<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Dissecting Comment Spam</title>
	<atom:link href="http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam/feed" rel="self" type="application/rss+xml" />
	<link>http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam</link>
	<description>My random thoughts about stuff</description>
	<lastBuildDate>Thu, 03 May 2007 15:53:21 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Will&#8217;s Blog  &#187; Blog Archive   &#187; Another spam referrer</title>
		<link>http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam/comment-page-1#comment-9317</link>
		<dc:creator>Will&#8217;s Blog  &#187; Blog Archive   &#187; Another spam referrer</dc:creator>
		<pubDate>Sat, 05 Mar 2005 00:40:41 +0000</pubDate>
		<guid isPermaLink="false">http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam#comment-9317</guid>
		<description>[...] lso came a few times to my blog via the http://12.163.72.13 non-existant URL (as mentioned previously) 	Looks like our spammers are evolving as they see fit to do so, but [...]</description>
		<content:encoded><![CDATA[<p>[...] lso came a few times to my blog via the <a href="http://12.163.72.13" rel="nofollow">http://12.163.72.13</a> non-existant URL (as mentioned previously) 	Looks like our spammers are evolving as they see fit to do so, but [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Raftery</title>
		<link>http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam/comment-page-1#comment-6032</link>
		<dc:creator>Tom Raftery</dc:creator>
		<pubDate>Wed, 02 Feb 2005 10:21:29 +0000</pubDate>
		<guid isPermaLink="false">http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam#comment-6032</guid>
		<description>Will, the code Cindy sent to you has an error - there should be no OR in the line before the ReWriteRule.

In other words it should look like:
RewriteCond %{HTTP_USER_AGENT} (Fetch\ API\ Request) [NC,OR]
RewriteCond %{HTTP_USER_AGENT} (Microsoft\ Scheduled\ Cache\ Content\ Download\ Service) [NC]
RewriteRule .* - [F]

In my own .htaccess file, I took a different approach, I blocked the ip and it has worked so far. Here&#039;s what I entered in my .htaccess file:
RewriteCond %{REMOTE_ADDR} ^12\.163\.72\.13$
RewriteRule .* - [F,L]

Hope this helps,

Tom</description>
		<content:encoded><![CDATA[<p>Will, the code Cindy sent to you has an error &#8211; there should be no OR in the line before the ReWriteRule.</p>
<p>In other words it should look like:<br />
RewriteCond %{HTTP_USER_AGENT} (Fetch\ API\ Request) [NC,OR]<br />
RewriteCond %{HTTP_USER_AGENT} (Microsoft\ Scheduled\ Cache\ Content\ Download\ Service) [NC]<br />
RewriteRule .* &#8211; [F]</p>
<p>In my own .htaccess file, I took a different approach, I blocked the ip and it has worked so far. Here&#8217;s what I entered in my .htaccess file:<br />
RewriteCond %{REMOTE_ADDR} ^12\.163\.72\.13$<br />
RewriteRule .* &#8211; [F,L]</p>
<p>Hope this helps,</p>
<p>Tom</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ann Elisabeth's blog</title>
		<link>http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam/comment-page-1#comment-5645</link>
		<dc:creator>Ann Elisabeth's blog</dc:creator>
		<pubDate>Thu, 27 Jan 2005 23:50:00 +0000</pubDate>
		<guid isPermaLink="false">http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam#comment-5645</guid>
		<description>&lt;strong&gt;12.163.72.13/Fetch API&lt;/strong&gt;
Several of us got lines in our logs, with that IP number as the referrer. No website, just that IP number dressed up as a site address. It&#039;s similar to the Bulgarian spammer machine, and uses proxies. So I did...</description>
		<content:encoded><![CDATA[<p><strong>12.163.72.13/Fetch API</strong><br />
Several of us got lines in our logs, with that IP number as the referrer. No website, just that IP number dressed up as a site address. It&#8217;s similar to the Bulgarian spammer machine, and uses proxies. So I did&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ck</title>
		<link>http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam/comment-page-1#comment-134</link>
		<dc:creator>ck</dc:creator>
		<pubDate>Sun, 24 Oct 2004 08:11:19 +0000</pubDate>
		<guid isPermaLink="false">http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam#comment-134</guid>
		<description>re. WP stripping words - what is a trailing?
And thanks for the tip - that comment spam is getting totally out of hand.</description>
		<content:encoded><![CDATA[<p>re. WP stripping words &#8211; what is a trailing?<br />
And thanks for the tip &#8211; that comment spam is getting totally out of hand.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: the lil lioness =^.^=</title>
		<link>http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam/comment-page-1#comment-133</link>
		<dc:creator>the lil lioness =^.^=</dc:creator>
		<pubDate>Thu, 21 Oct 2004 04:09:59 +0000</pubDate>
		<guid isPermaLink="false">http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam#comment-133</guid>
		<description>&lt;strong&gt;Protect yourself (and your friends)&lt;/strong&gt;
My friends and I recieved over 2500 comment spams over the past 48-hours... me, being the blog admin had the pleasure of recieving all the notifications that there were comments awaiting moderation, and now have th eplasure of ddeleting the comments an...</description>
		<content:encoded><![CDATA[<p><strong>Protect yourself (and your friends)</strong><br />
My friends and I recieved over 2500 comment spams over the past 48-hours&#8230; me, being the blog admin had the pleasure of recieving all the notifications that there were comments awaiting moderation, and now have th eplasure of ddeleting the comments an&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fiona</title>
		<link>http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam/comment-page-1#comment-124</link>
		<dc:creator>Fiona</dc:creator>
		<pubDate>Mon, 18 Oct 2004 01:45:43 +0000</pubDate>
		<guid isPermaLink="false">http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam#comment-124</guid>
		<description>Thanks will. Second bit didn&#039;t work though.. .well it stopped me from accessing, giving me a 500 error</description>
		<content:encoded><![CDATA[<p>Thanks will. Second bit didn&#8217;t work though.. .well it stopped me from accessing, giving me a 500 error</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: William Luu</title>
		<link>http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam/comment-page-1#comment-123</link>
		<dc:creator>William Luu</dc:creator>
		<pubDate>Sun, 17 Oct 2004 01:18:26 +0000</pubDate>
		<guid isPermaLink="false">http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam#comment-123</guid>
		<description>Hi Cindy, cool! Thanks for the tip! I didn&#039;t notice those two user agents until now. I checked through my server logs, thus far I&#039;ve only found the Fetch API Request one, and not the Microsoft Scheduled Cache Content Download Service.

I&#039;ll update the post with your advice!</description>
		<content:encoded><![CDATA[<p>Hi Cindy, cool! Thanks for the tip! I didn&#8217;t notice those two user agents until now. I checked through my server logs, thus far I&#8217;ve only found the Fetch API Request one, and not the Microsoft Scheduled Cache Content Download Service.</p>
<p>I&#8217;ll update the post with your advice!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cindy</title>
		<link>http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam/comment-page-1#comment-122</link>
		<dc:creator>cindy</dc:creator>
		<pubDate>Sat, 16 Oct 2004 20:00:25 +0000</pubDate>
		<guid isPermaLink="false">http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam#comment-122</guid>
		<description>I found that they are using two other agents to harvest the comment link url&#039;s.  I have blocked them too.  Check your server logs and I bet you find them too.

RewriteCond %{HTTP_USER_AGENT} (Fetch\ API\ Request) [NC,OR]
RewriteCond %{HTTP_USER_AGENT} (Microsoft\ Scheduled\ Cache\ Content\ Download\ Service) [NC,OR]
RewriteRule .* - [F] 

It may block some valid offline page readers but better that than spam.  I&#039;m not even running MT or WordPress and they still got me... until I blocked them.</description>
		<content:encoded><![CDATA[<p>I found that they are using two other agents to harvest the comment link url&#8217;s.  I have blocked them too.  Check your server logs and I bet you find them too.</p>
<p>RewriteCond %{HTTP_USER_AGENT} (Fetch\ API\ Request) [NC,OR]<br />
RewriteCond %{HTTP_USER_AGENT} (Microsoft\ Scheduled\ Cache\ Content\ Download\ Service) [NC,OR]<br />
RewriteRule .* &#8211; [F] </p>
<p>It may block some valid offline page readers but better that than spam.  I&#8217;m not even running MT or WordPress and they still got me&#8230; until I blocked them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: the lil lioness =^.^= &#187; Protect yourself (and your friends)</title>
		<link>http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam/comment-page-1#comment-132</link>
		<dc:creator>the lil lioness =^.^= &#187; Protect yourself (and your friends)</dc:creator>
		<pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam#comment-132</guid>
		<description>[...] e th eplasure of ddeleting the comments and the emails&#8230; 	 	Protect yourself, people! &lt;a href=&quot;http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam&quot; targegt=&quot;_blank&quot;&gt;Will has a great post on getting rid of spammers&lt;/a&gt; - basically, [...]</description>
		<content:encoded><![CDATA[<p>[...] e th eplasure of ddeleting the comments and the emails&#8230; 	 	Protect yourself, people! <a href="http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam" targegt="_blank">Will has a great post on getting rid of spammers</a> &#8211; basically, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Will's Blog &#187; GoogleRank, Spammers, Phising</title>
		<link>http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam/comment-page-1#comment-136</link>
		<dc:creator>Will's Blog &#187; GoogleRank, Spammers, Phising</dc:creator>
		<pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam#comment-136</guid>
		<description>[...] k of 4/10. 	[If you don&#8217;t know why that above web address is of interest, go read my &lt;a href=&quot;http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam&quot; target=&quot;_blank&quot;&gt;previous post&lt;/a&gt;]. 	So how does a website that does not exist, end [...]</description>
		<content:encoded><![CDATA[<p>[...] k of 4/10. 	[If you don&#8217;t know why that above web address is of interest, go read my <a href="http://will.id.au/blog/archive/2004/10/06/dissecting-comment-spam" target="_blank">previous post</a>]. 	So how does a website that does not exist, end [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

