Stay Connected:
Subscribe to our feed

Subscribe with FeedBurner




PREVIOUS POST
« Top 10 Sci-Fi/Fantasy Movies Lists
NEXT POST
Happy 30th Anniversary D&D »
Comment Spam Sucks

Q: What Sucks?
A: Comment spam.

SF Signal, along with countless other Moveable Type blogs, has been inundated with comment spam lately. Posting blog spam is, of course, the pastime of ass-clowns everywhere. But wethinks we's gots a solution.

The way these programs work is to post the the well-known moveable type comment CGI file called mt-comments.cgi. To block the spam programs, all you need to do is change the name of that cgi file to something unique (like, say, blog-comment-spammers-suck.cgi). Then, modify your mt.cfg file to set the CommentScript variable like so:

CommentScript blog-comment-spammers-suck.cgi
That's it.

Time will tell if this works. A comment spammer would have to specifically pull your unique name for him to start spamming again, the ass-clown. And if all Moveable Type blogs implement this, then it no longer becomes economically fruitful for these ass-clowns to profit. I Googled this hack after I implemented it and found that the same technique is working for this guy. Let's cross our collective fingers or else we resort to some other ass-clown-deterrent like ever-revving MT-BlackList, image verification, comment registration or (yikes!) disabling comments altogether.

Bookmark and Share
Comment on this post Comments (17) | PermaLink | Category: Meta
Posted by John DeNardo at Thursday October 14, 2004 at 8:32 PM
© 2004 SF Signal



Go John Go! Nice job!

Posted by Scott on Thursday October 14, 2004 at 11:48 PM

Has anyone run this ass-clown laced diatribe against the Lix scorer?

Posted by JP on Thursday October 14, 2004 at 11:56 PM

Thanks John, I am sure your LIX score does not adequately recognize the service you have done for us :) I said service...

Posted by Tim on Thursday October 14, 2004 at 11:59 PM

Well, somehow, the Blacklist is still, as of 6:08am GMT, denying comment spammers. Shouldn't this hack stop this? Unless they have changed their bot already. odd.

Posted by JP on Friday October 15, 2004 at 12:09 AM

D'oh!

They must be using some other methods. I've made some more changes to file names and link strings. Let's see if that helps.

Posted by John on Friday October 15, 2004 at 10:25 AM

So far so good. No comment spam, or spam at all, since you cleared out the activity log and made the comment CGI file changes.

Posted by JP on Friday October 15, 2004 at 1:45 PM

Yeah, but according the that guy, we should be seeing some emtries along the lines of entries for "Page Not Found: ********/mt-comments.cgi". My fingers remain crossed which, btw, makes it really difficult to type.

Posted by John on Friday October 15, 2004 at 1:49 PM

Damn fine idea. I turned commenting on just about a week ago on the science fiction news portion of The Dragon Page. Took three days for the asshats to find me. MT-Blacklist does the trick, though I like the idea of changing the back end as more of a "stick it in your ass" move. :->

Posted by Evo on Friday October 15, 2004 at 6:20 PM

Was this a solo (look at the email address on the bottom most comment...it was posted 2 minutes ago) hit?

Posted by Pete on Friday October 15, 2004 at 6:35 PM

Still getting spammed. These are being stopped by the blacklist, at least.

I'm doing some research. I am getting more and more convinced that a Blacklist is just a war of escalation that bloggers cannot win. Too much maintenance on our parts, and way too easy to forge IP addresses and disguise email addresses for the spammers.

The spammers have programs that actually parse the commenting forms, so renaming fields only helps sometimes.

Maybe a combination of disguising the HTML in script (so the parsing fails) and requiring registration (no anonymous comments) will be more successful?

Posted by John on Friday October 15, 2004 at 11:29 PM

BTW, an excellent overview of the war on comment spam can be found here.

Posted by John on Friday October 15, 2004 at 11:48 PM

An an even better article, specifically about Moveable Type and spam deterrents, is here.

Posted by John on Saturday October 16, 2004 at 1:00 AM

Well, it looks like the stupid drug sites are hitting us today...

Posted by Peter on Saturday October 16, 2004 at 3:56 PM

Great, dickheads have found a new way to post comment spam...(sigh) I don't suppose we could just find who's doing it, and club them senseless with louisville sluggers could we? We'd call them, um, aggressive anti-spam encouragement rods to circumvent any legal challenges. Any takers??

Doug

Posted by Doug on Thursday January 27, 2005 at 3:57 PM

Methinks this is a manual ass-clown given it's a single comment (which I have already removed) and the target post. I also blocked the IP, for whatever that's worth.

Posted by John on Thursday January 27, 2005 at 4:36 PM

Ummmm...speaking of comment spam....you might want to look above this comment.

Posted by Fred Kiesche on Wednesday July 27, 2005 at 6:04 AM

Thanks, Fred. I've just removed that comment. And a special thanks to the spammer who neatly provided all of the URLS we needed to add to our blacklist. :D

Posted by John on Wednesday July 27, 2005 at 9:00 AM

Post a Comment
(Will not be displayed)
Remember me?
   

[Note: Do not paste from WYSIWYG programs like MS Word, or formatting code will appear in your comment.]