Block libwww-perl with POST

I’ve been so busy this last week, I haven’t posted.

Comment spam has really exploded lately. I think Rathamahata might be right - probably lots of newbie Russian spammers out there.

So I took a random comment spam, and turned it inside out. It happened to be the last one to arrive.

valentine-day-gift-idea.50megs.com
has a javascript that ultimately leads to affiliate ID: 49221 at topsearch10, as well as links from the body pointing the same place.

What was interesting with the free webhost here, is that when I tried to load the javascript in wannabrowser, I got an error, but it worked in a regular browser. Now, WHY is that? Got something to hide?

K, back to the spammer.

This is a low volume spammmer, unlike some of the others I’ve seen lately.

User agent:
libwww-perl/5.803
I’ve had hits with that user agent from others. Some asking for robots.txt, some legitimate spiders. And one legitimate feed reader: XmlRssTimingBot/2.03 (libwww-perl/5.803). I’m leaning towards blocking POST as a request type with this user agent. I’ve also seen other versions of this user agent. Other software revisions. So block libwww-perl with POST.

IP:
204.15.149.58
It’s a proxy

Other IP addresses seen with that user agent (various versions), posting comments:
201.6.101.190 (proxy in Brazil)
64.246.42.58 (proxy. EV1 server)
202.57.138.131 (proxy in Bangkok)

E-mail address:
xanax@yandex.ru
(I got a few others from that address, and so far that corresponds with the user agent)

One Response to “Block libwww-perl with POST”

  1. Etanisla says:

    Speaking of libwww-perl, I’m getting a string of attempted trackback spams coming from 38.96.1.145. Should I be concerned that this IP is located in Washington D.C.? Half wants to don the conspiracy hat, the other half is too busy laughing at the current conspiracies already out there.

    Anyways… The user agent of the bot is:
    “Biyubi/5.0 (Sistema Fenix; G11; Familia Toledo; es-mx) 3 pages libwww-perl/5.65″

    Biyubi is a legit browser for a Mexican themed Linux distro (Fenix). It is the part at the end that allows me to comment today.

    The bot is trying to get around refer checks by using “google.com” as the refer. Anyone that has read sitelogs should easily spot why this is a false refer.

Leave a Reply