<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><title type="text">WeirdLooking.com: Michael Barton's Blog</title><rights>Copyright 2006</rights><author><name>Michael Barton</name><email>palrich@gmail.com</email></author><updated>2012-02-05T07:31:20Z</updated><generator>WeirdLooking.com</generator><logo>http://www.weirdlooking.com/images/feed.png</logo><link rel="alternate" type="text/html" href="http://www.weirdlooking.com/" /><link rel="self" type="application/xml+atom" href="http://www.weirdlooking.com/atom/tag/spam" /><id>http://www.weirdlooking.com/</id><entry><title type="text">i don't like (comment) spam!</title><author><name>Michael Barton</name></author><link rel="alternate" type="text/html" href="http://www.weirdlooking.com/blog/i-dont-like-comment-spam" /><id>http://www.weirdlooking.com/blog/i-dont-like-comment-spam</id><published>2005-12-23T06:06:20Z</published><updated>2005-12-23T06:06:20Z</updated><content type="html">You know, all of the comment spam is coming from the servers of Web hosting companies.&amp;nbsp; Which makes sense; they rarely monitor or charge for outgoing connections.&amp;nbsp; I assume that &lt;a href=&quot;http://www.weirdlooking.com/blog/4&quot; style=&quot;position: relative; padding-left: 8px; zoom: 1;&quot;&gt;&lt;span style=&quot;position: absolute; top: -5px; left: 0px; width: 16px; height: 16px; background: URL(http://www.weirdlooking.com/exticon?http%3A%2F%2Fwww.weirdlooking.com%2Fblog%2F4) no-repeat center center; -moz-opacity: 0.3; opacity: 0.3; filter:alpha(opacity=30);&quot;&gt;&lt;/span&gt;this page&lt;/a&gt; made its way into an automated comment spamming tool or something.&amp;nbsp; I&amp;rsquo;m going to delete most of that spam, I think.&amp;nbsp; Then I can remove the lame rel=&amp;rdquo;nofollow&amp;rdquo;s on comment links.&lt;br /&gt;&lt;br /&gt;As mentioned, I assume that this spam is posted by some sort of automated tool.&amp;nbsp; So, I have put an end to automated posting.&amp;nbsp; How, you ask?&amp;nbsp; I just hid one of those evil Unix timestamps in the form.&amp;nbsp; If you post a comment 30 minutes after that timestamp, it gives you an error (and a preview where you can click Submit again, so it&amp;rsquo;s not evil).&lt;br /&gt;&lt;br /&gt;Yeah, that&amp;rsquo;s easy to circumvent.&amp;nbsp; The form also includes a checksum of the time (generated via fantastic, super-secret cryptographic methods that you&amp;rsquo;ll never figure out, so don&amp;rsquo;t even bother trying).&amp;nbsp; The end result is that stale instances of the form, like those I assume live in a spammer&amp;rsquo;s database, won&amp;rsquo;t work.&lt;br /&gt;&lt;br /&gt;They could still easily download the page and scrape out a valid timestamp and checksum, but I think it&amp;rsquo;s probably enough for now to not be the low-hanging fruit.</content><category term="computers and internet" /><category term="spam" /><category term="website" /><link rel="comments" type="application/atom+xml" href="http://www.weirdlooking.com/atom/comments/46" /><wfw:commentRss>http://www.weirdlooking.com/atom/comments/46</wfw:commentRss><slash:comments>9</slash:comments></entry></feed>
