<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Fighting Trackback Spam with Email Blacklists</title>
	<atom:link href="http://www.shaftek.org/blog/2005/02/01/fighting-trackback-spam-with-email-blacklists/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.shaftek.org/blog/2005/02/01/fighting-trackback-spam-with-email-blacklists/</link>
	<description>ShafTek.org = SHAFranovich TECHnologies</description>
	<lastBuildDate>Wed, 23 Dec 2009 13:41:13 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: grumpOps</title>
		<link>http://www.shaftek.org/blog/2005/02/01/fighting-trackback-spam-with-email-blacklists/comment-page-1/#comment-124</link>
		<dc:creator>grumpOps</dc:creator>
		<pubDate>Tue, 01 Feb 2005 21:33:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.shaftek.org/blog/2005/02/01/fighting-trackback-spam-with-email-blacklists/#comment-124</guid>
		<description>&lt;strong&gt;The Blogosphere and Blacklists&lt;/strong&gt;

Yakov has got me thinking about anti-spam methods applied to blog comments and trackbacks.  He has done some work looking at DNS Realtime Black Lists or RBLs (list of banned IP addresses) and found that an astonishing percentage of comment spam can b...
</description>
		<content:encoded><![CDATA[<p><strong>The Blogosphere and Blacklists</strong></p>
<p>Yakov has got me thinking about anti-spam methods applied to blog comments and trackbacks.  He has done some work looking at DNS Realtime Black Lists or RBLs (list of banned IP addresses) and found that an astonishing percentage of comment spam can b&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: netwizard</title>
		<link>http://www.shaftek.org/blog/2005/02/01/fighting-trackback-spam-with-email-blacklists/comment-page-1/#comment-123</link>
		<dc:creator>netwizard</dc:creator>
		<pubDate>Tue, 01 Feb 2005 20:42:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.shaftek.org/blog/2005/02/01/fighting-trackback-spam-with-email-blacklists/#comment-123</guid>
		<description>I hear you loud and clear, but unfortunatly I am not the first to suggest it. See &lt;a href=&quot;http://bradchoate.com/weblog/2004/11/05/mt-dsbl&quot; rel=&quot;nofollow&quot;&gt;MT-DSBL&lt;/a&gt; and &lt;a href=&quot;http://weblog.sinteur.com/index.php?p=7967&quot; rel=&quot;nofollow&quot;&gt;WP-DSBL&lt;/a&gt;.

My main point here was to observe how email spammers and comment spammers tend to use the same machines, and attacking both with the same tools is helpful. What is more interesting now is the fact that the tools used to fight comment spam are mirroring exactly the evolution of tools used for email spam. For example, another commenter suggested the filtering of proxy names which is something that SpamAssassin did originally for X-Mailer tags. There is also the TypeKey service from SixApart which is basically authentication. There is also blacklists, Turing tests, Hashcash, etc.

The key is what can we learn from email so we don&#039;t make the same mistakes. I don&#039;t really know if we will.</description>
		<content:encoded><![CDATA[<p>I hear you loud and clear, but unfortunatly I am not the first to suggest it. See <a href="http://bradchoate.com/weblog/2004/11/05/mt-dsbl" rel="nofollow">MT-DSBL</a> and <a href="http://weblog.sinteur.com/index.php?p=7967" rel="nofollow">WP-DSBL</a>.</p>
<p>My main point here was to observe how email spammers and comment spammers tend to use the same machines, and attacking both with the same tools is helpful. What is more interesting now is the fact that the tools used to fight comment spam are mirroring exactly the evolution of tools used for email spam. For example, another commenter suggested the filtering of proxy names which is something that SpamAssassin did originally for X-Mailer tags. There is also the TypeKey service from SixApart which is basically authentication. There is also blacklists, Turing tests, Hashcash, etc.</p>
<p>The key is what can we learn from email so we don&#8217;t make the same mistakes. I don&#8217;t really know if we will.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Grumpy</title>
		<link>http://www.shaftek.org/blog/2005/02/01/fighting-trackback-spam-with-email-blacklists/comment-page-1/#comment-122</link>
		<dc:creator>Grumpy</dc:creator>
		<pubDate>Tue, 01 Feb 2005 19:33:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.shaftek.org/blog/2005/02/01/fighting-trackback-spam-with-email-blacklists/#comment-122</guid>
		<description>In the email world blacklists are the devil&#039;s spawn.  Why would we want to inflict that upon this new medium?</description>
		<content:encoded><![CDATA[<p>In the email world blacklists are the devil&#8217;s spawn.  Why would we want to inflict that upon this new medium?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: netwizard</title>
		<link>http://www.shaftek.org/blog/2005/02/01/fighting-trackback-spam-with-email-blacklists/comment-page-1/#comment-121</link>
		<dc:creator>netwizard</dc:creator>
		<pubDate>Tue, 01 Feb 2005 18:51:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.shaftek.org/blog/2005/02/01/fighting-trackback-spam-with-email-blacklists/#comment-121</guid>
		<description>Unfortunatly its only a stop-gap solution EXACTLY like email spam. For an example, see &lt;a href=&quot;http://spamassassin.apache.org/presentations/2004-09-Toorcon/html/mgp00005.html&quot; rel=&quot;nofollow&quot;&gt;this presentation&lt;/a&gt; of how in the early days spamware used to announce itself in email. That is no longer true, and the same will apply here.</description>
		<content:encoded><![CDATA[<p>Unfortunatly its only a stop-gap solution EXACTLY like email spam. For an example, see <a href="http://spamassassin.apache.org/presentations/2004-09-Toorcon/html/mgp00005.html" rel="nofollow">this presentation</a> of how in the early days spamware used to announce itself in email. That is no longer true, and the same will apply here.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cindy</title>
		<link>http://www.shaftek.org/blog/2005/02/01/fighting-trackback-spam-with-email-blacklists/comment-page-1/#comment-120</link>
		<dc:creator>cindy</dc:creator>
		<pubDate>Tue, 01 Feb 2005 17:55:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.shaftek.org/blog/2005/02/01/fighting-trackback-spam-with-email-blacklists/#comment-120</guid>
		<description>as of this morning you can also block them by checking http_via for pinappleproxy.</description>
		<content:encoded><![CDATA[<p>as of this morning you can also block them by checking http_via for pinappleproxy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://www.shaftek.org/blog/2005/02/01/fighting-trackback-spam-with-email-blacklists/comment-page-1/#comment-119</link>
		<dc:creator>John</dc:creator>
		<pubDate>Tue, 01 Feb 2005 17:33:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.shaftek.org/blog/2005/02/01/fighting-trackback-spam-with-email-blacklists/#comment-119</guid>
		<description>Another interesting trick you can use is see what IP address the URLs in comments point to - most comment spammers and referrer spammers have there sites at only one or two IP addresses. Simply block the posting if an URL resolves to one of the forbidden IP addresses...</description>
		<content:encoded><![CDATA[<p>Another interesting trick you can use is see what IP address the URLs in comments point to &#8211; most comment spammers and referrer spammers have there sites at only one or two IP addresses. Simply block the posting if an URL resolves to one of the forbidden IP addresses&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.429 seconds -->
