YES, //drupal (and willy) are growing up; the first spam article on willy has been //posted. The //MT community (way more popular than drupal for unknown reasons) have had //spam for a long time as well as //"solutions" for this misbehave. Drupal doesnt have a anti spam module (yet), but I do think about giving anonymous no rights to post.
The user has the address 208.147.1.1 with is a CIDR block belonging to ... big surprise ... //C&W.
The spam wasn't posted with an automated job, but a real person behind a keyboard (either that or a very smart script emaulting a very stupid user) calling herself Jenny.
According to //google she (?) didnt post a lot with this spam, only 2 messages yet. But google might be cathing up, willy isnt listed yet as well.
This is one of the log entries:
208.147.1.1 - - 13/Apr/2004:17:30:18 +0200 "POST /myblog/comment/reply/5031 HTTP/1.1" 302 38 "http://willy.boerland.com/myblog/comment/reply/5031" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
Not a very interesting box (23/tcp filtered telnet, 25/tcp filtered smtp, 80/tcp filtered, http, 135/tcp filtered msrpc, 161/tcp filtered snmp, 8080/tcp filtered http-proxy). The promoted website seems a lot more interesting, but please kids dont do anything I wouldnt do! :-)
1/tcp open tcpmux
21/tcp open ftp
22/tcp open ssh OpenSSH 3.1p1 (protocol 1.99)
25/tcp open smtp Exim smtpd 4.24
80/tcp open http Apache httpd 1.3.29
110/tcp open pop3 cppop pop3d 9.9
111/tcp open rpcbind
135/tcp filtered msrpc
143/tcp open imap UW Imapd 2003.339-cpanel
443/tcp open ssl OpenSSL
465/tcp open ssl OpenSSL
993/tcp open ssl OpenSSL
995/tcp open ssl OpenSSL
3306/tcp open mysql MySQL 4.0.18-standard
6666/tcp open melange Melange Chat Server 1.10
OS details: Linux 2.4.6 - 2.4.21
Uptime 17.889 days (since Fri Mar 26 22:37:32 2004)
The funny thing is the way "Jenny" (our friend) found willy. "She" is searching for "adding comments blog/forum " on google:
http://www.google.co.th/search?q=blogs+add+a+comment&ie=UTF-8&oe=UTF-8&hl=en&btnG=Google+Search&meta= http://www.google.co.th/search?q=Forum+add+a+comment&hl=en&lr=&ie=UTF-8&oe=UTF-8&start=130&sa=N
and because of drupal's [friendly] url's, willy ranks high in both searches.
So dear willy readers. What should we do with this?
- Retract comment posting rights from anonymous users?
- Delete the comment?
- Googlebomb the spammed site?
- Ignore this all together?
- Or do you have a better idea and do you want to post this (anonymous? ;-) )
Share your mind, post it here!