheers done that and set the timouts on squid through the roof too.

Let’s see how it goes.

Posted by: Chris on January 22, 2004 3:01 PM | Permalink | Reply to this

### Re: One Down

Cute.

*sigh*

Posted by: ACJ on January 22, 2004 3:36 PM | Permalink | Reply to this

### Re: One Down

I see that TrackBack spam is the new comment spam. :/

Posted by: Josh on January 22, 2004 4:40 PM | Permalink | Reply to this

### Re: One Down

The beauty of this blog is that it was all well-formed, valid trackback spam.

Posted by: jacob on January 22, 2004 4:57 PM | Permalink | Reply to this
### took them long enough

So it’s been six months since comment spamming begain in earnest. And they’re just now figuring out that TrackBack was designed for automated, remote commenting? Sheesh.