New Contact Info

Categories: Asides

I’ve finally had to delete the old email address associated with this site (mike at this domain) because of unmanageable amounts of spam. To contact me, please either look me up on the usma.edu English department web site, or send me a message at my gmail.com address, which is “preterite” and then the @ and the rest. (Yes, I like Pynchon.)

Update: In going through my harvested comment spam, I’ve seen a recent spamming strategy that may or may not be old news to other folks. Check out, for example, the spam-farm that the Wayne State Applied Genomics Technology Center site has become, by entering the URL for one of their member pages – http://agtc.wayne.edu/agtc/Members/bucks/ – followed by the drug of your choice – acyclovir, adipex, allegra, ambien, ativan, cialis, ephedra, fioricet, hydrocodone, levitra, lorazepam, paxil, et cetera – and a .html. Other victims include the University of Madrid’s Integrated Systems Laboratory, semanticweb.org, and the Denmark Learning Lab documentation site. All are sites using Plone, but that should likely be a warning sign for you CMS administrators. Charlie, Clancy, Bradley – have any of you run into this problem? (Are we certain that Knews isn’t pushing erectile dysfunction remedies on the side? :-) )

Comments

  1. Clancy

    Oh, God, you have no IDEA. Charlie, Matt, Bradley, and I just deleted HUNDREDS of spam user accounts. Charlie then installed a captcha so that users would have to do a simple math problem in order to be able to create a new account. BUT, something was wrong with the module, because it kept telling people they had the wrong answer to the problems (these were 8 + 2 type problems). So we had to disable the module for the time being.

    Reply

  2. mike (author)

    Interesting. And that’s really sucky. Were the account signups scripted or manual? Like, how closely together in time were they created? Because if it’s a script, that’s easy enough to stop, and if it’s manual, ban the IP. But I’m sure y’all are way past me there.

    I dislike captchas because of section 508 concerns, though I know there are workarounds. Have y’all thought about a scaled privileges approach, so someone who leaves obviously real human comments could be blessed to post and obvious human posters could be blessed to have their own pages? I know it sounds like a pain in the ass, but it’s basically what WP’s Spam Karma does, and Spam Karma works extremely well for me.

    Reply

  3. Jim Ridolfo

    The spam problem is extremely widespread and targets Plone. Basically if one allows instant account registration and a Member folder, then the person, (who is apparently a known identity) automates the creation of anywhere from 20-200 accounts in under a few minutes. Google quickly indexes the site thanks to the pornographers automated script, and within a few hours the site starts receiving 10-15 visits a second from search engines.

    The automated script basically uploads dozens of html porn, gambling, prescription drug , java redirect scripts, and then uses the site for denial of service attacks, hosting porn on a large scale, and also working at times as part of a DDoS botnet.

    Basically, there is only one course of action:

    1) Lock the site down, disallow new user registration 2) Patch plone to the latest security releases 3) Delete all accounts (which often look legit and are difficult to sort by time of creation under plone)

    plone.org has been slow to acknowledge this as a very serious problem.

    Reply

Reply:

Markdown works.

Never published here.

Moderation queue may take a bit.