May 4, 2005

An email I received today...

X-Originating-IP: [] (
Date: Wed, 4 May 2005 04:37:08 +0200
From: "Cynthia Wood" <cynthia_wood1@*******.it>
Subject: From Cynthia Wood
Reply-to: cynthia123wood@*******.com

Lloyds TSB Group plc
25 Gresham Street
London EC2V 7HN


I discovered a dormant account in my office, as Group finance director with Lloyds bank London. It will be in my interest to transfer this fund worth $20,000,000 million dollars in an account offshore. If you can be a collaborator to this please indicate interest immediately for us to proceed. Remember this is absolutely confidential. My husband does not know about this risk taking. My family will be in shambles if it burst out and i will also be in trouble aswell as loose my precious job. Your contact phone numbers and name will be necessary for this effect.

Regards and respect,

Cynthia Wood
Group Finance Director
Lloyds bank London

Dear Cynthia

Firstly, you should really talk to your web site people as, according to the Lloyds TSB site, Helen A. Weir is the Group Finance Director. Much as I am interested in your figure of 20 trillion dollars, I find it difficult to work out (a) why a British institution would have money in dollars instead of pounds, (b) why a British institution would have an account containing some 10 times the GDP of the United Kingdom, and (c) why the Group Finance Director would be emailing random people offering shady under-the-table deals, though I can see why you would therefore be emailing me from Italy.

Incidentally, you should learn how to properly write subjects for emails. "From Cynthia Wood" tells me nothing that the "From" line doesn't already.

Sorry I can't help, however I have this fellow in Nigeria who's trying to get rid of $10 million as well, so perhaps the two of you could get together in a mutually benificial arrangement.

Love, Alden.

April 14, 2005

Outing Spammers

I got bored, and looked up the domain information for some of the domains with which the one spammer keeps trying to bombard my site. It said the domains were registered to:

Phill, Jane (NIC-8754)
Jane Phill
142 W 44 Street
Phone: 2128523####

There's a number of problems with that information of course. For one thing, the phone number has too many digits (I've blanked the last 4 there). For another, the street address is for Osteria al Doge, a resteraunt who I'm sure would be appalled that their address is being used to register domains.

Fortunately by googling "Jane Phill" I found Spam Huntresses blog, which has more info: the spammers in question are the Bulgarian twins Iavor and Emil Zahariev . It's nice to put a name to the people who want to pollute my site. :)

April 4, 2005


I can't say enough good things about Jay Allen's MT-Blacklist. Using Brad Choate's MTSQL plugin and some code from the forums on Jay's site posted by TweezerMan, I've added the current count of blocked spams in the right-hand bar on my weblog's index page. It only updates when I post an entry, but at the moment I can see it's reading 3583 spams blocked. The number will rise once I post this entry, of course, because at the moment some plonker is attempting to trackback spam me and MT-Blacklist is blocking them all. Thanks to Jay's plugin, I'm spending less and less time cleaning up after spammers.

Someday I'm going to invent a plugin which interfaces with MT-Blacklist and, when it receives a spam, causes the spammer's computer to explode, then gives them 15,000 volts to the gonads. Then I shall become very rich with donations from grateful bloggers. Huzzah!

March 8, 2005

Fighting Weblog spam

MT-Blacklist has blocked almost 2000 spams on my weblog so far. Some still get through prompting me to add more string blocks. Damn them. Damn them all.

Though my site doesn't get as much spam as many others, I'm beginning to see the appeal of outing them.

February 4, 2005

Think like a spammer

I got a comment today. See if you can spot anything suspicious about it.

%syn(Cool|Nice|Rulezz)% %syn(blog,|portal| site ! I)% hope to make %syn(my own|own weblog|my diary)%, not worse than yours ;)

Gosh, no, nothing suspect about that...

("not worse than yours"?! Cheeky.)

The "nofollow" attribute was recently introduced (see announcements by Google and Yahoo), the theory being if links in comments don't count towards the target's ranking in search engines, spammers will be less inclined to spam blogs. I'm still sceptical. Spamming blogs costs nothing, and the process can be automated. Unless every single blog on the net upgrades to use the nofollow attribute, I don't think there's any reason for the spammers to stop.

I don't think I'll be uninstalling MT-Blacklist any time soon...

January 8, 2005

Ultimate Blacklist!

Via Aardvark:

Aunty Spam's Net Patrol reports: A little birdie with insider knowledge has confirmed that Verizon is blocking all international IP space from RIPE, APNIC, and more, and is only unblocking specific domains, based on their IP address, when complaints are made and escalated.

If that's true, then it seems Verizon has stumbled on an interesting solution to the spam problem, though probably not a sustainable one over the long term, due to the amount of complaints they'll get (though they may well be blocking the complaints as well!).

November 30, 2004

Make Love, Not Spam

Lycos is introducing a new way to fight spam. It's a screensaver which attacks the web sites of spammers, draining their bandwidth and making their site unresponsive. I'm not at all sure it's legal, but really how many people are going to have sympathy for the spammers?

Of course this could backfire. As we've already seen with SORBS, it's easy to accidentally target people who haven't done anything wrong. It's common, for instance, for a number of completely unrelated web sites to be hosted on the same server simply because the owners are signed up with the same web hosting company. An attack on one site on such a server would impact the other unrelated sites as well...

November 19, 2004

SORBS Strikes Back

Good old SORBS (Spam and Open-Relay Blocking System) is still at it. Not only are they blocking whole ISPs, they're apparently also blocking email from servers hosted on dynamic IP addresses. Once again, SORBS is throwing the baby out with the bath water.

The reason thay're blocking anything from dynamic IP addresses is because virus-ridden PCs can be used to send spam. Gosh, wait until they realise that 100% of spam emails are sent via the SMTP protocol! "OMG! By blocking any email sent with that protocol, we can block 100% of spam! We'll be saviours!"

As I mentioned a while back on my LJ, SORBS came to my attention because I tried to email a friend of mine, and it bounced. If there's one thing I hate more than spam, it's having a perfectly valid email bounce for no good reason. (I've been able to email George since, and it looks like Paradise was taken off SORBS' list.)

Blacklisting is bad, it stops legitimate emails and doesn't really affect spammers much, because they use fake email addresses and don't get the bounces. Of course, if everyone used the blacklist, that would stop the spammers... for about five minutes before they found a way around it. Spammers make quite a lot of money, you see, so they're determined to keep doing it. The only way to stop spam for good is to cut it off at the source. Blacklisting doesn't do that, it just makes the problem invisible, like taking painkillers for a brain tumour.

Of course, people will still use blacklists. However if you consider using SORBS, you might stop to consider what valid emails you might miss out on.

Incidentally, SORBS is currently in fourth position for a worthless project.

November 2, 2004

Spammed by Paramount!

It's not often I'm surprised by spam, but today I was spammed by Paramount studios. Apparently they had taken me for a War of the Worlds fan and wanted me to help pimp their upcoming movie. A quick search of my web site revealed that War of the Worlds is mentioned on five DiscCon Guide entries, and in the Who Killed Kennedy eBook, so, er, no, that is still a bit of a leap to make.

This is, I suspect, an overzealous marketing underling... I guess it makes a change from endless viagra, Nigerian scam and speed camera spams.

September 9, 2004

Spam and Movable Type comments

Back last year I posted about a possible way Movable Type could combat the spam problem thusly:

Even Movable Type has problems with spam, and they've been talking about ways to combat it.

Personally I'd have thought the easiest way would be to have a page which lists all the recently posted comments, in chronological order... that way the blog owner would be able to see comments made on months-old entries.

I see Movable Type 3 not only has such a page, but it does email notification like LiveJournal does. In fact, the back-end of MT 3.11 is pretty cool all told. :)

