<?xml version="1.0" encoding="utf-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><language>en-us</language><copyright>Copyright 2006</copyright><managingEditor>palrich@gmail.com</managingEditor><webMaster>palrich@gmail.com</webMaster><lastBuildDate>Sun, 05 Feb 2012 07:29:53 +0000</lastBuildDate><pubDate>Sun, 05 Feb 2012 07:29:53 +0000</pubDate><ttl>60</ttl><generator>WeirdLooking.com</generator><link>http://www.weirdlooking.com/</link><description>WeirdLooking.com: Michael Barton's Blog</description><title>WeirdLooking.com: Michael Barton's Blog</title><image><url>http://www.weirdlooking.com/images/feed.png</url><title>WeirdLooking.com: Michael Barton's Blog</title><link>http://www.weirdlooking.com/</link></image><item><title>i don't like (comment) spam!</title><dc:creator>Michael Barton</dc:creator><link>http://www.weirdlooking.com/blog/i-dont-like-comment-spam</link><guid>http://www.weirdlooking.com/blog/i-dont-like-comment-spam</guid><pubDate>Fri, 23 Dec 2005 06:06:20 +0000</pubDate><description>You know, all of the comment spam is coming from the servers of Web hosting companies.&amp;nbsp; Which makes sense; they rarely monitor or charge for outgoing connections.&amp;nbsp; I assume that &lt;a href=&quot;http://www.weirdlooking.com/blog/4&quot; style=&quot;position: relative; padding-left: 8px; zoom: 1;&quot;&gt;&lt;span style=&quot;position: absolute; top: -5px; left: 0px; width: 16px; height: 16px; background: URL(http://www.weirdlooking.com/exticon?http%3A%2F%2Fwww.weirdlooking.com%2Fblog%2F4) no-repeat center center; -moz-opacity: 0.3; opacity: 0.3; filter:alpha(opacity=30);&quot;&gt;&lt;/span&gt;this page&lt;/a&gt; made its way into an automated comment spamming tool or something.&amp;nbsp; I&amp;rsquo;m going to delete most of that spam, I think.&amp;nbsp; Then I can remove the lame rel=&amp;rdquo;nofollow&amp;rdquo;s on comment links.&lt;br /&gt;&lt;br /&gt;As mentioned, I assume that this spam is posted by some sort of automated tool.&amp;nbsp; So, I have put an end to automated posting.&amp;nbsp; How, you ask?&amp;nbsp; I just hid one of those evil Unix timestamps in the form.&amp;nbsp; If you post a comment 30 minutes after that timestamp, it gives you an error (and a preview where you can click Submit again, so it&amp;rsquo;s not evil).&lt;br /&gt;&lt;br /&gt;Yeah, that&amp;rsquo;s easy to circumvent.&amp;nbsp; The form also includes a checksum of the time (generated via fantastic, super-secret cryptographic methods that you&amp;rsquo;ll never figure out, so don&amp;rsquo;t even bother trying).&amp;nbsp; The end result is that stale instances of the form, like those I assume live in a spammer&amp;rsquo;s database, won&amp;rsquo;t work.&lt;br /&gt;&lt;br /&gt;They could still easily download the page and scrape out a valid timestamp and checksum, but I think it&amp;rsquo;s probably enough for now to not be the low-hanging fruit.</description><category>computers and internet</category><category>spam</category><category>website</category><comments>http://www.weirdlooking.com/blog/i-dont-like-comment-spam#comments</comments><wfw:comment>http://www.weirdlooking.com/comments/46</wfw:comment><wfw:commentRss>http://www.weirdlooking.com/rss/comments/46</wfw:commentRss><slash:comments>9</slash:comments></item></channel></rss>
