<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: FBI Spam</title>
	<atom:link href="http://www.timboucher.com/journal/2006/05/18/fbi-spam/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.timboucher.com/journal/2006/05/18/fbi-spam/</link>
	<description>public domain playground. friendly entities welcome.</description>
	<pubDate>Sun, 22 Nov 2009 19:51:24 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: The Evolution of Spam-Consciousness - Pop Occulture</title>
		<link>http://www.timboucher.com/journal/2006/05/18/fbi-spam/comment-page-1/#comment-16967</link>
		<dc:creator>The Evolution of Spam-Consciousness - Pop Occulture</dc:creator>
		<pubDate>Thu, 25 May 2006 18:05:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.timboucher.com/journal/2006/05/18/fbi-spam/#comment-16967</guid>
		<description>[...] While we&#8217;re on the subject, also check out the spammy blog posts that Garrett recently discovered. Are they written by a real person or a script which is able to simulate natural language? Then we have the enormous spam attacks several of us have been enduring via comments and trackbacks on our WordPress blogs. [...]</description>
		<content:encoded><![CDATA[<p>[...] While we&#8217;re on the subject, also check out the spammy blog posts that Garrett recently discovered. Are they written by a real person or a script which is able to simulate natural language? Then we have the enormous spam attacks several of us have been enduring via comments and trackbacks on our WordPress blogs. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim Boucher</title>
		<link>http://www.timboucher.com/journal/2006/05/18/fbi-spam/comment-page-1/#comment-15304</link>
		<dc:creator>Tim Boucher</dc:creator>
		<pubDate>Sat, 20 May 2006 19:41:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.timboucher.com/journal/2006/05/18/fbi-spam/#comment-15304</guid>
		<description>Well, you know you can just turn off comments and trackbacks in WordPress, right? It's really no reason to leave WP. Anyway, with this blog, I'm also really not willing to turn them off because the whole point is the conversational element, really. But this Akismet plugin seems to be getting the job done just fine.</description>
		<content:encoded><![CDATA[<p>Well, you know you can just turn off comments and trackbacks in WordPress, right? It&#8217;s really no reason to leave WP. Anyway, with this blog, I&#8217;m also really not willing to turn them off because the whole point is the conversational element, really. But this Akismet plugin seems to be getting the job done just fine.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan</title>
		<link>http://www.timboucher.com/journal/2006/05/18/fbi-spam/comment-page-1/#comment-14534</link>
		<dc:creator>Dan</dc:creator>
		<pubDate>Fri, 19 May 2006 19:04:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.timboucher.com/journal/2006/05/18/fbi-spam/#comment-14534</guid>
		<description>I had exactly the same phenteremine attacks for ages. In the end, I found they were mostly coming from a particular subnet range, so I just just blocked that subnet (via .htaccess). I kept getting lots of spam after from other sites though, another reason why I packed in wordpress. That's why I'm now comment free and happy at the moment :)</description>
		<content:encoded><![CDATA[<p>I had exactly the same phenteremine attacks for ages. In the end, I found they were mostly coming from a particular subnet range, so I just just blocked that subnet (via .htaccess). I kept getting lots of spam after from other sites though, another reason why I packed in wordpress. That&#8217;s why I&#8217;m now comment free and happy at the moment <img src='http://www.timboucher.com/journal/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim Boucher</title>
		<link>http://www.timboucher.com/journal/2006/05/18/fbi-spam/comment-page-1/#comment-14524</link>
		<dc:creator>Tim Boucher</dc:creator>
		<pubDate>Fri, 19 May 2006 16:17:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.timboucher.com/journal/2006/05/18/fbi-spam/#comment-14524</guid>
		<description>Uh.... what? So what do I need to do?</description>
		<content:encoded><![CDATA[<p>Uh&#8230;. what? So what do I need to do?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thomas Conlon</title>
		<link>http://www.timboucher.com/journal/2006/05/18/fbi-spam/comment-page-1/#comment-14104</link>
		<dc:creator>Thomas Conlon</dc:creator>
		<pubDate>Fri, 19 May 2006 08:20:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.timboucher.com/journal/2006/05/18/fbi-spam/#comment-14104</guid>
		<description>Seems like pingbacks are being used to probe your version of wp as there seems to be a recent bug, I would assume buffer overflow as the likely desired effect.

xml-rpc call plus malicious code and incorrect user permissions (like if the pingback flooded your buffer and inserted an o/s command to set up a pptp tunnel and environment for a user who can log in remotely because his xml shit was run as administrator or the service account for apache.

I would expect a phenteramine company using php probes to want to infiltrate in order to hijack your mail server and send spam.

Apparently you can do:
"0Ã—0031 (49) 
Access denied " as a return code so there must be some type of filtering module

The bad news is that XMLRPC is plain scary and you may be getting a little probe against your system with each pingback

"The payload is in XML, a single  structure.

The  must contain a  sub-item, a string, containing the name of the method to be called. The string may only contain identifier characters, upper and lower-case A-Z, the numeric characters, 0-9, underscore, dot, colon and slash. It's entirely up to the server to decide how to interpret the characters in a methodName. "

Like how bout i rip on mysql usernames not "mary's blog linked to joe's"
or you gotta have perl installed with php right?  Lots you can do to the os there, good luck.

-tc</description>
		<content:encoded><![CDATA[<p>Seems like pingbacks are being used to probe your version of wp as there seems to be a recent bug, I would assume buffer overflow as the likely desired effect.</p>
<p>xml-rpc call plus malicious code and incorrect user permissions (like if the pingback flooded your buffer and inserted an o/s command to set up a pptp tunnel and environment for a user who can log in remotely because his xml shit was run as administrator or the service account for apache.</p>
<p>I would expect a phenteramine company using php probes to want to infiltrate in order to hijack your mail server and send spam.</p>
<p>Apparently you can do:<br />
&#8220;0Ã—0031 (49)<br />
Access denied &#8221; as a return code so there must be some type of filtering module</p>
<p>The bad news is that XMLRPC is plain scary and you may be getting a little probe against your system with each pingback</p>
<p>&#8220;The payload is in XML, a single  structure.</p>
<p>The  must contain a  sub-item, a string, containing the name of the method to be called. The string may only contain identifier characters, upper and lower-case A-Z, the numeric characters, 0-9, underscore, dot, colon and slash. It&#8217;s entirely up to the server to decide how to interpret the characters in a methodName. &#8221;</p>
<p>Like how bout i rip on mysql usernames not &#8220;mary&#8217;s blog linked to joe&#8217;s&#8221;<br />
or you gotta have perl installed with php right?  Lots you can do to the os there, good luck.</p>
<p>-tc</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: zacharius</title>
		<link>http://www.timboucher.com/journal/2006/05/18/fbi-spam/comment-page-1/#comment-14096</link>
		<dc:creator>zacharius</dc:creator>
		<pubDate>Thu, 18 May 2006 23:30:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.timboucher.com/journal/2006/05/18/fbi-spam/#comment-14096</guid>
		<description>yeah, i already had that. it puts them all into batch moderation. no sweat.

 hold on...

 there's a FBI assault team outside my door...

FUCK!!</description>
		<content:encoded><![CDATA[<p>yeah, i already had that. it puts them all into batch moderation. no sweat.</p>
<p> hold on&#8230;</p>
<p> there&#8217;s a FBI assault team outside my door&#8230;</p>
<p>FUCK!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim Boucher</title>
		<link>http://www.timboucher.com/journal/2006/05/18/fbi-spam/comment-page-1/#comment-14051</link>
		<dc:creator>Tim Boucher</dc:creator>
		<pubDate>Thu, 18 May 2006 22:18:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.timboucher.com/journal/2006/05/18/fbi-spam/#comment-14051</guid>
		<description>I've also just installed Akismet so hopefully a lot of these spam problems will be diminished even further:

http://akismet.com/faq/</description>
		<content:encoded><![CDATA[<p>I&#8217;ve also just installed Akismet so hopefully a lot of these spam problems will be diminished even further:</p>
<p><a href="http://akismet.com/faq/" rel="nofollow"></a><a href='http://akismet.com/faq/'>http://akismet.com/faq/</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
