guestbook spam cure wanted

The machines we love to hate

Moderator: Wiz Feinberg

User avatar
Anders Brundell
Posts: 636
Joined: 2 Nov 1999 1:01 am
Location: Falun, Sweden

guestbook spam cure wanted

Post by Anders Brundell »

Our guest book gets spammed with viagra ads and other crap all the time. New spam comes in no matter how often I clean it up. Is there any program or something that can cure this?
Take a look at http://www.countrysweden.com/dcmc/gastbok/gastbok.asp

Thanks on beforehand!
Anders
User avatar
Jim Cohen
Posts: 21844
Joined: 18 Nov 1999 1:01 am
Location: Philadelphia, PA

Post by Jim Cohen »

I have the same problem with Dreambook.com who provides my free guestbook. My band's guestbook is spammed every 2 or 3 days now, by the same person. Dreambook has a feature to alert you whenever anyone signs your guestbook, and will send you an email that includes the text of what they wrote in the book. So now I quickly jump on it, go to the site and delete it, usually within a few minutes after its been posted (if I'm near my computer at the time).

Dreambook also has a feature to prevent this computer from ever signing your guestbook again. Of course I use that, but this person seems to use a different computer each time.

Personally, I think it's Howard.
(just kidding)
Bobby D. Hunter
Posts: 165
Joined: 24 Jul 2004 12:01 am
Location: USA

Post by Bobby D. Hunter »

Try reading your raw access log for the time periods when the comment spammer does his thing, and ban that IP address each time. You will probably find that he is spamming you through transparent open proxies. No actual person is likely to visit you via one of these proxies so banning them all won't hurt your website.

Another thing you can try is redirecting all spam comment URLs to the spamvertized location, thus the spammer will spam his own websites' logs.

Both of the above solutions require a knowledge of and permission to use .htaccess mod_access and mod_rewrite directives.

Another solution is to switch to a different guestbook script that provides a mechanism for detecting spam words in the URL and deleting that post before it goes live. You can also look for a script that challenges the commentor with a scrambled image that must be typed into an input field before the comment is submitted. The latter will totally eliminate all automated comment spam, but not human inputted spam. It is unlikely that this person is actually visiting your guestbook from so many different locations. He is most likely using an automated script to spam all vulnerable guestbooks at once.

------------------
Bobby D. Hunter
Security for SGF
Hunting down Slimeball Game
Reporting member of SpamCop

<font size="1" color="#8e236b"><p align="center">[This message was edited by Bobby D. Hunter on 09 February 2006 at 08:25 AM.]</p></FONT>
User avatar
Anders Brundell
Posts: 636
Joined: 2 Nov 1999 1:01 am
Location: Falun, Sweden

Post by Anders Brundell »

Thanks, Bobby!

I'll ask some friends of mine to explain and execute what you've described. I'm not able to understand this myself, sorry to say.

Anders