<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Spam floods and Performancing Problems</title>
	<atom:link href="http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/feed/" rel="self" type="application/rss+xml" />
	<link>http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/</link>
	<description>Weblog Tools Blogging Tools Blog</description>
	<pubDate>Fri, 29 Aug 2008 21:37:26 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
		<item>
		<title>By: Fudeblog by Cesar Cardoso &#187; Normal, para um valor x de normal</title>
		<link>http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1109616</link>
		<dc:creator>Fudeblog by Cesar Cardoso &#187; Normal, para um valor x de normal</dc:creator>
		<pubDate>Sun, 21 Jan 2007 15:32:35 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1109616</guid>
		<description>[...] Parece que tivemos mais uma botnet entrando no ar, porque o Weblog Tools Collection notou um aumento no flood de spam de comentÃ¡rio. Particularmente sÃ³ notei um ou dois falsos positivos a mais que a mÃ©dia, mas teve gente que notou aumentos maiores. [...]</description>
		<content:encoded><![CDATA[<p>[...] Parece que tivemos mais uma botnet entrando no ar, porque o Weblog Tools Collection notou um aumento no flood de spam de comentÃ¡rio. Particularmente sÃ³ notei um ou dois falsos positivos a mais que a mÃ©dia, mas teve gente que notou aumentos maiores. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Charles</title>
		<link>http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1106268</link>
		<dc:creator>Charles</dc:creator>
		<pubDate>Fri, 19 Jan 2007 03:31:24 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1106268</guid>
		<description>OK, Never Mind! My main site's host server was down yesterday and software issues unrelated to WordPress turned out to be the culprit in my 'undeletable blogspam' - but many thanks to Everton Blair for your suggestion - I did rename my blog file today &#38; will do so regularly. Cheers.</description>
		<content:encoded><![CDATA[<p>OK, Never Mind! My main site&#8217;s host server was down yesterday and software issues unrelated to WordPress turned out to be the culprit in my &#8216;undeletable blogspam&#8217; - but many thanks to Everton Blair for your suggestion - I did rename my blog file today &amp; will do so regularly. Cheers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Charles</title>
		<link>http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1105749</link>
		<dc:creator>Charles</dc:creator>
		<pubDate>Thu, 18 Jan 2007 17:15:12 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1105749</guid>
		<description>My business site's blog has a new wrinkle in blogspam today. The spam has flooded in daily for months, but my assistant moderates it by marking it as spam &#38; it disappears. Today there are 4 comments that will not go away - they remain in the queue for moderation, even though we have deleted them repeatedly, marked them as spam, even repeatedly tried to singly delete them. Nothing has worked. They persist in the queue. Here's the URL for one of them:
  http://ws.arin.net/cgi-bin/whois.pl?queryinput=195.225.177.14
If anybody has any ideas, we'd appreciate it.</description>
		<content:encoded><![CDATA[<p>My business site&#8217;s blog has a new wrinkle in blogspam today. The spam has flooded in daily for months, but my assistant moderates it by marking it as spam &amp; it disappears. Today there are 4 comments that will not go away - they remain in the queue for moderation, even though we have deleted them repeatedly, marked them as spam, even repeatedly tried to singly delete them. Nothing has worked. They persist in the queue. Here&#8217;s the URL for one of them:<br />
  <a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=195.225.177.14">http://ws.arin.net/cgi-bin/who.....225.177.14</a><br />
If anybody has any ideas, we&#8217;d appreciate it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael eh?</title>
		<link>http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1104822</link>
		<dc:creator>Michael eh?</dc:creator>
		<pubDate>Wed, 17 Jan 2007 20:46:26 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1104822</guid>
		<description>While checking my 404 errors I notice some strange file requests. Since my blog is in another directory than root these attempts didn't work and were logged.

/xmlrpc.php   twice
/xmlrpc/xmlrpc.php  Once
/xmlsrv/xmlrpc.php  Once
/blog/""  Once
The actual file was accessed 8 times this month alone.

Obviously spammers are using this file maybe as an access point. The question is of what use is it? No doubt spammers are taking apart WP to find openings to hack their way in. Though this points to a file other than wp_comments_post.php.  Maybe those who are having problem should check their logs on this howmany times this file is being accessed.</description>
		<content:encoded><![CDATA[<p>While checking my 404 errors I notice some strange file requests. Since my blog is in another directory than root these attempts didn&#8217;t work and were logged.</p>
<p>/xmlrpc.php   twice<br />
/xmlrpc/xmlrpc.php  Once<br />
/xmlsrv/xmlrpc.php  Once<br />
/blog/&#8221;"  Once<br />
The actual file was accessed 8 times this month alone.</p>
<p>Obviously spammers are using this file maybe as an access point. The question is of what use is it? No doubt spammers are taking apart WP to find openings to hack their way in. Though this points to a file other than wp_comments_post.php.  Maybe those who are having problem should check their logs on this howmany times this file is being accessed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ColdForged</title>
		<link>http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1104620</link>
		<dc:creator>ColdForged</dc:creator>
		<pubDate>Wed, 17 Jan 2007 15:11:13 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1104620</guid>
		<description>They were getting me again as well. I couldn't test the efficacy of my mod_security SK2 plugin -- mentioned in a comment the last time you posted about these floods -- as my host had left mod_security out of the installation when they rebuilt the server.

I refer to these as "Maxthon floods" as the culprits have user agents containing "Maxthon" which isn't &lt;i&gt;too&lt;/i&gt; common. As such, I tried to help stave off the attacks with this bit of htaccess ruleset:

&lt;code&gt;

   # Maxthon killing
   RewriteCond %{REQUEST_METHOD} POST
   RewriteCond %{HTTP_USER_AGENT} Maxthon
   RewriteRule .* - [F=412,L]

&lt;/code&gt;</description>
		<content:encoded><![CDATA[<p>They were getting me again as well. I couldn&#8217;t test the efficacy of my mod_security SK2 plugin &#8212; mentioned in a comment the last time you posted about these floods &#8212; as my host had left mod_security out of the installation when they rebuilt the server.</p>
<p>I refer to these as &#8220;Maxthon floods&#8221; as the culprits have user agents containing &#8220;Maxthon&#8221; which isn&#8217;t <i>too</i> common. As such, I tried to help stave off the attacks with this bit of htaccess ruleset:</p>
<p><code></p>
<p>   # Maxthon killing<br />
   RewriteCond %{REQUEST_METHOD} POST<br />
   RewriteCond %{HTTP_USER_AGENT} Maxthon<br />
   RewriteRule .* - [F=412,L]</p>
<p></code></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: steve</title>
		<link>http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1103893</link>
		<dc:creator>steve</dc:creator>
		<pubDate>Wed, 17 Jan 2007 07:39:46 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1103893</guid>
		<description>on my end, i regularly update my mod_security filters and overall, works quite well. filtered spam doesn't even reach WordPress at all - and for those keywords/phrases that do get through, i'll let SK or BB handle them - just a simple and elegant 412:precondition failed. :) however, mod_security is not for everyone.</description>
		<content:encoded><![CDATA[<p>on my end, i regularly update my mod_security filters and overall, works quite well. filtered spam doesn&#8217;t even reach WordPress at all - and for those keywords/phrases that do get through, i&#8217;ll let SK or BB handle them - just a simple and elegant 412:precondition failed. <img src='http://weblogtoolscollection.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> however, mod_security is not for everyone.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1103683</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Tue, 16 Jan 2007 22:50:57 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1103683</guid>
		<description>I frequently advocate the use of John Sinteur's Block-Lists anti spam measures.
Find it here http://weblog.sinteur.com/index.php?p=8106 (The Daily Irrelevant).
In combination with Akismet and Bad Behaviour it has prevented all but three spam comments from penetrating my site.</description>
		<content:encoded><![CDATA[<p>I frequently advocate the use of John Sinteur&#8217;s Block-Lists anti spam measures.<br />
Find it here <a href="http://weblog.sinteur.com/index.php?p=8106">http://weblog.sinteur.com/index.php?p=8106</a> (The Daily Irrelevant).<br />
In combination with Akismet and Bad Behaviour it has prevented all but three spam comments from penetrating my site.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael B</title>
		<link>http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1103626</link>
		<dc:creator>Michael B</dc:creator>
		<pubDate>Tue, 16 Jan 2007 18:43:29 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1103626</guid>
		<description>My site got hit yesterday morning hard, harder than I've ever seen.  Luckily, SK2 got everything, some 1000 comments.  Not being very familiar with how most of these work, I guess I was lucky.  I don't know if while it was happening the site suffered any, but nothing seemed out of the ordinary.  I've seen a plugin that uses some JS to manipulate the wp-comments file's name, I'll look for it.</description>
		<content:encoded><![CDATA[<p>My site got hit yesterday morning hard, harder than I&#8217;ve ever seen.  Luckily, SK2 got everything, some 1000 comments.  Not being very familiar with how most of these work, I guess I was lucky.  I don&#8217;t know if while it was happening the site suffered any, but nothing seemed out of the ordinary.  I&#8217;ve seen a plugin that uses some JS to manipulate the wp-comments file&#8217;s name, I&#8217;ll look for it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Raj</title>
		<link>http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1103618</link>
		<dc:creator>Raj</dc:creator>
		<pubDate>Tue, 16 Jan 2007 18:31:59 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1103618</guid>
		<description>Could there be a script that can get the IP of spammer and add it to the .htaccess file for certain duration of time to completely deny access to the domain? I thought about doing it many a times, but with my limited knowledge of coding, I could not go any further than just dreaming about it.</description>
		<content:encoded><![CDATA[<p>Could there be a script that can get the IP of spammer and add it to the .htaccess file for certain duration of time to completely deny access to the domain? I thought about doing it many a times, but with my limited knowledge of coding, I could not go any further than just dreaming about it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael eh?</title>
		<link>http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1103590</link>
		<dc:creator>Michael eh?</dc:creator>
		<pubDate>Tue, 16 Jan 2007 17:07:37 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1103590</guid>
		<description>One sure fire way that got rid of spammers from newsgroup alt.binaries.pictures.anime was to track down the site that the spammers were spamming for and complain it off the server. Some ever track down info 3 to 4 links up to the hosts main trunk. Within 2 weeks, spamming in that newsgroup was dead after I made the comment 'if the spammers have no site to spam for, what would they spam for?'

I love moderation function though I'm not sure if it blocks the user IP when it is marked for spam. Maybe wp-comments-post.php should check who references it, maybe a parameter from wheither it's inside the site or externally linked.

I seen enough multilink spam that an upper limit should be set for URLs in a comment. Since spam is automated, it's pointless for warnings.

I also wonder if RSS feed is being used to aid spammers.</description>
		<content:encoded><![CDATA[<p>One sure fire way that got rid of spammers from newsgroup alt.binaries.pictures.anime was to track down the site that the spammers were spamming for and complain it off the server. Some ever track down info 3 to 4 links up to the hosts main trunk. Within 2 weeks, spamming in that newsgroup was dead after I made the comment &#8216;if the spammers have no site to spam for, what would they spam for?&#8217;</p>
<p>I love moderation function though I&#8217;m not sure if it blocks the user IP when it is marked for spam. Maybe wp-comments-post.php should check who references it, maybe a parameter from wheither it&#8217;s inside the site or externally linked.</p>
<p>I seen enough multilink spam that an upper limit should be set for URLs in a comment. Since spam is automated, it&#8217;s pointless for warnings.</p>
<p>I also wonder if RSS feed is being used to aid spammers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Garrett</title>
		<link>http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1103565</link>
		<dc:creator>Chris Garrett</dc:creator>
		<pubDate>Tue, 16 Jan 2007 11:46:15 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1103565</guid>
		<description>Sorry about that, am hoping our server woes are behind us</description>
		<content:encoded><![CDATA[<p>Sorry about that, am hoping our server woes are behind us</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Everton Blair</title>
		<link>http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1103502</link>
		<dc:creator>Everton Blair</dc:creator>
		<pubDate>Tue, 16 Jan 2007 09:45:37 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1103502</guid>
		<description>I was having the same problems, and I renamed my comments post file and all has been well since.
http://www.connectedinternet.co.uk/2007/01/01/1263/

Some spammers caught on, so I just changed the name again -takes 1 min to do.</description>
		<content:encoded><![CDATA[<p>I was having the same problems, and I renamed my comments post file and all has been well since.<br />
<a href="http://www.connectedinternet.co.uk/2007/01/01/1263/">http://www.connectedinternet.c.....1/01/1263/</a></p>
<p>Some spammers caught on, so I just changed the name again -takes 1 min to do.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rugjeff&#8217;s Blog About Blogging &#187; Blog Archive &#187; How Can We Control Blog Spamming</title>
		<link>http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1103484</link>
		<dc:creator>Rugjeff&#8217;s Blog About Blogging &#187; Blog Archive &#187; How Can We Control Blog Spamming</dc:creator>
		<pubDate>Tue, 16 Jan 2007 07:22:59 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1103484</guid>
		<description>[...] For some strange reason, my blog is being bombarded with spam comments.Â  This has always been a minor issue but this past week the spam comments on my blog have tripled.Â  At first I thought nothing of it, then I came across a post from Weblog Tools Collection. [...]</description>
		<content:encoded><![CDATA[<p>[...] For some strange reason, my blog is being bombarded with spam comments.Â  This has always been a minor issue but this past week the spam comments on my blog have tripled.Â  At first I thought nothing of it, then I came across a post from Weblog Tools Collection. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ajay</title>
		<link>http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1103470</link>
		<dc:creator>Ajay</dc:creator>
		<pubDate>Tue, 16 Jan 2007 05:15:12 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1103470</guid>
		<description>Mark, I think spammers are trying to hit the wp-comments-post.php to try and post their comment.

One solution could be to change the name of this file and all references to it and then block access to the wp-comments-post.php file to throw up 403 errors.

This is a workaround like Matt suggested above, but it may help curb the attack a bit.</description>
		<content:encoded><![CDATA[<p>Mark, I think spammers are trying to hit the wp-comments-post.php to try and post their comment.</p>
<p>One solution could be to change the name of this file and all references to it and then block access to the wp-comments-post.php file to throw up 403 errors.</p>
<p>This is a workaround like Matt suggested above, but it may help curb the attack a bit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1103468</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Tue, 16 Jan 2007 04:56:42 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1103468</guid>
		<description>I feel your pain too, my meagre blog was/is being hammered consistency with requests that were more than enough to cause a kernel out of memory exception to be thrown, which then kills of whichever processes it feels need to die, in my case mysql and apache.

Bad Behaviour didn't help, neither did Spam Karma 2 or Akismet, as the problem was not the spam getting onto my blog, but the severe number of requests coming through that was crashing my system.

I've found renaming my comment page and then blocking all requests to the old wp-comments-post.php file using Apache's mod_security has so far been a successful bandaid, as well as some IP blacklisting of the most common offenders.

I'd love to hear a real solution for this too.</description>
		<content:encoded><![CDATA[<p>I feel your pain too, my meagre blog was/is being hammered consistency with requests that were more than enough to cause a kernel out of memory exception to be thrown, which then kills of whichever processes it feels need to die, in my case mysql and apache.</p>
<p>Bad Behaviour didn&#8217;t help, neither did Spam Karma 2 or Akismet, as the problem was not the spam getting onto my blog, but the severe number of requests coming through that was crashing my system.</p>
<p>I&#8217;ve found renaming my comment page and then blocking all requests to the old wp-comments-post.php file using Apache&#8217;s mod_security has so far been a successful bandaid, as well as some IP blacklisting of the most common offenders.</p>
<p>I&#8217;d love to hear a real solution for this too.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1103429</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Tue, 16 Jan 2007 02:56:20 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/01/15/spam-floods-and-performancing-problems/#comment-1103429</guid>
		<description>I feel your pain. In fact, I'm living it too. We've had to upgrade our hosting and it's still not enough at some times during these floods. These people are idiots. They are taking down all the little guys.

I am not a programmer but if there is anything you think I can do to help, I would be more than happy to do so.</description>
		<content:encoded><![CDATA[<p>I feel your pain. In fact, I&#8217;m living it too. We&#8217;ve had to upgrade our hosting and it&#8217;s still not enough at some times during these floods. These people are idiots. They are taking down all the little guys.</p>
<p>I am not a programmer but if there is anything you think I can do to help, I would be more than happy to do so.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
