<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Wordpress Plugins &#187; Spam</title>
	<atom:link href="http://wordpress-plugins.feifei.us/category/spam/feed/" rel="self" type="application/rss+xml" />
	<link>http://wordpress-plugins.feifei.us</link>
	<description>WP Plugins and Widgets For Wordpress 2.1+</description>
	<lastBuildDate>Fri, 03 Jul 2009 03:40:37 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Pagerank Forum Spam</title>
		<link>http://wordpress-plugins.feifei.us/42/pagerank-forum-spam/</link>
		<comments>http://wordpress-plugins.feifei.us/42/pagerank-forum-spam/#comments</comments>
		<pubDate>Thu, 26 Feb 2009 00:20:58 +0000</pubDate>
		<dc:creator>Elliott Back</dc:creator>
				<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://wordpress-plugins.feifei.us/?p=42</guid>
		<description><![CDATA[I hate nothing more than showing up on a forum article by Turkish spammers about how to get backlinks.  Clearly they&#8217;re well behind the times, as not only are all my blogs nofollow, but also I delete spam with vigour.  The article in question (run through Google translate) says roughly:
5 ** 6 ** [...]]]></description>
			<content:encoded><![CDATA[<p>I hate nothing more than showing up on a <a href="http://www.r10.net/dmoz-ve-diger-dizinler/298686-2-page-ranking-6-6-page-ranking-5-10-pr4-ve-daha-fazla-backlink.html" rel="nofollow">forum article</a> by Turkish spammers about how to get backlinks.  Clearly they&#8217;re well behind the times, as not only are all my blogs nofollow, but also I delete spam with vigour.  The article in question (run through Google translate) says roughly:</p>
<blockquote><p><strong>5 ** 6 ** 6 PR 2 PR 10 Backlink PR4 and More</strong><br />
Foreign blogs and comment areas banclink hear or see her friends are and I did some research for you own emegimdir from anywhere you can quote me degildir.azc?k ingilizce is complete and <strong>the site name, e-mail them your name, and then thanks to write your thank you is enough</strong></p>
<p>Spam Plugin for WP Hashcash by Wordpress Plugins -> pr6<br />
Subscribe to Comments 2.1 Tempus fugit -> pr6<br />
Better Comments Manager &#8211; Wordpress Plugin release -> PR5<br />
Subscribe to Comments 2.1 Tempus fugit -> PR5 </p></blockquote>
<p>Yeah, no.  Saying &#8220;thanks&#8221; and spamming your link is not enough you morons.  Stop spamming.  For those interested, the signatures in the logs vary, it&#8217;s not particularly easy to block this kind of spam, since human are submitting it manually.  You could slowly start banning referrers from known sites:</p>
<blockquote><p>85.103.7.211 &#8211; - [25/Feb/2009:16:49:20 -0500] &#8220;GET /hashcash/ HTTP/1.1&#8243; 200 11459 &#8220;http://www.r10.net/dmoz-ve-diger-dizinler/298686-2-page-ranking-6-6-page-ranking-5-10-pr4-ve-daha-fazla-backlink.html&#8221; &#8220;Mozilla/5.0 (Windows; U; Windows NT 5.1; tr; rv:1.9.0.6) Gecko/2009011913 Firefox/3.0.6 GTB5&#8243;<br />
85.103.7.211 &#8211; - [25/Feb/2009:16:49:21 -0500] &#8220;GET /wp-includes/js/comment-reply.js?ver=20081210 HTTP/1.1&#8243; 200 864 &#8220;http://wordpress-plugins.feifei.us/hashcash/&#8221; &#8220;Mozilla/5.0 (Windows; U; Windows NT 5.1; tr; rv:1.9.0.6) Gecko/2009011913 Firefox/3.0.6 GTB5&#8243;<br />
85.103.7.211 &#8211; - [25/Feb/2009:16:49:21 -0500] &#8220;GET /wp-content/themes/db/style.css HTTP/1.1&#8243; 200 2491 &#8220;http://wordpress-plugins.feifei.us/hashcash/&#8221; &#8220;Mozilla/5.0 (Windows; U; Windows NT 5.1; tr; rv:1.9.0.6) Gecko/2009011913 Firefox/3.0.6 GTB5&#8243;</p></blockquote>
<p>It&#8217;s too bad that Wordpress plugin and theme authors appear to be specifically targeted, as we&#8217;re generally a very spam-hating crowd.</p>
]]></content:encoded>
			<wfw:commentRss>http://wordpress-plugins.feifei.us/42/pagerank-forum-spam/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Attack of the Wordpress-Hacking Spam Trackbacks</title>
		<link>http://wordpress-plugins.feifei.us/40/attack-of-the-wordpress-hacking-spam-trackbacks/</link>
		<comments>http://wordpress-plugins.feifei.us/40/attack-of-the-wordpress-hacking-spam-trackbacks/#comments</comments>
		<pubDate>Sat, 07 Jun 2008 19:56:03 +0000</pubDate>
		<dc:creator>Elliott Back</dc:creator>
				<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://wordpress-plugins.feifei.us/40/attack-of-the-wordpress-hacking-spam-trackbacks/</guid>
		<description><![CDATA[So this is a cute comment I got, a trackback spam that&#8217;s also a SQL injection exploit for Wordpress.  Check it out:
Website: &#8216; AND 1=0) UNION SELECT 1 FROM wp_users WHERE user_login=&#8217;admin&#8217; and substring(reverse(lpad(conv(substring(user_pass,8,1), 16, 2),4,&#8217;0&#8242;)),4,1)=&#8217;1&#8242; /* (IP: 124.217.250.190 , svservers.com)
URI: http://None
Excerpt: None&#8230;
It appears to be a known-cryptotext or weak-hash exploit against Wordpress looking [...]]]></description>
			<content:encoded><![CDATA[<p>So this is a cute comment I got, a trackback spam that&#8217;s also a SQL injection exploit for Wordpress.  Check it out:</p>
<blockquote><p><strong>Website</strong>: &#8216; AND 1=0) UNION SELECT 1 FROM wp_users WHERE user_login=&#8217;admin&#8217; and substring(reverse(lpad(conv(substring(user_pass,8,1), 16, 2),4,&#8217;0&#8242;)),4,1)=&#8217;1&#8242; /* (IP: 124.217.250.190 , <a href="http://svservers.com" title="http://svservers.com" target="_blank">svservers.com</a>)</p>
<p><strong>URI</strong>: http://None</p>
<p><strong>Excerpt</strong>: None&#8230;</p></blockquote>
<p>It appears to be a known-cryptotext or weak-hash exploit against Wordpress looking for an admin password with an obvious signature.  Cute.</p>
]]></content:encoded>
			<wfw:commentRss>http://wordpress-plugins.feifei.us/40/attack-of-the-wordpress-hacking-spam-trackbacks/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>More &#8220;GUID Spam&#8221;</title>
		<link>http://wordpress-plugins.feifei.us/39/more-guid-spam/</link>
		<comments>http://wordpress-plugins.feifei.us/39/more-guid-spam/#comments</comments>
		<pubDate>Sat, 10 May 2008 23:54:15 +0000</pubDate>
		<dc:creator>Elliott Back</dc:creator>
				<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://wordpress-plugins.feifei.us/39/more-guid-spam/</guid>
		<description><![CDATA[Darren recently mentioned that he has been receiving a pointless kind of spam in the last couple days he is calling GUID Spam:
I&#8217;ve been getting a new species of comment spam. They’re meaningless strings of numbers and letters, often without links. I’ve been calling it GUID (globally unique identifiers) spam because that’s what they most [...]]]></description>
			<content:encoded><![CDATA[<p>Darren recently mentioned that he has been receiving a pointless kind of spam in the last couple days he is calling <a href="http://www.darrenbarefoot.com/archives/2008/05/boring-site-note-what-is-with-the-guid-comment-spam.html">GUID Spam</a>:</p>
<blockquote><p>I&#8217;ve been getting a new species of comment spam. They’re meaningless strings of numbers and letters, often without links. I’ve been calling it GUID (globally unique identifiers) spam because that’s what they most resemble.</p></blockquote>
<p>I&#8217;ve been seeing it too:</p>
<blockquote><p>Website: 5d0813b34159 (IP: 213.251.189.201 , <a href="http://gw1.ovh.net" title="http://gw1.ovh.net" target="_blank">gw1.ovh.net</a>)<br />
URI    : <a href="http://5d0813b34159.us" title="http://5d0813b34159.us" target="_blank">5d0813b34159.us</a><br />
Excerpt:<br />
&lt;strong&gt;5d0813b34159&#8230;&lt;/strong&gt;<br />
5d0813b34159b436b3d8&#8230;</p>
<p>Website: 68c95c8a9410 (IP: 64.131.83.138 , <a href="http://srv.anony-mous.info" title="http://srv.anony-mous.info" target="_blank">srv.anony-mous.info</a>)<br />
URI    : <a href="http://68c95c8a9410.us" title="http://68c95c8a9410.us" target="_blank">68c95c8a9410.us</a><br />
Excerpt:<br />
&lt;strong&gt;68c95c8a9410&#8230;&lt;/strong&gt;<br />
68c95c8a9410017afcac&#8230;</p>
<p>Website: 853bf2b234ad (IP: 64.141.108.29 , 64.141.108.29)<br />
URI    : <a href="http://853bf2b234ad.us" title="http://853bf2b234ad.us" target="_blank">853bf2b234ad.us</a><br />
Excerpt:<br />
&lt;strong&gt;853bf2b234ad&#8230;&lt;/strong&gt;<br />
853bf2b234add2151fa1&#8230;</p>
<p>Website: 087f722478aa (IP: 67.159.44.134 , <a href="http://TE01.techentrance.com" title="http://TE01.techentrance.com" target="_blank">TE01.techentrance.com</a>)<br />
URI    : <a href="http://087f722478aa.us" title="http://087f722478aa.us" target="_blank">087f722478aa.us</a><br />
Excerpt:<br />
&lt;strong&gt;087f722478aa&#8230;&lt;/strong&gt;<br />
087f722478aaf73ffa8f&#8230;</p>
<p>Website: 655dec378813 (IP: 74.54.136.66 , <a href="http://corsica.websitewelcome.com" title="http://corsica.websitewelcome.com" target="_blank">corsica.websitewelcome.com</a>)<br />
URI    : <a href="http://655dec378813.us" title="http://655dec378813.us" target="_blank">655dec378813.us</a><br />
Excerpt:<br />
&lt;strong&gt;655dec378813&#8230;&lt;/strong&gt;<br />
655dec3788132527049e&#8230;</p></blockquote>
<p>This kind of spam looks like a partial md5 sum of the URL, or it could just be random.  Perhaps the spammer is using compromised hosts to drop these tags, and then coming back over time to see when they are removed, or if they stay up forever.  That would give him a list of possible sites to spam in the future.</p>
]]></content:encoded>
			<wfw:commentRss>http://wordpress-plugins.feifei.us/39/more-guid-spam/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Manual Blog Comment Spam</title>
		<link>http://wordpress-plugins.feifei.us/38/manual-blog-comment-spam/</link>
		<comments>http://wordpress-plugins.feifei.us/38/manual-blog-comment-spam/#comments</comments>
		<pubDate>Sat, 29 Mar 2008 03:30:05 +0000</pubDate>
		<dc:creator>Elliott Back</dc:creator>
				<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://wordpress-plugins.feifei.us/38/manual-blog-comment-spam/</guid>
		<description><![CDATA[I had the pleasure of getting a spam comment from a manual Russian spammer:
Author: Rapidshare
Email:  fileshunt@gmail.com
Website:  fileshunt.com
IP: 212.44.130.15
I completely agree with all that here is told
You can see that this is actually a human from the log:
212.44.130.15 &#8211; - [28/Mar/2008:09:12:42 -0400] &#8220;GET /hashcash HTTP/1.1&#8243; 200 7439 &#8220;-&#8221; &#8220;Opera/9.26 (Windows NT 5.1; U; ru)&#8221;
212.44.130.15 [...]]]></description>
			<content:encoded><![CDATA[<p>I had the pleasure of getting a spam comment from a manual Russian spammer:</p>
<blockquote><p><strong>Author</strong>: Rapidshare<br />
<strong>Email</strong>:  <a href="mailto:fileshunt@gmail.com" title="mailto:fileshunt@gmail.com">fileshunt@gmail.com</a><br />
<strong>Website</strong>:  <a href="http://fileshunt.com" title="http://fileshunt.com" target="_blank">fileshunt.com</a><br />
<strong>IP</strong>: 212.44.130.15</p>
<p>I completely agree with all that here is told</p></blockquote>
<p>You can see that this is actually a human from the log:</p>
<blockquote><p>212.44.130.15 &#8211; - [28/Mar/2008:09:12:42 -0400] &#8220;GET /hashcash HTTP/1.1&#8243; 200 7439 &#8220;-&#8221; &#8220;Opera/9.26 (Windows NT 5.1; U; ru)&#8221;<br />
212.44.130.15 &#8211; - [28/Mar/2008:09:12:44 -0400] &#8220;GET /wp-content/themes/db/style.css HTTP/1.1&#8243; 200 2646 &#8220;http://wordpress-plugins.feifei.us/hashcash&#8221; &#8220;Opera/9.26 (Windows NT 5.1; U; ru)&#8221;<br />
212.44.130.15 &#8211; - [28/Mar/2008:09:12:46 -0400] &#8220;GET /wp-content/uploads/2008/01/hashcash.png HTTP/1.1&#8243; 200 59975 &#8220;http://wordpress-plugins.feifei.us/hashcash&#8221; &#8220;Opera/9.26 (Windows NT 5.1; U; ru)&#8221;<br />
212.44.130.15 &#8211; - [28/Mar/2008:09:14:58 -0400] &#8220;GET /favicon.ico HTTP/1.1&#8243; 200 1330 &#8220;http://wordpress-plugins.feifei.us/hashcash&#8221; &#8220;Opera/9.26 (Windows NT 5.1; U; ru)&#8221;</p></blockquote>
<p>I highly doubt an efficient bot network would GET requests on my favicon, theme stylesheet, and images.    My second spammer sent me this:</p>
<blockquote><p><strong>Author</strong>: penis enlargement<br />
<strong>Email</strong>: <a href="mailto:penisenlargementz@gmail.com" title="mailto:penisenlargementz@gmail.com">penisenlargementz@gmail.com</a><br />
<strong>Website</strong>: <a href="http://naturalherbalz.com" title="http://naturalherbalz.com" target="_blank">naturalherbalz.com</a><br />
<strong>IP</strong>: 202.143.112.106</p>
<p>Natural herbal health care medicines, Articles, informations and daily updated health concerns issues and their solutions for better health and better life. <a href="http://www.naturalherbalz.com" title="http://www.naturalherbalz.com" target="_blank">www.naturalherbalz.com</a></p></blockquote>
<p>If you look at their logs, it is incredibly clear what is happening here:</p>
<blockquote><p>202.143.112.106 &#8211; - [28/Mar/2008:10:02:46 -0400] &#8220;GET /hashcash/ HTTP/1.0&#8243; 200 7511 &#8220;http://www.google.com.pk/search?q=powered by wordpress blogs comments add url&#8221; &#8220;Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.13) Gecko/20080311 Firefox/2.0.0.13&#8243;<br />
202.143.112.106 &#8211; - [28/Mar/2008:10:02:50 -0400] &#8220;GET /wp-content/themes/db/style.css HTTP/1.0&#8243; 200 2646 &#8220;http://wordpress-plugins.feifei.us/hashcash/&#8221; &#8220;Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.13) Gecko/20080311 Firefox/2.0.0.13&#8243;<br />
202.143.112.106 &#8211; - [28/Mar/2008:10:02:51 -0400] &#8220;GET /wp-content/themes/db/img/bg.jpg HTTP/1.0&#8243; 200 8203 &#8220;http://wordpress-plugins.feifei.us/wp-content/themes/db/style.css&#8221; &#8220;Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.13) Gecko/20080311 Firefox/2.0.0.13&#8243;</p></blockquote>
<p>This manual spammer searched for &#8220;powered By Wordpress blogs comments add url,&#8221; came to my site, and submitted his spam comment.  So spammers are targeting Wordpress as a platform with cheap labour in foreign countries to post spam comments.</p>
]]></content:encoded>
			<wfw:commentRss>http://wordpress-plugins.feifei.us/38/manual-blog-comment-spam/feed/</wfw:commentRss>
		<slash:comments>38</slash:comments>
		</item>
		<item>
		<title>Gaming Wordpress &#8220;DoFollow&#8221; Blogs</title>
		<link>http://wordpress-plugins.feifei.us/23/gaming-wordpress-dofollow-blogs/</link>
		<comments>http://wordpress-plugins.feifei.us/23/gaming-wordpress-dofollow-blogs/#comments</comments>
		<pubDate>Sun, 29 Jul 2007 03:09:56 +0000</pubDate>
		<dc:creator>Elliott Back</dc:creator>
				<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://wordpress-plugins.feifei.us/23/gaming-wordpress-dofollow-blogs/</guid>
		<description><![CDATA[I came across this list of dofollow blogs today and was, well, frankly astonished.  The point of the nofollow attribute on links was to reduce comment spam by removing the search engine optimization incentive of improving your ranking by getting a free link.  Of course, those who didn&#8217;t support the standard argued that [...]]]></description>
			<content:encoded><![CDATA[<p>I came across this <a href="http://www.digeratimarketing.co.uk/2007/07/20/over-160-relevant-link-following-blogs/">list of dofollow blogs </a>today and was, well, frankly astonished.  The point of the nofollow attribute on links was to reduce comment spam by removing the search engine optimization incentive of improving your ranking by getting a free link.  Of course, those who didn&#8217;t support the standard argued that it stifled conversations on the blogosphere by penalizing regular comments and spammers alike.</p>
<p>This list of blogs (and other like it) could help introduce you to a sector of the blogosphere which you feel more comfortable working in if you want credit for your comments.  It could, but that&#8217;s probably not it&#8217;s primary purpose.</p>
<p>No, yet again, the great <em>wheel of spam</em> continues to roll as people looking for a few easy links are picking out sites in their niche they know have either do-followed their comments or are running really old blogging software.</p>
]]></content:encoded>
			<wfw:commentRss>http://wordpress-plugins.feifei.us/23/gaming-wordpress-dofollow-blogs/feed/</wfw:commentRss>
		<slash:comments>23</slash:comments>
		</item>
	</channel>
</rss>
