All Narfed Up photography and words by Bryan Villarin

Bad Behavior not 100%?

I’m not sure what’s going on, but a lot comment spam from 71.57.133.162 is getting through. Bad Behavior 1.2.2 is filtering everything but that one, it seems. (Yes, I did check the logs for activity.) I emailed Mike two days ago, but haven’t gotten a reply yet. For now, I’ve denied that IP access via .htaccess. Update: I didn’t realize that I wasn’t alone on this. Tom and Anne got hit, too.

 

10 Comments

Bryan,

a lot of us were hit by that one - see:
http://www.tomrafteryit.net/comment-spam-run-last-night/

I blocked via .htaccess as well

Posted by Tom Raftery on 6 October 2005 @ 7am

Weird! Fortunately, they didn’t get all the way through - I just meant that BB never stopped it at the gates. My moderation list must’ve stopped it or something, I don’t know.

I hope Ann gets whoever it is! :)

Posted by Bryan on 6 October 2005 @ 10am

I’ve been getting him by that IP a lot too!

Posted by Nick on 6 October 2005 @ 11am

Add to .htaccess:

deny from 71.57.133.162

Posted by Bryan on 6 October 2005 @ 12pm

Ah, yes, you did e-mail me. A PICTURE. I can’t do anything with a PICTURE!

Posted by IO ERROR on 6 October 2005 @ 12pm

I’m sorry Mike, I know! Don’t be mad, I’ll keep watching the logs.

You’re still the greatest…

Posted by Bryan on 6 October 2005 @ 1pm

And, just to clarify, Michael Hampton hates false positives, so Bad Behavior will never be “100%”.

So far, my blacklist has picked up all of the spam that BB has let through.

Posted by MacManX on 6 October 2005 @ 7pm

Yeah, your blacklist definitely provides that extra level of “defense”. I’m still happy overall, and I didn’t mean to make it sound like I was complaining.

Posted by Bryan on 6 October 2005 @ 10pm

I’ve noticed a huge increase on my site as well… although haven’t found a duplicate IP (although haven’t paid much attention aside from the IP shown in the WP Moderation queue). None have gotten through the need to be an approved commenter… but considering that this is recent… wonder if HashCash has been broken.

Posted by Chris on 7 October 2005 @ 7pm

Yeah, for me, Michael says it’s being manually entered in. So it’s not spambots. All spam is still being caught by WordPress built-in countermeasures, alongside with a moderation word list and word blacklist.

Posted by Bryan on 8 October 2005 @ 8am

Leave a Comment

ATI gone bad? FAlbum displays Flickr photos on WordPress