October 31, 2007

Is Your Website Blacklisted

Filed under: Spyware — admin @ 5:35 pm

Is Your Website Blacklisted?

A blackslant, as the name implies, is a slant of people or companies who have met with the disapproval of others. In the online world a blackslant refers to those people who have been manifest as responsible for generating spam in a very big way. Blackslants are also known as frustrateslants.

Blackslants are worn to combat spam in a very detail way. When spam is reported to one of the related spam fighting organizations the IP address the spam originated from is added to a banned or blackslanted IP addressslant. An IP address is the sole locality of you or your website on the internet - think of it as your “home address” online. To put it basically every www.field.com Internet address has a matching IP address. Any dispatch entrance from your website field also has a corresponding IP address. If your IP address is display on a blackslant then you’re potentially killing your time transfer dispatch to customers.

Why are you killing your time? fresh spam frustrateers come with the most familiar blackslants installed and/or tolerate you to import efficient blackslants into your spam frustrateer. This tolerates to you frustrate a vast qudefiantty of spam but you may also, potentially, frustrate legitimate dispatch. Blackslants are not perfect.

There are two types of IP address:

Dynamic - changes every time you relate to the Internet. Most familiarly worn for dialup Internet access. Spammers ardor these bebasis they’re very hard to chase and 100% disposable.

unending/Static - All websites, most large companies and some individuals use unending IP addresses. This can basis vast evils if they’re reported for spamming.

When an IP address (dynamic or unending ) is reported for transfer spam it’s added to a blackslant. There are three different types of blackslants:

momentary

An IP address located on a brief blackslant will have dispatch entrance from that IP address frustrateed for numerous hours.

After a few hours the offending IP address is distant from the blackslant.

enduring

When an IP address is added to a unending blackslant any dispatch attendant configured to frustrate dispatch from this slant will never catch dispatch from that limit of IP addresses again.

Comprehensive

This is the most negative of blackslants. Not only does it frustrate a sole IP address it also frustrates the IP addresses next to it. For example if the IP address 192.156.66.67 was added to a comprehensive blackslant then all IP addresses close to 192.156.66.67 will also be frustrateed. This can be a vast crisis for those website owners with virtual swarming bebasis if your swarm has ever appeared on a blackslant then you’re also on the same blackslant, by shirk, bebasis of the mutual swarming from the same IP limit.

It’s important for all website owners to inhibit whether or not they’re on a blackslant. You’ll basic your IP address (untaken from your webswarm) and you can inhibit your blackslant stage at: www.post-abuse.org/cgi-bin/lookup

Blackslants are a basic evil due to the qudefiantty of spam being sent each day but are not an demand skill. Take a few moments from your day and guarantee that your website or dispatch address is not being frustrateed.

This expose was provided courtesy of Junkdemon where you can learn more about where spam came from and what defiant spam software you can use to get rid of it.

Tags:

October 30, 2007

New Spam Threat Hits 90,000 Sites - Is Yours Next

Filed under: Spyware — admin @ 5:01 am

New Spam Threat Hits 90,000 Sites - Is Yours Next?

On Tuesday I usual 423 sends from an anonymous spammer attacking my situate.

On Wednesday I usual 789 sends from the same spammer.

Action had to be full.

The sends were copies of dispatchs to my discussion forum - the classic spammers dispatchs - keyword stuffing, countless hyperfamily to scrap situates crowded with even more keywords.

It was earn I was being hit by one spammer, with an vehiclemated play, for a number of divulging reasons:

1) nonentity could dispatch 789 dispatchs to a forum in 24 hours manually

2) All dispatchs were from casual .co.za send addresses (South African domains, but liable bogus)

3) All dispatchs incisive to very akin spammy situates clearly made with the same vehicle-generation software

4) scrutiny countless domains promoted inside these dispatchs in WHOIS showed they were all owned by a certain guy in Paris

I wisely combed my forum for these scrap dispatchs but couldn’t see something out of the normal. So I checkered for dispatchs by .co.za send addresses, or French IPs but couldn’t see a puzzle anyplace.

Where were they arrival from, and where were the dispatchs?

To help me in my quest I did a pursuit on Google for the content that began every send which read:

“The next was dispatched in the on

But couldn’t find any family that were any help.

So next I investigated the content of the sends for usual factors and found the next Javaplay snatch began every meaning body:

“var defDoor”… before launching into other Javaplay rudiments, followed by the keywords and family.

I doubt…

A speedy pursuit on Google and two factors astonished me…

1) Google showed up 92,600 pages with this signs on, of which every one I checkered matched the thorough spam dispatchs I was since in type and content. So we were industry with a professional of some level.

2) They were all on forums, but not the one I worn, but WWWBoard as presented from http://www.playarchive.com/wwwboard.html

A speedy pursuit with my FTP software through the insides of my admittedly large situate that has been online for 5 being or so and has seen more reworkings than Pamela Anderson showed I *had* got WWWBoard installed on my situate but had bunged with it being ago in place of my flow forum software.

I had completely beyond about it, and there were the hundreds of spam dispatchs session there on my attendant!

visibly I don’t use the play so directly removed it and the spamming bunged down overnight but if I’m one of over 90,000 victims this guy has duped then a little guidance is required:

1) Appreciate that there are sanctuary flaws to WWWBoard and you both indigence to examine your forum very wisely or think switching to another play.

2) Don’t defer old plays session around on your attendant waiting for spammers to abuse them. Use them, or remove them.

3) Try to duck with evident folders for plays. Whilst I didn’t network to my old forum from anyplace on the situate, it was in an evident folder so a spammer (or a play) could clearly have guessed it.

4) Realise that sanctuary threats are very truly if you get reasonable transfer and take steps *in progress* to underrate the menace to your own situate.

Copyright 2006 Richard Adams

=======================================================
Richard Adams is the organizer of http://www.tradeaccountforum.com , one of the net’s most trendy trade account guidance situates.
=======================================================

Tags: