Home > Spam > Fighting link spammers, again.

Fighting link spammers, again.

March 18th, 2005

Looking at my logs this morning, I found that 5 new domains are used by spammers to fake referers hits on websites. Update your blackist friends:

  • .fearcrow.com
  • .vpshs.com
  • .poker-hands-secrets.com
  • .pacific-poker-top-place.com
  • .samiuls.com

Moreover, I randomly chose a range of IP I blacklist to contact their owner when it looked like the owner was definitively not the spammer himself.
Indeed, I found this note on a WHOIS request performed on one compromised IP:

remarks: For any kind of abuse orignating from our network please
remarks: abuse@xxxxxxxx-company.com

I then sent them a mail in order to inform them that 4 of their IP were used to attack other websites.
I’ll quote here the template I wrote down, if it can be useful for others:

Hello,

I run a webserver and have setup a protection against spammers which
give me a list of IP addresses that are used by them to attack websites.

Sometimes, I perform some WHOIS action on those IP to find if I can
contact their owner to inform them that their IP are corrupted by
spammers.

I’m sorry to tell you that, at least …. of yours are in this case:

- IP #1
- IP #2

- IP #N

Those IPs were used by spammers to send malicious HTTP requests on my
webserver.
Maybe you can investigate to see how thoses computers get corrupted.

Note that this becomes a very wide method for spammers, they launch
worms and viruses to get access on webserver and then use them as
“zombie” machines.

Best regards.

If you can, take the time to send such emails, that can be helpful for a lot of people.

Spam

  1. No comments yet.
  1. No trackbacks yet.