<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>Autarchy of the Private Cave &#187; spam</title> <atom:link href="https://bogdan.org.ua/tags/spam/feed" rel="self" type="application/rss+xml" /><link>https://bogdan.org.ua</link> <description>Tiny bits of bioinformatics, [web-]programming etc</description> <lastBuildDate>Wed, 28 Dec 2022 16:09:04 +0000</lastBuildDate> <language>en-US</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>https://wordpress.org/?v=3.8.27</generator> <item><title>The list of spammers emails</title><link>https://bogdan.org.ua/2013/11/13/the-list-of-spammers-emails.html</link> <comments>https://bogdan.org.ua/2013/11/13/the-list-of-spammers-emails.html#comments</comments> <pubDate>Wed, 13 Nov 2013 16:55:07 +0000</pubDate> <dc:creator><![CDATA[Bogdan]]></dc:creator> <category><![CDATA[Misc]]></category> <category><![CDATA[Web]]></category> <category><![CDATA[email]]></category> <category><![CDATA[spam]]></category> <guid
isPermaLink="false">http://bogdan.org.ua/?p=2029</guid> <description><![CDATA[All sane people agree that spam is a blight of the internet, be it email spam or comments spam or forum spam or any other form of unsolicited, blatant, shameless, out-of-context advertising. Multiple spam-fighting and spam-stopping systems are being developed. With automated spam, automated spam-fighting systems might be the only choice. Sending rightfully angry emails [&#8230;]]]></description> <content:encoded><![CDATA[<p>All sane people agree that spam is a blight of the internet, be it email spam or comments spam or forum spam or any other form of unsolicited, blatant, shameless, out-of-context advertising. Multiple spam-fighting and spam-stopping systems are being developed.</p><p>With automated spam, automated spam-fighting systems might be the only choice. Sending rightfully angry emails to ISPs to notify about their customers violating service agreements is probably a waste of effort (something tells me most of these complaints end up in the trash folder, or even in the&#8230; spam folder). However, I get a feeling that some spam is <strong>not</strong> automated &#8211; it appears to have been actually prepared and sent by a human. (Alternatively, spammers behind those spams simply have better software.) Anyway, some spams seem to contain valid contact data of the advertized entity &#8211; like an email.</p><p>The resulting idea is very simple and was probably already implemented somewhere by someone: simply publish online contact emails of the entities which, apparently, had chosen spam as the primary means of advertising. These emails will be sooner or later harvested by spammers, added to spam databases, and will start getting progressively more spam.</p><p>There are a few drawbacks to this approach:</p><ul><li>knowing spam-collection points enables &#8220;black PR&#8221;-like mass-mailings in the name of one&#8217;s competitor, double-hurting the innocents; I do not see a clear method of preventing this, other than by concealing spam collection methods;</li><li>human intelligence is required to identify if the contained email truly belongs to the advertised entity; this is fairly time-consuming, especially when scaled up; a possible solution (with its own problems) would be to build an online gateway for submitting curated spam samples, thus distributing the workload to all the participating volunteers;</li><li>the next logical step is actually harvesting and then publishing all the emails from the advertised website;</li><li>the biggest drawback, however, is low efficiency of this approach; increasing spam percentage will only be a mild nuisance, which isn&#8217;t likely to propagate high enough to affect spam-deciders; also, indirectly spamming someone&#8217;s mailbox will result in the loss of time, which could have been otherwise used for facebook and other important activities <img
src="https://bogdan.org.ua/wp-includes/images/smilies/icon_smile.gif" alt=":)" class="wp-smiley" /></li></ul><p>What do you think? Should such a method be used?</p><p>Below I provide a few sample records from real spam comments, which had true-looking emails. I&#8217;m including some extra meta-data. Ideally, this should be stored in some kind of a database.</p><p>Submitted on 2013/11/13 at 15:23 GMT<br
/> Author : Ð’Ð¸ÐºÑ‚Ð¾Ñ€ (IP: 95.134.110.37 , 37-110-134-95.pool.ukrtel.net)<br
/> E-mail : <a
href="mailto:aionind@yandex.ru" title="aionind@yandex.ru">aionind@yandex.ru</a><br
/> E-mail : <a
href="mailto:sale@aion-industry.ru" title="sale@aion-industry.ru">sale@aion-industry.ru</a><br
/> E-mail : <a
href="mailto:info@aion-industry.ru" title="info@aion-industry.ru">info@aion-industry.ru</a><br
/> Submitted on 2013/11/26 at 8:53 GMT<br
/> Author : Ð’Ð¸ÐºÑ‚Ð¾Ñ€ (IP: 95.134.146.235 , 235-146-134-95.pool.ukrtel.net)<br
/> E-mail : <a
href="mailto:kvazargr@yandex.ru" title="kvazargr@yandex.ru">kvazargr@yandex.ru</a><br
/> E-mail : <a
href="mailto:info@kvazar-gr.ru" title="info@kvazar-gr.ru">info@kvazar-gr.ru</a><br
/> Submitted on 2013/11/28 at 7:24 GMT<br
/> Author : Ð’Ð¸ÐºÑ‚Ð¾Ñ€ (IP: 95.134.117.155 , 155-117-134-95.pool.ukrtel.net)<br
/> E-mail : <a
href="mailto:relevater@yandex.ru" title="relevater@yandex.ru">relevater@yandex.ru</a><br
/> E-mail : <a
href="mailto:info@relevate.ru" title="info@relevate.ru">info@relevate.ru</a><br
/> E-mail : <a
href="mailto:support@relevate.ru" title="support@relevate.ru">support@relevate.ru</a><br
/> E-mail : <a
href="mailto:billing@relevate.ru" title="billing@relevate.ru">billing@relevate.ru</a></p><p>There&#8217;s definitely a need for a public database, API keys, and quorum algorithms&#8230;</p><p>Author : casinoworka (IP: 91.207.4.201 , 201.4.207.91.unknown.SteepHost.Net)<br
/> E-mail : <a
href="mailto:pharmacywork7777777@gmail.com" title="pharmacywork7777777@gmail.com">pharmacywork7777777@gmail.com</a><br
/> E-mail : <a
href="mailto:info@prowessmedical.com" title="info@prowessmedical.com">info@prowessmedical.com</a></p><p><a
class="a2a_button_citeulike" href="https://www.addtoany.com/add_to/citeulike?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2013%2F11%2F13%2Fthe-list-of-spammers-emails.html&amp;linkname=The%20list%20of%20spammers%20emails" title="CiteULike" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_pocket" href="https://www.addtoany.com/add_to/pocket?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2013%2F11%2F13%2Fthe-list-of-spammers-emails.html&amp;linkname=The%20list%20of%20spammers%20emails" title="Pocket" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_kindle_it" href="https://www.addtoany.com/add_to/kindle_it?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2013%2F11%2F13%2Fthe-list-of-spammers-emails.html&amp;linkname=The%20list%20of%20spammers%20emails" title="Kindle It" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_evernote" href="https://www.addtoany.com/add_to/evernote?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2013%2F11%2F13%2Fthe-list-of-spammers-emails.html&amp;linkname=The%20list%20of%20spammers%20emails" title="Evernote" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_pinterest" href="https://www.addtoany.com/add_to/pinterest?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2013%2F11%2F13%2Fthe-list-of-spammers-emails.html&amp;linkname=The%20list%20of%20spammers%20emails" title="Pinterest" rel="nofollow noopener" target="_blank"></a><a
class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share#url=https%3A%2F%2Fbogdan.org.ua%2F2013%2F11%2F13%2Fthe-list-of-spammers-emails.html&#038;title=The%20list%20of%20spammers%20emails" data-a2a-url="https://bogdan.org.ua/2013/11/13/the-list-of-spammers-emails.html" data-a2a-title="The list of spammers emails"><img
src="https://static.addtoany.com/buttons/share_save_120_16.png" alt="Share"></a></p>]]></content:encoded> <wfw:commentRss>https://bogdan.org.ua/2013/11/13/the-list-of-spammers-emails.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Debian: how to whitelist IP addresses in tumgrey-SPF</title><link>https://bogdan.org.ua/2013/08/07/debian-how-to-whitelist-ip-address-in-tumgrey-spf.html</link> <comments>https://bogdan.org.ua/2013/08/07/debian-how-to-whitelist-ip-address-in-tumgrey-spf.html#comments</comments> <pubDate>Wed, 07 Aug 2013 12:13:38 +0000</pubDate> <dc:creator><![CDATA[Bogdan]]></dc:creator> <category><![CDATA[*nix]]></category> <category><![CDATA[how-to]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[Debian]]></category> <category><![CDATA[mxguarddog]]></category> <category><![CDATA[spam]]></category> <category><![CDATA[SPF]]></category> <category><![CDATA[tumgreyspf]]></category> <guid
isPermaLink="false">http://bogdan.org.ua/?p=1970</guid> <description><![CDATA[SPF is nice for protecting your mail server from spam, but sometimes there is a need to bypass SPF checking. For example, if you rely on 3rd party servers to do spam protection for you Current setup: MX records point to the spam protection mail servers, which then connect to my server and deliver (hopefully [&#8230;]]]></description> <content:encoded><![CDATA[<p><a
href="http://en.wikipedia.org/wiki/Sender_Policy_Framework">SPF</a> is nice for protecting your mail server from spam, but sometimes there is a need to bypass SPF checking. For example, if you rely on 3rd party servers to do spam protection for you <img
src="https://bogdan.org.ua/wp-includes/images/smilies/icon_smile.gif" alt=":)" class="wp-smiley" /></p><p>Current setup:</p><ul><li>MX records point to the spam protection mail servers, which then</li><li>connect to my server and deliver (hopefully spam-free) mail.</li></ul><p>Problem: some senders (like last.fm) do have proper, strict SPF records. <a
href="http://packages.debian.org/squeeze/tumgreyspf">Tumgreyspf</a> on my server then rejects emails relayed through the spam-protection service.</p><p>If these spam protection relay servers are the only which send mail to your server, then it makes sense to fully disable/uninstall tumgreyspf. Putting tumgreyspf into the permanent &#8220;learning mode&#8221; (set <code>defaultSeedOnly = 1</code> in <code>/etc/tumgreyspf/tumgreyspf.conf</code>) may not fix the SPF problem described above, as SeedOnly seems to only affect greylisting, and not rejecting unauthorized senders.</p><p>Solution: whitelist relay server IPs.<br
/> <span
id="more-1970"></span></p><p>I will use MXGuardDog <a
href="http://mxguarddog.com">spam blocker</a> as an example. This solution is a slightly extended version of <a
href="http://noe.wikidot.com/tumgreyspf-whitelist">this one</a>, and used <a
href="https://github.com/linsomniac/tumgreyspf/blob/master/README">tumgreyspf README</a> as the reference.</p><ul><li>For each of the IPs you want to whitelist, create a directory tree under <code>/var/lib/tumgreyspf/config/client_address</code>. Here is a copy-pasteable example for MXGuardDog, based on their <a
href="http://www.mxguarddog.com/faq.ip_list/">list of server IPs</a>, valid as of August 2013:<br
/> <code><br
/> mkdir -p /var/lib/tumgreyspf/config/client_address/108/166/117<br
/> mkdir -p /var/lib/tumgreyspf/config/client_address/174/129/28<br
/> mkdir -p /var/lib/tumgreyspf/config/client_address/216/58/39<br
/> mkdir -p /var/lib/tumgreyspf/config/client_address/222/229/219<br
/> mkdir -p /var/lib/tumgreyspf/config/client_address/64/15/147<br
/> mkdir -p /var/lib/tumgreyspf/config/client_address/66/85/178<br
/> </code></li><li>Into each of these IP range-specific directories, put a config file, which disables checks (or symlink one). First, create <code>/etc/tumgreyspf/disable.conf</code> with the following lines in it:<br
/> <code><br
/> SPFSEEDONLY = 0<br
/> GREYLISTTIME = 600<br
/> CHECKERS =<br
/> OTHERCONFIGS =<br
/> </code><br
/> It is just like the <code>default.conf</code>, but has empty <code>CHECKERS</code> and <code>OTHERCONFIGS</code> lines.<br
/> Now, symlink it into each of the IP range directories:<br
/> <code><br
/> ln -s /etc/tumgreyspf/disable.conf /var/lib/tumgreyspf/config/client_address/108/166/117/__default__<br
/> ln -s /etc/tumgreyspf/disable.conf /var/lib/tumgreyspf/config/client_address/174/129/28/__default__<br
/> ln -s /etc/tumgreyspf/disable.conf /var/lib/tumgreyspf/config/client_address/216/58/39/__default__<br
/> ln -s /etc/tumgreyspf/disable.conf /var/lib/tumgreyspf/config/client_address/222/229/219/__default__<br
/> ln -s /etc/tumgreyspf/disable.conf /var/lib/tumgreyspf/config/client_address/64/15/147/__default__<br
/> ln -s /etc/tumgreyspf/disable.conf /var/lib/tumgreyspf/config/client_address/66/85/178/__default__<br
/> </code></li></ul><p>Note the double-underscores to the left and right of <code>default</code>.</p><p>That&#8217;s it.</p><p><a
class="a2a_button_citeulike" href="https://www.addtoany.com/add_to/citeulike?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2013%2F08%2F07%2Fdebian-how-to-whitelist-ip-address-in-tumgrey-spf.html&amp;linkname=Debian%3A%20how%20to%20whitelist%20IP%20addresses%20in%20tumgrey-SPF" title="CiteULike" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_pocket" href="https://www.addtoany.com/add_to/pocket?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2013%2F08%2F07%2Fdebian-how-to-whitelist-ip-address-in-tumgrey-spf.html&amp;linkname=Debian%3A%20how%20to%20whitelist%20IP%20addresses%20in%20tumgrey-SPF" title="Pocket" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_kindle_it" href="https://www.addtoany.com/add_to/kindle_it?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2013%2F08%2F07%2Fdebian-how-to-whitelist-ip-address-in-tumgrey-spf.html&amp;linkname=Debian%3A%20how%20to%20whitelist%20IP%20addresses%20in%20tumgrey-SPF" title="Kindle It" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_evernote" href="https://www.addtoany.com/add_to/evernote?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2013%2F08%2F07%2Fdebian-how-to-whitelist-ip-address-in-tumgrey-spf.html&amp;linkname=Debian%3A%20how%20to%20whitelist%20IP%20addresses%20in%20tumgrey-SPF" title="Evernote" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_pinterest" href="https://www.addtoany.com/add_to/pinterest?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2013%2F08%2F07%2Fdebian-how-to-whitelist-ip-address-in-tumgrey-spf.html&amp;linkname=Debian%3A%20how%20to%20whitelist%20IP%20addresses%20in%20tumgrey-SPF" title="Pinterest" rel="nofollow noopener" target="_blank"></a><a
class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share#url=https%3A%2F%2Fbogdan.org.ua%2F2013%2F08%2F07%2Fdebian-how-to-whitelist-ip-address-in-tumgrey-spf.html&#038;title=Debian%3A%20how%20to%20whitelist%20IP%20addresses%20in%20tumgrey-SPF" data-a2a-url="https://bogdan.org.ua/2013/08/07/debian-how-to-whitelist-ip-address-in-tumgrey-spf.html" data-a2a-title="Debian: how to whitelist IP addresses in tumgrey-SPF"><img
src="https://static.addtoany.com/buttons/share_save_120_16.png" alt="Share"></a></p>]]></content:encoded> <wfw:commentRss>https://bogdan.org.ua/2013/08/07/debian-how-to-whitelist-ip-address-in-tumgrey-spf.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>ExpressionEngine contact form (email module) spam vulnerability</title><link>https://bogdan.org.ua/2009/01/26/expressionengine-contact-form-email-module-spam-vulnerability.html</link> <comments>https://bogdan.org.ua/2009/01/26/expressionengine-contact-form-email-module-spam-vulnerability.html#comments</comments> <pubDate>Mon, 26 Jan 2009 09:50:05 +0000</pubDate> <dc:creator><![CDATA[Bogdan]]></dc:creator> <category><![CDATA[CMS]]></category> <category><![CDATA[PHP]]></category> <category><![CDATA[Programming]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[Web]]></category> <category><![CDATA[EE]]></category> <category><![CDATA[ExpressionEngine]]></category> <category><![CDATA[spam]]></category> <category><![CDATA[vulnerability]]></category> <guid
isPermaLink="false">http://bogdan.org.ua/?p=575</guid> <description><![CDATA[Yesterday I had a look at mod.email.php &#8211; the Email module of ExpressionEngine CMS. It appears that it is very easy to use ExpressionEngine&#8217;s contact form (which uses Email module) to send emails to arbitrary addresses &#8211; simply put, send spam using someone&#8217;s EE. And here&#8217;s why: recipients hidden field is passed to the client; [&#8230;]]]></description> <content:encoded><![CDATA[<p>Yesterday I had a look at mod.email.php &#8211; the Email module of ExpressionEngine CMS.</p><p>It appears that it is very easy to use ExpressionEngine&#8217;s contact form (which uses Email module) to send emails to arbitrary addresses &#8211; simply put, send spam using someone&#8217;s EE.</p><p>And here&#8217;s why:</p><ul><li><em>recipients</em> hidden field is passed to the client; it is encrypted, but with access to the mod.email.php code, it is a matter of several minutes to write your own email-encoding function which will produce a completely valid <em>recipients</em> field</li><li>there&#8217;s also <em>XID</em> field, which seems to be unique for each page load</li></ul><p>Spamming algorithm is clear, so I won&#8217;t elaborate. (I could have missed some session variables, though &#8211; didn&#8217;t check them.)</p><p>This information is valid as of ExpressionEngine 1.6.6, but nothing in the change-logs indicates that this mechanism was modified in the newer versions of EE.</p><p><ins
datetime="2009-01-26T13:12:42+00:00">Update:</ins> I&#8217;ve tested, and this vulnerability does exist. The simplest prevention measure is to enable Captcha for Contact Form.</p><p>I&#8217;ve <a
href="http://expressionengine.com/archived_forums/viewthread/103537/" class="broken_link" rel="nofollow">notified</a> the developers.</p><p><a
class="a2a_button_citeulike" href="https://www.addtoany.com/add_to/citeulike?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F01%2F26%2Fexpressionengine-contact-form-email-module-spam-vulnerability.html&amp;linkname=ExpressionEngine%20contact%20form%20%28email%20module%29%20spam%20vulnerability" title="CiteULike" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_pocket" href="https://www.addtoany.com/add_to/pocket?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F01%2F26%2Fexpressionengine-contact-form-email-module-spam-vulnerability.html&amp;linkname=ExpressionEngine%20contact%20form%20%28email%20module%29%20spam%20vulnerability" title="Pocket" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_kindle_it" href="https://www.addtoany.com/add_to/kindle_it?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F01%2F26%2Fexpressionengine-contact-form-email-module-spam-vulnerability.html&amp;linkname=ExpressionEngine%20contact%20form%20%28email%20module%29%20spam%20vulnerability" title="Kindle It" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_evernote" href="https://www.addtoany.com/add_to/evernote?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F01%2F26%2Fexpressionengine-contact-form-email-module-spam-vulnerability.html&amp;linkname=ExpressionEngine%20contact%20form%20%28email%20module%29%20spam%20vulnerability" title="Evernote" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_pinterest" href="https://www.addtoany.com/add_to/pinterest?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F01%2F26%2Fexpressionengine-contact-form-email-module-spam-vulnerability.html&amp;linkname=ExpressionEngine%20contact%20form%20%28email%20module%29%20spam%20vulnerability" title="Pinterest" rel="nofollow noopener" target="_blank"></a><a
class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share#url=https%3A%2F%2Fbogdan.org.ua%2F2009%2F01%2F26%2Fexpressionengine-contact-form-email-module-spam-vulnerability.html&#038;title=ExpressionEngine%20contact%20form%20%28email%20module%29%20spam%20vulnerability" data-a2a-url="https://bogdan.org.ua/2009/01/26/expressionengine-contact-form-email-module-spam-vulnerability.html" data-a2a-title="ExpressionEngine contact form (email module) spam vulnerability"><img
src="https://static.addtoany.com/buttons/share_save_120_16.png" alt="Share"></a></p>]]></content:encoded> <wfw:commentRss>https://bogdan.org.ua/2009/01/26/expressionengine-contact-form-email-module-spam-vulnerability.html/feed</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>Spam Karma 2 (SK2) is a life saver plugin</title><link>https://bogdan.org.ua/2008/04/09/spam-karma-2-sk2-is-a-life-saver-plugin.html</link> <comments>https://bogdan.org.ua/2008/04/09/spam-karma-2-sk2-is-a-life-saver-plugin.html#comments</comments> <pubDate>Wed, 09 Apr 2008 12:29:52 +0000</pubDate> <dc:creator><![CDATA[Bogdan]]></dc:creator> <category><![CDATA[CMS]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[Web]]></category> <category><![CDATA[WP PlugIns]]></category> <category><![CDATA[karma]]></category> <category><![CDATA[plugin]]></category> <category><![CDATA[protection]]></category> <category><![CDATA[spam]]></category> <category><![CDATA[spam karma]]></category> <guid
isPermaLink="false">http://bogdan.org.ua/?p=289</guid> <description><![CDATA[As an update to WordPress anti-spam plugins, I highly recommend Spam Karma 2. For a time, it seems to be the ultimate protection. I turned off all the other anti-spam plugins (including Aksimet), and everything&#8217;s just perfect! SK2 gathers up to a thousand spam comments/trackbacks during a single week on this blog, and I never [&#8230;]]]></description> <content:encoded><![CDATA[<p>As an update to <a
href="http://bogdan.org.ua/2007/01/22/wordpress-anti-spam-plugins.html">WordPress anti-spam plugins</a>, I highly recommend <a
href="http://unknowngenius.com/blog/wordpress/spam-karma/">Spam Karma 2</a>. For a time, it seems to be the ultimate protection. I turned off all the other anti-spam plugins (including Aksimet), and everything&#8217;s just perfect! <a
href="http://unknowngenius.com/blog/wordpress/spam-karma/">SK2</a> gathers up to a thousand spam comments/trackbacks during a single week on this blog, and I never had a complaint from blog visitors on their inability to add a comment (though some did have to fill in captcha to post a comment with links).</p><p>And SK2 still works under WP 2.5! (SK 2.3 was released to support WP 2.1)</p><p>Kudos to <a
href="http://unknowngenius.com/blog/">Dave</a>!</p><p>It would be a pity if this excellent plugin is abandoned and stops functioning in one of the upcoming WP releases.</p><p><ins
datetime="2008-07-14T23:03:36+00:00">Update:</ins> <a
href="http://unknowngenius.com/blog/archives/2008/07/14/spam-karma-is-gpl/">SpamKarma is now GPL</a> (at <a
href="http://code.google.com/p/spam-karma/">google code</a>).</p><p><a
class="a2a_button_citeulike" href="https://www.addtoany.com/add_to/citeulike?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2008%2F04%2F09%2Fspam-karma-2-sk2-is-a-life-saver-plugin.html&amp;linkname=Spam%20Karma%202%20%28SK2%29%20is%20a%20life%20saver%20plugin" title="CiteULike" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_pocket" href="https://www.addtoany.com/add_to/pocket?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2008%2F04%2F09%2Fspam-karma-2-sk2-is-a-life-saver-plugin.html&amp;linkname=Spam%20Karma%202%20%28SK2%29%20is%20a%20life%20saver%20plugin" title="Pocket" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_kindle_it" href="https://www.addtoany.com/add_to/kindle_it?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2008%2F04%2F09%2Fspam-karma-2-sk2-is-a-life-saver-plugin.html&amp;linkname=Spam%20Karma%202%20%28SK2%29%20is%20a%20life%20saver%20plugin" title="Kindle It" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_evernote" href="https://www.addtoany.com/add_to/evernote?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2008%2F04%2F09%2Fspam-karma-2-sk2-is-a-life-saver-plugin.html&amp;linkname=Spam%20Karma%202%20%28SK2%29%20is%20a%20life%20saver%20plugin" title="Evernote" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_pinterest" href="https://www.addtoany.com/add_to/pinterest?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2008%2F04%2F09%2Fspam-karma-2-sk2-is-a-life-saver-plugin.html&amp;linkname=Spam%20Karma%202%20%28SK2%29%20is%20a%20life%20saver%20plugin" title="Pinterest" rel="nofollow noopener" target="_blank"></a><a
class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share#url=https%3A%2F%2Fbogdan.org.ua%2F2008%2F04%2F09%2Fspam-karma-2-sk2-is-a-life-saver-plugin.html&#038;title=Spam%20Karma%202%20%28SK2%29%20is%20a%20life%20saver%20plugin" data-a2a-url="https://bogdan.org.ua/2008/04/09/spam-karma-2-sk2-is-a-life-saver-plugin.html" data-a2a-title="Spam Karma 2 (SK2) is a life saver plugin"><img
src="https://static.addtoany.com/buttons/share_save_120_16.png" alt="Share"></a></p>]]></content:encoded> <wfw:commentRss>https://bogdan.org.ua/2008/04/09/spam-karma-2-sk2-is-a-life-saver-plugin.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>WordPress [Anti-]Spam plugins</title><link>https://bogdan.org.ua/2007/01/22/wordpress-anti-spam-plugins.html</link> <comments>https://bogdan.org.ua/2007/01/22/wordpress-anti-spam-plugins.html#comments</comments> <pubDate>Mon, 22 Jan 2007 15:25:26 +0000</pubDate> <dc:creator><![CDATA[Bogdan]]></dc:creator> <category><![CDATA[Web]]></category> <category><![CDATA[WP PlugIns]]></category> <category><![CDATA[karma]]></category> <category><![CDATA[spam]]></category> <guid
isPermaLink="false">http://www.bogdan.org.ua/2007/01/22/wordpress-anti-spam-plugins.html</guid> <description><![CDATA[You may discover, that as your blog gets more visitors and pageviews, your are getting more spam in comments to your posts. They originate as actually comments, pings, and trackbacks. Fighting spam nowadays is a common task. If you check the statistics of spam-fighting software, installed either on your client machine, or on the servers [&#8230;]]]></description> <content:encoded><![CDATA[<p>You may discover, that as your blog gets more visitors and pageviews, your are getting more spam in comments to your posts. They originate as actually comments, pings, and trackbacks.<br
/> <span
id="more-105"></span><br
/> Fighting spam nowadays is a common task. If you check the statistics of spam-fighting software, installed either on your client machine, or on the servers of your company, you might be surprised by the fact that spam traffic and quantities of letters are higher than non-spam.</p><p>One could think that as the spam-problem is fairly well known, there should be reliable methods to get rid of spam. However, the spam problem is like the &#8220;weapon-shield&#8221; competition: the stronger the weapon, the thicker the shield. Spammers adapt, unfortunately.</p><p>Getting down to business. In this post I&#8217;ll describe how I am solving the spam problem in my blog.</p><p>The first plugin is <a
href="http://www.g-loaded.eu/2006/04/02/comment-policy-wordpress-plugin/">Comment Policy</a>. It adds a required checkbox below the comment form, which needs to be checked in order to successfully post a comment. Checkbox field name is auto-modified by JavaScript, which means that clients (preferably spam bots) without JavaScript support will be unable to post a comment. Thus, comment policy stops non-JavaScript spam bots.</p><p>Note, that this plugin defends only the comments, not pings/trackbacks.</p><p>It can be argued that JavaScript requirement might prevent people from posting comments &#8211; true, but with all those Ajax interfaces only the tiny percent of visitors would have JS disabled. Visitors with text browsers (lynx, links, etc) would be the only group unable to post&#8230; which is bad.</p><p>The reason I keep this plugin is the presence of the actual comments policy, which clearly states what kinds of comments will not be allowed. Overkill, I know <img
src="https://bogdan.org.ua/wp-includes/images/smilies/icon_smile.gif" alt=":)" class="wp-smiley" /></p><p>Another plugin is <a
href="http://guff.szub.net/2005/08/23/email-immunizer/">email immunizer</a>. It is supposed to protect mailto: links from harvesters. Never tested it, though: I do not post mailto: links. This is a just-in-case measure.</p><p><a
href="http://www.theblog.ca/anti-spam">Peter&#8217;s Custom Anti-Spam</a> is a Captcha plugin, i.e. it displays some text as a picture, requiring the text be input into the provided field. Evidently, protects only comments. Not 100% efficient, as there are bots able to read images. Fortunately, the majority cannot :). This plugin is only one from <a
href="http://wordpress.org/plugins/tags/spam">many</a>, and I chose it for no specific reasons &#8211; except that it is &#8220;fresh&#8221;, requires no additional accounts hosted somewhere, and is rather small. You can extend the list of captcha words with your own, which can be fun if used properly :).</p><p><a
href="http://sw-guide.de/wordpress/plugins/simple-trackback-validation/">Simple trackback validation</a> checks if the referring page exists and contains a link to your blog. If it doesn&#8217;t &#8211; the trackback/ping can be held for moderation, added to the akismet&#8217;s spam queue, or simply deleted. This is a good one to have.</p><p>WP-ContactForm is not really spam-protection, but it helps you avoid publishing email address in any form, but people can still <a
href="http://bogdan.org.ua/contact">contact</a> you. Note, that my contact form is protected by a &#8220;math captcha&#8221;: there is a trivial math question, which requires a single numeric answer. This is also good protection &#8211; not a single spam message from the contact form after protection was installed!</p><p>Corrections, questions, additions and comments on what you&#8217;re using are welcome.</p><p><ins
datetime="2007-08-22T11:01:40+00:00">Update:</ins> since I started using SpamKarma2 plugin, all other plugins nearly lost their usefulness. SpamKarma2 is excellent &#8211; try it! Since mid-late 2007 by Jan 2008 over 100000 spam comments were discarded on my blog by SpamKarma2, which has gone GPL way.</p><p><a
class="a2a_button_citeulike" href="https://www.addtoany.com/add_to/citeulike?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2007%2F01%2F22%2Fwordpress-anti-spam-plugins.html&amp;linkname=WordPress%20%5BAnti-%5DSpam%20plugins" title="CiteULike" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_pocket" href="https://www.addtoany.com/add_to/pocket?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2007%2F01%2F22%2Fwordpress-anti-spam-plugins.html&amp;linkname=WordPress%20%5BAnti-%5DSpam%20plugins" title="Pocket" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_kindle_it" href="https://www.addtoany.com/add_to/kindle_it?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2007%2F01%2F22%2Fwordpress-anti-spam-plugins.html&amp;linkname=WordPress%20%5BAnti-%5DSpam%20plugins" title="Kindle It" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_evernote" href="https://www.addtoany.com/add_to/evernote?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2007%2F01%2F22%2Fwordpress-anti-spam-plugins.html&amp;linkname=WordPress%20%5BAnti-%5DSpam%20plugins" title="Evernote" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_pinterest" href="https://www.addtoany.com/add_to/pinterest?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2007%2F01%2F22%2Fwordpress-anti-spam-plugins.html&amp;linkname=WordPress%20%5BAnti-%5DSpam%20plugins" title="Pinterest" rel="nofollow noopener" target="_blank"></a><a
class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share#url=https%3A%2F%2Fbogdan.org.ua%2F2007%2F01%2F22%2Fwordpress-anti-spam-plugins.html&#038;title=WordPress%20%5BAnti-%5DSpam%20plugins" data-a2a-url="https://bogdan.org.ua/2007/01/22/wordpress-anti-spam-plugins.html" data-a2a-title="WordPress [Anti-]Spam plugins"><img
src="https://static.addtoany.com/buttons/share_save_120_16.png" alt="Share"></a></p>]]></content:encoded> <wfw:commentRss>https://bogdan.org.ua/2007/01/22/wordpress-anti-spam-plugins.html/feed</wfw:commentRss> <slash:comments>1</slash:comments> </item> </channel> </rss>