25 October 2005

Comment Spammers from

Stepping into an ugly mess

Some (new?) spambot is trawling my site lately, possibly looking for open comment forms. I see some of them coming in from hosts like ( and ( Searching the web for references to shows lots of guestbook and bulletin board bot entries and a page on the "Spam Huntress" weblog (and following to this one about "new master spambot"). Tracerouting those IPs reveals that they seem to go through -- which belongs to (Net Access Corporation, a spam-friendly hosting provider, who knows?). Maybe I'll send the URL of this post here to Read on for a bit more details...

The bot lists several typical IE user agent strings. Typical for the log entries is that they don't load images or css files and that the referrer is the same page that it accesses, but without the ending slash. Some samples: - - [25/Oct/2005:15:10:17 +0200] "GET /blogs/ch-athens/112/ HTTP/1.1" 200 6917 "" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1)" - - [25/Oct/2005:15:19:10 +0200] "GET /blogs/ch-athens/89/ HTTP/1.1" 200 5616 "" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)" - - [25/Oct/2005:15:24:49 +0200] "GET /blogs/ch-athens/88/ HTTP/1.1" 200 6257 "" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)"
The rate of access is not very high, the bot is possibly trying to avoid throttle defenses. It sounds very much like this bot is just searching for blogs/guestbooks/bulletin boards to spam, while the spamming itself will be done by another bot (what "Spam Huntress" refers to as "master spambot"). Filtering them out could be done at the IP level, untill they move on to another provider.

UPDATE: It seems my thoughts on Net Access Corporation were right, see this Senderbase report on Net Access Corporation showing lots of SPAM coming from their IPs.

Posted by betabug at 16:02 | Comments (2) | Trackbacks (0)
Re: Comment Spammers from

"Check" on that! They came in from a fellow blogger who linked to me. They detected the comment cgi straight away and went entry after entry, for the range of some days now. It looks like the script stops after a "set" of hits. Each sneak attack of them was eventually followed by comment spam coming from totally different locations. So ... I guess this is another confirm, huh? :)
And thanks for this post - I was just researching about what's been hitting my site lately.

Posted by: avitali at November 06,2005 19:42
Re: Comment Spammers from

Thanks for posting this - I was getting quite a few hits from the same source and was a little concerned. Looks like I'll be updating htaccess.....

Posted by: Jeff at January 04,2006 16:04
