« Automatic Registrations Off For The Night | Versha Sharma's Blog | Back at TPM and Cafe after two-week break »

Subversive Spam


I'm just as tired of writing post titles about spammers as you are, guys. Oof.

The new problems: Registration has been shut off all week (automatic registration, that is; if people want to register, they have to email me to manually set up an account.) These new fellas are subverting the registration block somehow - tech guru Al is looking into it. We're not quite sure what to make of it. Movable Type is working with us on an anti-spam plugin (progress!), and Al is planning on talking to SixApart on this very serious, very annoying issue.

I've said this before, but it bears repeating: we can only track down IP addresses when someone leaves a comment. We sadly cannot ban the IP addresses of all the recent spammers, 'cause they've only left blog posts, no comments.

I like these tech recommendations a lot. We'll certainly see what we can do - the basic problem with that specific suggestion is that we don't operate on WordPress, we're on Movable Type.

Continue:
-emailing me directly (versha@talkingpointsmemo.com) - I'll definitely see direct emails SOONER than any emails sent to talk@ or help@.
-when a spammer has 25 or more posts, you don't have to take the time to send me individual post links - just send me the link to the spammer's profile, or the spammer's profile name. Either one works.

As always, thank you!

21 Comments

| Leave a comment
user-pic

GO AL GO!

Thanks Versha, I've changed your email from help to versha. Good luck.

peace and love, jon

user-pic

Got your address in my e-mail address book now.

user-pic

I got one back I sent you, Versha, but there had been files added to it. Uh-oh. I deleted it without opening the files; it may have been more harmful than i had thought.

user-pic

Not much more to say than what's been said in previous blogs. Thanks for all you're doing and hope you can figure out a fix soon. The spam is really unbearable and makes the cafe virtually unusable after your work hours.

user-pic

Just want to say how much I appreciate this site. Having intelligent people actually offer sources so that I can better fend off the trolls we have around here(my place of work) is the greatest thing to happen to my peace of mind in a very long time.

user-pic

What a pain for you, Versha, but thank you. You'd think grown ups could act like grown ups, but then you'd think a lot of things that aren't so... welcome to 2009 in America.

user-pic

Versa - something else is going on. This site seems to be auto-reloading its pages every few seconds. I'm not sure what's going on here, but no other site I am on appears to be doing that.

user-pic

I'd spotted that, as well.

user-pic

yes, its incredibly annoying

user-pic

I think I noticed it for the first time yesterday. And it is incredibly annoying.

user-pic

I think my visits here will diminish significantly until I can be certain this site is trustworthy.

user-pic

You should try firefox, the only thing I see, on reloads, is the tpm logo spin in its tab.

user-pic

For what it's worth: While no doubt excellent on a day to day basis, Al Shaw may not know enough about the subtleties of Internet interfaces to be considered a "guru" here. There are people who are true gurus (e.g. specialists) that are quite expensive that you only hire them for small amounts of time -- when you really, really need them. This appears to be such a case. You need to get someone so smart that they will be able to put significant pressures on your software providers to give real answers in a reasonable amount of time.

user-pic

Thanks, Versha!

user-pic

As always greatly appreciate all your time and efforts!

user-pic

Oy!

Thanks! You might be wary of hostile bloggers, too.

Just sayin'

user-pic

Versha,
My dashboard reports you are using version 4.21 of the MovableType pro software. This site (among others) reports that version 4.21 has a lot of security holes and recommends upgrading to version 4.26.

And yeah, I noticed way too late that I searched the wrong platform ... been dealing with some WordPress sites recently and had a 2am brainfart. I figured since the specific plugin was sort of irrelevant to the point it wasn't worth going through a couple hundred MovableType plugins to find similar capacities.

And just curious ... your server logs don't include an IP address? (rhetorical question, pretty sure they kind of have to). You should be able to track an IP down that way ... cross-reference by either time or URL.

I emailed to talk@ earlier today on this issue, I'll forward it to your personal email just in case you miss the comment/other email.

user-pic
version 4.21 has a lot of security holesAh, so it is just a stoopid, easy-to-remove hacker. Good to know. No doubt, the hacker thinks they're clever...
user-pic
Ah, so it is just a stoopid, easy-to-remove hacker.
Well, that jumps a couple of steps ahead and relies on some assumptions ... is the system really on v4.21, is the spammer using a hole in that platform, etc. It's kind of like looking into someone's basement through a dusty window covered with cobwebs. I'm just trying to help with some educated guesses. Sometimes it's actually helpful, and sometimes people find that sort of thing a pain in the ass. This has been a problem long enough I figure chirping up might not piss anyone off - but I don't want to raise any expectations.
user-pic

Piss of whom? TPM has a real problem that they apparently can't solve. Updating the latest patches is web-maintenance 101.

Of course, you are quite right. This may not even fix the problem, but when debugging you start with the simplest things first (always make sure the device is plugged in!)

I wasn't motivated to even do the checking you did until your original post, kgb. Frankly, you did TPM (and by extension the community here) by your tech recommendation post. It's a very cheap lesson for TPM... and if some posters here feel any comments have been "harsh", too bad. I'm not sure they understand what it is like working in a professional environment where it's okay to point out errors without feeding the person warm milk at the same time.

Bravo to you, sir! If nothing else, you get things going in a very specific way.

user-pic

http://tpmcafe.talkingpointsmemo.com/talk/blogs/igigo/2009/09/supply.php?ref=reccafe

WE GOT ONE.

This igo or whatever has just about obliterated recent bloggers.

Leave a comment

Share
Close Social Web Email

"To" Email Address

Your Name

Your Email Address