| Damn Spam! |
|
|
TrackbackTrackback URL for this entry: http://spam.tinyweb.net/trackback.php/unwelcome-new-users Here's what others have to say about 'Unwelcome new users':
iN8sWoRld.net » Blog Archive » Chinese Spam Mafia? Unwelcome new users from Beyond The Network America
Turns out the unwelcome new users all came from some old "friends" of ours, Beyond The Network America. These particular spammers have been hitting Geeklog sites for several months now. Their bot registers a new user, parses the registration email that is being sent out and logs back into the site with that information a minute later, then immediately starts spamming. However, none of those new users managed to log in - probably because the email sent out from the site in question is in German. For the record, here are the IP address ranges owned by Beyond The Network America. We have seen these bots coming from all of those address ranges, so we'd suggest to block them: 205.252.* In the instance here, the bots came from 7 different IP addresses within the 209.8.* range. Now I only have to find out why my .htaccess rule to block them does not seem to work on that particular site ... Unwelcome new users, the sequel
Okay, so fixing my .htaccess blocked any new user registration attempts from the IP addresses in question. However, last night I got yet another new user with a realitypornhouse.com email address. And this time, he managed to log in a post a spam comment. How did that happen?
Sneaky. Note the 209.8.22.250 IP in the referrer. That's in Beyond The Network America's address range, so it's the same bunch of spammers, only now they're using proxies. More stuff to block
Two more domain names used for account creation: onlygaybutts.com, interracial-porn.biz I've also noticed that a human went through the signup process (coming from the same network and using one of the domains mentioned here). So someone is monitoring this and noticed my countermeasures. Good to know ... And IronMax has a list of IP address ranges worth blocking that also includes a few more address ranges belonging to Beyond the Network America that I wasn't aware of. |
||||||||||
| Copyright © 2008 Damn Spam! | Powered By Geeklog |