Log in

View Full Version : Referrer Spamming? No, thanks.



bi11i
08-09-2005, 06:55 PM
Today when checking my Junkylife blog, I found a comment to a recently posted entry. The email address listed as [email protected] (which isn't functional) and the message to my post, "the most popular cannabis website in the world". The URL of course was left as www.cannabis.com. The IP is easily traceable to here, as well. Three more comments left with the same message, email, and IP, none of which have anything to do with any of my posts.

First of all, my 'Feedback & Suggestion' to cannabis.com is to stop your referrer spamming. Not only is it completely rude, but it's totally ineffective. I suggest you read up on the new 'nofollow' tag which tells Google and other such search engines to ignore these URLs in blogging comments. Essentially, the only thing you're doing is pissing me off and driving me away. Here are some links to further assist: http://www.sixapart.com/pronet/weblog/2005/01/introduction_to.html
http://blog.searchenginewatch.com/blog/050118-204728

My second suggestion, being the admin and creator of a moderately trafficked discussion-based board (focusing in a somewhat similar area as cannabis.com) is to take the time to build your community legitimately. Spamming my blog is no way to get my positive attention. Why not make some banners to be used in conjunction with vBulletin's referrer field? If you've a licensed copy of your forum software, there are many, MANY add-ons that allow you to spread the word without offending those around you. Hosting, running, and promoting a site such as yours by using illegitimate means certainly can't do anything good for your cause, can it? What does this say about your organization?

Also, show some respect, eh? I'm certainly interested in what you might have to say, but you can't present it to me by shoving it up my arse - I just don't respond all that well to that type of marketing. Make [email protected] a valid email address so I have someplace to gripe other than having to post it here, for all to see. I'm fairly certain you'll delete this anyway, so it probably doesn't matter, but if you're making yourself available to moderate each and every member on your board, shouldn't I be able to at least use your 'Contact Us' link below to get in touch with you?

Finally, here's a suggestion: give credit where credit is due. If you're running a legit copy of vBulletin, then why remove the copyright info when it specifically violates your user agreement and cripples your forum software?

All in all, your site looks great - lots of info, lots of linkage and resource - I honestly think you're doing yourself more harm than good by taking the spammer route. Just my $.02. (Oh yeah, and stop spamming my blog, ok? Thanks.)

Beeblebrox.420
08-09-2005, 07:06 PM
I'm reasonably certain you're the victim of a spammer who is forging his email header - a trivial thing to do. I've never received any spam directly from this website. I will direct Ron Bennett, the site registrant and owner, to this thread, however. AFAIK, this site does not send unsolicited emails.

Cannabis.com
08-09-2005, 08:10 PM
We don't spam, period.

Sounds like someone or bot posted some comments to your blog.

Feel free to post the originating IP address(es) - perhaps there's an open proxy on here somewhere we are not aware of, etc.

Ron

Beeblebrox.420
08-09-2005, 08:17 PM
I missed that it was a post, not an email. If it IS an IP address that traceroutes back to here, then it's probably forged as well. It's trivial (well, if you understand how) to forge an IP address, as long as you neither need nor expect a TCP/IP ACKnowledgement packet in return. No, I'm not going to detail the process.

bi11i
08-09-2005, 10:35 PM
Here's what I've got:



A new comment on the post #120 "2003.03.11" is waiting for your approval http://www.removedbyme.com/index.php/2003/03/11/20030311/ (http://www.removedbyme.com/index.php/2003/03/11/20030311/)

Author : the most popular cannabis website in the world (IP: 69.20.59.47 , 69.20.59.47) E-mail : [email protected]

URI : http://www.cannabis.com (http://www.cannabis.com/)

Whois: http://ws.arin.net/cgi-bin/whois.pl?queryinput=69.20.59.47 Comment:

<a href="http://www.cannabis.com" rel="nofollow"> the most popular cannabis website in the world </a>
Normally I just delete these and move on, however it just appears to be so much extra effort to spoof something like this (especially for a non-email spoof), and for what?

Either way, I appreciate your quick response and your looking into it.

Cannabis.com
08-09-2005, 11:24 PM
It appears the program determined the author's IP from the email address field? ... some things don't look right:

1. #120 "2003.03.11" ? Are you talking about a comment in your blog from March of 2003!? We didn't even use that IP until Jan-2004.

2. The IP is shown as 69.20.59.47, 69.20.59.47 with no reverse record even though the IP actually has one - or perhaps the reverse is forged to appear as the IP address ... if so, that's a new twist to bogus reverse records I'd not seen before.

Feel free to post more details, if any, regarding this matter - again, we don't spam, period.

Ron

red662
08-10-2005, 06:54 PM
i have never recieved mail from c.com only at registration 2 confirm my password.

bi11i
08-12-2005, 08:38 PM
1. Comments are timeless - you can comment on posts dating back to 2000, if a person would want to. All comments were left on the same day, on misc posts - typical bot activity.

2. Wordpress determines the IP based what it receives from the commenter's browser at the time of comment - not via email. I am, however, emailed this information. Could be spoofed and according to you it definitely is - I'll take your word for it, although I'm definitely intrigued as to why someone would put forth that much promotional effort for nothing....

I've received nothing additional since then and have had no complaints from any of the other 40 blogs hosted by me - I'll leave it as a fluke and will certainly come back if I see anything additional.

Thanks for looking into it. I'd love to see some email functionality here (so the subscription, notification, and contact us features would be in working order.) What gives?


It appears the program determined the author's IP from the email address field? ... some things don't look right:

1. #120 "2003.03.11" ? Are you talking about a comment in your blog from March of 2003!? We didn't even use that IP until Jan-2004.

2. The IP is shown as 69.20.59.47, 69.20.59.47 with no reverse record even though the IP actually has one - or perhaps the reverse is forged to appear as the IP address ... if so, that's a new twist to bogus reverse records I'd not seen before.

Feel free to post more details, if any, regarding this matter - again, we don't spam, period.

Ron

Cannabis.com
08-13-2005, 02:02 AM
While there's the possibility of an unknown open proxy on the server and/or other security vulnerability, it appears to me that the IP is forged and/or Wordpress is perhaps somehow being fooled - again I say that because that IP has a reverse record, and yet the entry you posted doesn't include that part.

Anyways, if it happens again, post here as soon as possible and I'll have the logs, etc looked into for anything unusual.

In the meantime, if your blog has an IP ban feature, feel free to ban the IPs associated with this site if you want.

Thank you for taking the time to post the details, and your patience.

Ron