Mar 31

The new spam

I just came across a new kind of spam, very cleverly made:

Screenshot of the new kind of spam I got

It's a clever ploy, posting praise with hidden images. Only it was a bit off in my case, but if I hadn't checked the source, I'd never have known that I was in fact in the advertising business.

This particular post actually slipped through Mollom, so beware, my Mollom using friends – I've submitted this one to Mollom as spam, but beware what might have gotten through the net.

Mollom is generally a brilliant service (I've had 5922 blocked spam attempts the last 348 days), but there's always going to be a small amount of false positives. Spam filterning is no replacement for vigilance :)

  • March 31, 2009

    Easy...

    Easy enough to detect, have a limit on the number of <a> tags in a comment?

  • mikkel
    March 31, 2009

    Yeah, I suppose I could write

    Yeah, I suppose I could write my own filtering for this, but fighting against spam is not my idea of fun. Good thing we have companies like Mollom and Akismet :)

  • March 31, 2009

    Don't trust Zoran

    As a rule, I just delete any comments made by anyone named Zoran. Have you ever met anyone named "Zoran" who is trustworthy?

    Seriously, I've been seeing this exact same spam on a couple of web sites that I run. It's pretty much the exact same comment - signed by the evil Dr. Zoran himself.

    I'm using Mollom as well - I'm hoping that if enough of us start reporting Zoran's kind comments as spam, then Mollom will eventually learn to never trust Zoran again.

    -mike

    P.S. Did I say "Zoran" enough?

  • mikkel
    March 31, 2009

    Yes, I’m quite sure you gave

    Yes, I'm quite sure you gave the evil Dr. Zoran adequate mention :)

  • March 31, 2009

    Use Aksimet

    I use Aksimet (www.akismet.com) with my blog. It has never failed. Neither friendlies in filter nor spam in blog. Every week I get approximately 10 comments like the one, you describe here. None of them ever made it through Aksimet.

    Chris

  • mikkel
    March 31, 2009

    Yeah, I’ve used Akismet too

    Yeah, I've used Akismet too before switching to Mollom, and it seems that it's a bit more restrictive than Mollom – in my experience too much so. I got a lot of false negatives, ie. real comments getting marked as spam, so I figure a few spams being let through is a lot more fun than having to scan the spam lists every day to see if something was filtered wrongly.

  • March 31, 2009

    I use Views to create an RSS

    I use Views to create an RSS feed of incoming site comments, then subscribe to it at the very top of my feed reader. Any comments which seem fishy - they're from someone I don't know, and/or they say something like "hey great post!" with no real substantial content - are investigated more closely - 95% of the time they turn out to be spam which then gets reported to Mollom. Since I pretty much always have my feed reader open, spam comments rarely last longer than twelve hours on my site. I highly recommend that anyone allowing comments on their Drupal-based site do the same.

  • Zoran
    March 31, 2009

    Good work! Your post/article

    Good work! Your post/article is an excellent example of why I keep coming back to.. just kidding ;)

  • mikkel
    March 31, 2009

    Yeah, I have basically the

    Yeah, I have basically the same setup, besides using the Comments RSS module instead of Views – mainly for legacy reasons…

    The thing that struck me about the current example is that there was apparently nothing wrong until I viewed the source code. Usually it's kind of obvious with commenter's homepage set to some spammy site, but this one actually fooled me on first glance :)

  • March 31, 2009

    In this case, it still would

    In this case, it still would have raised my feelers because the comment doesn't really say anything; it's just flattery. And it's only one sentence long, as well. If a spammer really wanted to fool me, they should post a comment to my site comprised of at least five or six sentences, on the topic of and in reply to the content of my post. But so far no spammers and/or their robots have done that.

  • April 2, 2009

    Zoran sucks

    I'd noticed Zoran-related spam for a while now, glad someone else has identified it too. The thing it, it's such a flattering, seemingly sincere comment that you're tempted to believe all the nice things and not look under the surface!

  • June 12, 2009

    Limit on links?! :o

    A [HTML_REMOVED]limit[HTML_REMOVED] on [HTML_REMOVED][HTML_REMOVED][HTML_REMOVED][HTML_REMOVED][HTML_REMOVED]-tags might also hit [HTML_REMOVED]link[HTML_REMOVED] friendly people. Like [HTML_REMOVED]me[HTML_REMOVED]. :/

  • June 13, 2009

    New spam

    Hey,

    thanks for post,i will trackback this. Very interesting.

    @Zoran :D I love him.

    Thanks

  • March 12, 2010

    Well my girl friend just broke up with me over email about an hour ago so thought this would be a great place to start spreding her pics like she did her legs. Just go to http://www.gf4free.com/members/surferdude23/ Enjoy!

    [HTML_REMOVED][HTML_REMOVED]http://www.gf4free.com/members/surferdude23/uploads/9.jpg[HTML_REMOVED][HTML_REMOVED]

About

I am Mikkel Høgh. I have been a web developer for about 8 years. I have my own company, Reveal IT, a long with a couple of friends. We specialize in helping our customers build awesome web sites with open source tools like Drupal and Django.

Subscribe

Elsewhere

Categories

Recent Posts

Archive

BlogRoll

Popular Posts