<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Spambot trackback spam attack in Security</title>
<link>http://www.dslreports.com/forum/r20232374</link>
<description></description>
<language>en</language>
<pubDate>Thu, 21 Aug 2008 01:32:39 EDT</pubDate>
<lastBuildDate>Thu, 21 Aug 2008 01:32:39 EDT</lastBuildDate>

<item>
<title>Re: Spambot trackback spam attack</title>
<link>http://www.dslreports.com/forum/remark,20232374</link>
<description><![CDATA[<A HREF="/useremail/u/506525"><b>rahlquist</b></A> : its a server, not gonna be changing IP's they are hitting me by domain name anyway, if they were hitting by IP they would hit my primary domain, not this one. (virtual named domains in apache).<br><br>More interested in getting the compromised machine owners to fixing their boxes than anything else, as it sits their impact on my machine now is minimal. I just want to be able to end it now that the problem is identified.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20232374</guid>
<pubDate>Thu, 27 Mar 2008 00:32:29 EDT</pubDate>
</item>

<item>
<title>Re: Spambot trackback spam attack</title>
<link>http://www.dslreports.com/forum/remark,20232351</link>
<description><![CDATA[<A HREF="/useremail/u/1531837"><b>Its a Secret</b></A> : As we were posting at the same time, try changing the ip of your router? It may help.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20232351</guid>
<pubDate>Thu, 27 Mar 2008 00:25:03 EDT</pubDate>
</item>

<item>
<title>Re: Spambot trackback spam attack</title>
<link>http://www.dslreports.com/forum/remark,20232331</link>
<description><![CDATA[<A HREF="/useremail/u/506525"><b>rahlquist</b></A> : <div class="bquote"><small>said by  Its a Secret <A HREF="/useremail/u/1531837"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Probably bots and unknown to the hosts. Just use software and router blocks to CYA. Good luck.<br><br>PS-Have you notified your ISP?<br> </div>My host is aware of the situation and has been helpful and is willing to do what they can. The problem is its a blog site and they were successful at first so they have tossed a good many zombies at this task.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20232331</guid>
<pubDate>Thu, 27 Mar 2008 00:18:46 EDT</pubDate>
</item>

<item>
<title>Re: Spambot trackback spam attack</title>
<link>http://www.dslreports.com/forum/remark,20232317</link>
<description><![CDATA[<A HREF="/useremail/u/1531837"><b>Its a Secret</b></A> : Probably bots and unknown to the hosts. Just use software and router blocks to CYA. Good luck. <br><br>PS-Have you notified your ISP? Also, try changing your router ip.<br><br>(edited for comments)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20232317</guid>
<pubDate>Thu, 27 Mar 2008 00:14:52 EDT</pubDate>
</item>

<item>
<title>Spambot trackback spam attack</title>
<link>http://www.dslreports.com/forum/remark,20232302</link>
<description><![CDATA[<A HREF="/useremail/u/506525"><b>rahlquist</b></A> : Hey folks,<br><br>I am currently being slowly but steadily attacked from multiple IP's that are trying to inject trackbacks to spam sites such as;<br><br><textarea name="code" class="text" cols=50 rows=10>205.234.137.18 - - &#91;26/Mar/2008:12:34:25 -0400&#93; "POST /trackback/48075?url=http%3A%2F%2Flevaquin.blinklist.com&amp;title=Levaquin+and+joint+pain&amp;blog_name=Levaquin+and+joint+pain&amp;excerpt=Levaquin+side+effects.+Levaquin+in+dogs.+Side+effects+of+levaquin.+Levaquin+in+dogs HTTP/1.0" 301 565 "-" "-"&#012;</textarea><!--end code block--><br>While I do have the attack under control for now using fail2ban on the server this is happening to (I modfied a default filter to ban any IP's hitting the /trackback/ on my site since I disabled it), what I would like to know is this.<br><br>As it stands I have a list of over 140 ip's that are comprimised zombies, is there anything that can be done to get these owners to clean these up short of doing a whois on each IP and trying to find a contact?<br><br><small>--<br>Fed Up With Stupidity?<br><br><A HREF="http://www.patentlystupid.com">Patentlystupid.com</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20232302</guid>
<pubDate>Thu, 27 Mar 2008 00:10:13 EDT</pubDate>
</item>

</channel>
</rss>
