<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.7" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Wiki-spam attack from diving-deep</title>
	<link>http://spamhuntress.com/2007/04/28/wiki-spam-attack-from-diving-deep/</link>
	<description>Just another WordPress weblog</description>
	<pubDate>Fri, 22 Aug 2008 04:18:27 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.7</generator>

	<item>
		<title>by: tuxsoul</title>
		<link>http://spamhuntress.com/2007/04/28/wiki-spam-attack-from-diving-deep/#comment-323933</link>
		<pubDate>Sun, 20 Jan 2008 14:26:28 +0000</pubDate>
		<guid>http://spamhuntress.com/2007/04/28/wiki-spam-attack-from-diving-deep/#comment-323933</guid>
					<description>Hi, sorry my english is bad, a few time ago, really a few hour's i have write one small extension to mediawiki to use project honey pot, if you use mediawiki you can test this extension.

Greeting's :wink:</description>
		<content:encoded><![CDATA[<p>Hi, sorry my english is bad, a few time ago, really a few hour&#8217;s i have write one small extension to mediawiki to use project honey pot, if you use mediawiki you can test this extension.</p>
<p>Greeting&#8217;s  <img src='http://spamhuntress.com/wp-includes/images/smilies/icon_wink.gif' alt=':wink:' class='wp-smiley' />
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: plr</title>
		<link>http://spamhuntress.com/2007/04/28/wiki-spam-attack-from-diving-deep/#comment-220722</link>
		<pubDate>Wed, 01 Aug 2007 20:58:44 +0000</pubDate>
		<guid>http://spamhuntress.com/2007/04/28/wiki-spam-attack-from-diving-deep/#comment-220722</guid>
					<description>www.equant.ru redirectls to www.orange-business.ru
Contacts are here: http://www.orange-business.ru/about/contacts/
Moscow office:
ul Yakimanskaya nab. 4-1, Moscow
phones: +7-495-620-9500, +7-495-705-9229</description>
		<content:encoded><![CDATA[<p><a href="http://www.equant.ru" rel="nofollow">www.equant.ru</a> redirectls to <a href="http://www.orange-business.ru" rel="nofollow">www.orange-business.ru</a><br />
Contacts are here: <a href="http://www.orange-business.ru/about/contacts/" rel="nofollow">http://www.orange-business.ru/about/contacts/</a><br />
Moscow office:<br />
ul Yakimanskaya nab. 4-1, Moscow<br />
phones: +7-495-620-9500, +7-495-705-9229
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Ahasuerus</title>
		<link>http://spamhuntress.com/2007/04/28/wiki-spam-attack-from-diving-deep/#comment-195075</link>
		<pubDate>Fri, 15 Jun 2007 22:15:23 +0000</pubDate>
		<guid>http://spamhuntress.com/2007/04/28/wiki-spam-attack-from-diving-deep/#comment-195075</guid>
					<description>These folks have been spamming the ISFDB Wiki for over a week now. We may be forced to upgrade to a more recent version of the MediaWiki software and implement captchas :(

The Russian language site is apparently owned by the Russian affiliate of France Telecom ("FT group") and the parent company's Webmaster's e-mail address is infos.groupe@orange-ftgroup.com according to http://www.francetelecom.com/en/tools/contact/index.html.</description>
		<content:encoded><![CDATA[<p>These folks have been spamming the ISFDB Wiki for over a week now. We may be forced to upgrade to a more recent version of the MediaWiki software and implement captchas <img src='http://spamhuntress.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<p>The Russian language site is apparently owned by the Russian affiliate of France Telecom (&#8221;FT group&#8221;) and the parent company&#8217;s Webmaster&#8217;s e-mail address is <a href="mailto:infos.groupe@orange-ftgroup.com">infos.groupe@orange-ftgroup.com</a> according to <a href="http://www.francetelecom.com/en/tools/contact/index.html." rel="nofollow">http://www.francetelecom.com/en/tools/contact/index.html.</a>
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Comment Spam @ WordPress &#171; Dasher&#8217;s Corner</title>
		<link>http://spamhuntress.com/2007/04/28/wiki-spam-attack-from-diving-deep/#comment-183745</link>
		<pubDate>Tue, 22 May 2007 08:38:18 +0000</pubDate>
		<guid>http://spamhuntress.com/2007/04/28/wiki-spam-attack-from-diving-deep/#comment-183745</guid>
					<description>[...] It&#8217;s not just Blogs that are suffering - wiki pollution is a growing problem with poorly secured or badly implemented Wikis.  SpamHuntress wrote recently about a massive wiki spam issue on one of the sites she manages.  It&#8217;s a tough nut to crack - there isn&#8217;t a clear definition or deliniation of responsabilities on who is responsible for what.  Is it the responsibility of the site owner to make sure their site is secure?  Some would say so&#8230; but when you try to operate a large community effort (such as managing or maintaining a wiki where you want to promote community participation) implementing extras controls (such as user authentication &#38; validation) dissuade people from participating. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] It&#8217;s not just Blogs that are suffering - wiki pollution is a growing problem with poorly secured or badly implemented Wikis.  SpamHuntress wrote recently about a massive wiki spam issue on one of the sites she manages.  It&#8217;s a tough nut to crack - there isn&#8217;t a clear definition or deliniation of responsabilities on who is responsible for what.  Is it the responsibility of the site owner to make sure their site is secure?  Some would say so&#8230; but when you try to operate a large community effort (such as managing or maintaining a wiki where you want to promote community participation) implementing extras controls (such as user authentication &amp; validation) dissuade people from participating. [&#8230;]
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: admin</title>
		<link>http://spamhuntress.com/2007/04/28/wiki-spam-attack-from-diving-deep/#comment-177594</link>
		<pubDate>Tue, 08 May 2007 00:12:40 +0000</pubDate>
		<guid>http://spamhuntress.com/2007/04/28/wiki-spam-attack-from-diving-deep/#comment-177594</guid>
					<description>Hi ALM,

There are some factors that will give more results when it comes to abuse reports. In my experience, these are some factors: Trust (that the person you complain to know that you know your stuff, and won't send false reports), Power (if you've got a public platform where people actually read your findings), Ease of investigation (some forms of abuse are easier to investigate than others).

I'd love to see the code you used to get that information. Not sure it'll work in my contact form, but maybe?

Also, if you do a search for that IP number on Google, you'll find lots of independent proof that something is up there. Lots of wiki diffs with that IP as author.</description>
		<content:encoded><![CDATA[<p>Hi ALM,</p>
<p>There are some factors that will give more results when it comes to abuse reports. In my experience, these are some factors: Trust (that the person you complain to know that you know your stuff, and won&#8217;t send false reports), Power (if you&#8217;ve got a public platform where people actually read your findings), Ease of investigation (some forms of abuse are easier to investigate than others).</p>
<p>I&#8217;d love to see the code you used to get that information. Not sure it&#8217;ll work in my contact form, but maybe?</p>
<p>Also, if you do a search for that IP number on Google, you&#8217;ll find lots of independent proof that something is up there. Lots of wiki diffs with that IP as author.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: ALM</title>
		<link>http://spamhuntress.com/2007/04/28/wiki-spam-attack-from-diving-deep/#comment-177553</link>
		<pubDate>Mon, 07 May 2007 20:47:14 +0000</pubDate>
		<guid>http://spamhuntress.com/2007/04/28/wiki-spam-attack-from-diving-deep/#comment-177553</guid>
					<description>... and I heard back from emil at intercage,

"Thanks for reporting this, I am going to look into what is happening."

(Moderator: I changed the full e-mail address to a partial one, so Emil wouldn't get too much spam)</description>
		<content:encoded><![CDATA[<p>&#8230; and I heard back from emil at intercage,</p>
<p>&#8220;Thanks for reporting this, I am going to look into what is happening.&#8221;</p>
<p>(Moderator: I changed the full e-mail address to a partial one, so Emil wouldn&#8217;t get too much spam)
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: ALM</title>
		<link>http://spamhuntress.com/2007/04/28/wiki-spam-attack-from-diving-deep/#comment-177551</link>
		<pubDate>Mon, 07 May 2007 20:42:30 +0000</pubDate>
		<guid>http://spamhuntress.com/2007/04/28/wiki-spam-attack-from-diving-deep/#comment-177551</guid>
					<description>Over the past week I've had spam coming through a form.  I started recording the server variables and found that REMOTE_ADDR and HTTP_VIA contained proxy server info (which varied), but HTTP_X_FORWARDED_FOR is always (well, 16 out of 18) 216.255.179.34 which is intercage.  I forwarded my findings to abuse@intercage.com but wasn't expecting response ... but you got one, so maybe I will.</description>
		<content:encoded><![CDATA[<p>Over the past week I&#8217;ve had spam coming through a form.  I started recording the server variables and found that REMOTE_ADDR and HTTP_VIA contained proxy server info (which varied), but HTTP_X_FORWARDED_FOR is always (well, 16 out of 18) 216.255.179.34 which is intercage.  I forwarded my findings to <a href="mailto:abuse@intercage.com">abuse@intercage.com</a> but wasn&#8217;t expecting response &#8230; but you got one, so maybe I will.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: InterCage :: Abuse</title>
		<link>http://spamhuntress.com/2007/04/28/wiki-spam-attack-from-diving-deep/#comment-175123</link>
		<pubDate>Tue, 01 May 2007 15:23:11 +0000</pubDate>
		<guid>http://spamhuntress.com/2007/04/28/wiki-spam-attack-from-diving-deep/#comment-175123</guid>
					<description>Hello Ann,

I appreciate the follow-up in the investigation. 85.255.115.213 has been removed from routing. 

The machine will be reviewed for cancellation per follow-up by our client tomorrow. It is more then likely a vHosting machine, so it may be the result of a single account, rather then a whole server. 

Never the less, Should you encounter this issue further, please follow-up with us.

Thank you for your time. Have a great day.

—
Abuse Department
InterCage, Inc.</description>
		<content:encoded><![CDATA[<p>Hello Ann,</p>
<p>I appreciate the follow-up in the investigation. 85.255.115.213 has been removed from routing. </p>
<p>The machine will be reviewed for cancellation per follow-up by our client tomorrow. It is more then likely a vHosting machine, so it may be the result of a single account, rather then a whole server. </p>
<p>Never the less, Should you encounter this issue further, please follow-up with us.</p>
<p>Thank you for your time. Have a great day.</p>
<p>—<br />
Abuse Department<br />
InterCage, Inc.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: admin</title>
		<link>http://spamhuntress.com/2007/04/28/wiki-spam-attack-from-diving-deep/#comment-175082</link>
		<pubDate>Tue, 01 May 2007 13:12:10 +0000</pubDate>
		<guid>http://spamhuntress.com/2007/04/28/wiki-spam-attack-from-diving-deep/#comment-175082</guid>
					<description>To Forseti:
The spam on my wiki gives me something to write on. And this wasn't an attack on my wiki only. I saw it on another wiki I own (smaller scale), and I believe it was also on other wikis.

To Intercage:
Thanks. I did some URL blocking, so I don't know if the spammer is still at it. I'd have to check someone else's wiki to be sure. But it's of course a "whack a mole" game. They'll be coming back somewhere else. Could you please recheck the domain a few times a week for a while, in case they come back somewhere else in your IP space? I'll recheck now and then too.

Mmm, yeah, right now they're on this IP:

85.255.115.213
85.255.115.213-xbox.dedi.inhoster.com

I wouldn't be surprised if it's the same webhost, but I don't remember if you're upstream from inhoster?</description>
		<content:encoded><![CDATA[<p>To Forseti:<br />
The spam on my wiki gives me something to write on. And this wasn&#8217;t an attack on my wiki only. I saw it on another wiki I own (smaller scale), and I believe it was also on other wikis.</p>
<p>To Intercage:<br />
Thanks. I did some URL blocking, so I don&#8217;t know if the spammer is still at it. I&#8217;d have to check someone else&#8217;s wiki to be sure. But it&#8217;s of course a &#8220;whack a mole&#8221; game. They&#8217;ll be coming back somewhere else. Could you please recheck the domain a few times a week for a while, in case they come back somewhere else in your IP space? I&#8217;ll recheck now and then too.</p>
<p>Mmm, yeah, right now they&#8217;re on this IP:</p>
<p>85.255.115.213<br />
85.255.115.213-xbox.dedi.inhoster.com</p>
<p>I wouldn&#8217;t be surprised if it&#8217;s the same webhost, but I don&#8217;t remember if you&#8217;re upstream from inhoster?
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Forseti</title>
		<link>http://spamhuntress.com/2007/04/28/wiki-spam-attack-from-diving-deep/#comment-175065</link>
		<pubDate>Tue, 01 May 2007 11:55:15 +0000</pubDate>
		<guid>http://spamhuntress.com/2007/04/28/wiki-spam-attack-from-diving-deep/#comment-175065</guid>
					<description>I am sorry to hear about that attack you were subjected to. Other than quality control (both in accepting only qualified contributors and those with good writing skills),  this is one of the reasons I am a proponent of invitation-only accounts. Perhaps you might want to consider such an option as well? Though the number of articles is greatly reduced, one gains in quality and in time - since there is less work in un-doing the edits of spammers, or questionable content.

Sure, it is a different philosophy (exclusive rather than inclusive), but one that is probably better adapted to wikis like yours that has an educational role and objective. I don't think anyone would cry foul if you decided to change your registration system...</description>
		<content:encoded><![CDATA[<p>I am sorry to hear about that attack you were subjected to. Other than quality control (both in accepting only qualified contributors and those with good writing skills),  this is one of the reasons I am a proponent of invitation-only accounts. Perhaps you might want to consider such an option as well? Though the number of articles is greatly reduced, one gains in quality and in time - since there is less work in un-doing the edits of spammers, or questionable content.</p>
<p>Sure, it is a different philosophy (exclusive rather than inclusive), but one that is probably better adapted to wikis like yours that has an educational role and objective. I don&#8217;t think anyone would cry foul if you decided to change your registration system&#8230;
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
