Spam

Comment Spam with HTML entities in the Url

Well, I found this one worth a note – for some time users tried to protect their email from spam bot harvesters by using html entities (codes representing the actual character) in their entries… believing that a spam bot cannot do the same as the browser can… well… they could.

Today I got about 50..60 spam entries from someone encoding his backlink-urls with HTML-entities.. and believe it or not – MT-Blacklist was not able to blacklist these urls… what a mess..

Url patterns look like this:

cas&105;nos-jp.com

&103;overnment-grant&115;.org

govern&109;ent-grant&115;.org

go&118;ernment-gra&110;ts.org

go&118;ernment-gra&110;ts.org

govern&109;ent-&103;rants.org

govern&109;ent-&103;rants.org

go&118;ernment-gra&110;ts.org

govern&109;ent-&103;rants.org

go&118;ernment-gra&110;ts.org

govern&109;ent-&103;rants.org

go&118;ernment-gra&110;ts.org

gov&101;rnment-gr&97;nts.org

&99;asino-jp.com

busin&101;ss-gr&97;nts.org

b&117;siness-&103;rants.org

busin&101;ss-&103;rants.org

gov&101;rnment-gran&116;s.org

governm&101;nt-&103;rants.org

governm&101;nt-&103;rants.org

governm&101;nt-&103;rants.org

gove&114;nment-gr&97;nts.org

Well – and that was some work to remove again…

Be sure to checkout Yoz Seven quick tips for a spam-free blog

http://cheerleader.yoz.com/archives/000849.html out – like I will do pretty soon…

Average rating
(1 vote)

Similar entries

  • Six Apart Trains Guns on 'Comment Spam' writes about the new authentication service "TypeKey" by SixApart that shall enable a central comment registration – so blog commenters will not need to register with every single weblog… oh well – redirecting…

  • Great – just as I found these new HTML entity spammers today Jay Allen released a new verion of his MT-Blacklist v1.64 – Just wonder if this would already be the cure? Version 1.64 is essentially a one-line change from…

  • via a comment in Aarons post I came across Spam Huntress weblog of a lady dedicated great effort to track down blog comment spammers… very interesting tips of logging, blocking, etc… Just currently reading the very interesting "Spam Kings" book…

  • Jay Allen's wonderful MT-Blacklist that helps to avoid penis pill spam and thousands of other idiotic comments on MT-blogs is hot and installed… there's also a documentation on updating automatically with some addons… But Jay talks about version 2 being…

  • using the MT Extensions MTObfuscate we know make sure, that your entered e-mails can only be read by JavaScript enabled browsers, that means most email harvesters and spam-generators will suck! :-) check this entries’ comment!...