<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Spam attack</title>
	<atom:link href="http://specht.com.au/michael/2006/01/27/spam-attack/feed/" rel="self" type="application/rss+xml" />
	<link>http://specht.com.au/michael/2006/01/27/spam-attack/</link>
	<description>A blog from Australia looking at technology, enterprise 2.0, management, Human Resources (HR) and recruitment.</description>
	<lastBuildDate>Thu, 18 Mar 2010 09:53:13 +1100</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Michael Specht</title>
		<link>http://specht.com.au/michael/2006/01/27/spam-attack/comment-page-1/#comment-14821</link>
		<dc:creator>Michael Specht</dc:creator>
		<pubDate>Thu, 10 Aug 2006 22:02:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.specht.com.au/michael/2006/01/27/spam-attack/#comment-14821</guid>
		<description>As the Mastercard ad says &quot;Priceless!&quot;</description>
		<content:encoded><![CDATA[<p>As the Mastercard ad says &#8220;Priceless!&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jason</title>
		<link>http://specht.com.au/michael/2006/01/27/spam-attack/comment-page-1/#comment-14785</link>
		<dc:creator>Jason</dc:creator>
		<pubDate>Thu, 10 Aug 2006 10:02:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.specht.com.au/michael/2006/01/27/spam-attack/#comment-14785</guid>
		<description>This same asshole found a way to infiltrate Annoy.com&#039;s postcard service, which is NOT designed to facilitate spam, since every card has to be entered individually. It does however, allow for people to send postcards  anonymously, since we cannot verify identity, and which is what we free speech advocates have fought for. 

As of late, it seems, someone&#039;s simple revenge on this spamming asshole has been to send postcards TO the people whose companies are being advertized with one small caveat. They are being sent FROM Vsevolod Stetsinsky himself. (Or so it seems!) Surely if he sends his advertisers enough vulgar postcards, they may reconsider hiring him to begin with. Just putting it out there...

http://annoy.com/postcards/</description>
		<content:encoded><![CDATA[<p>This same asshole found a way to infiltrate Annoy.com&#8217;s postcard service, which is NOT designed to facilitate spam, since every card has to be entered individually. It does however, allow for people to send postcards  anonymously, since we cannot verify identity, and which is what we free speech advocates have fought for. </p>
<p>As of late, it seems, someone&#8217;s simple revenge on this spamming asshole has been to send postcards TO the people whose companies are being advertized with one small caveat. They are being sent FROM Vsevolod Stetsinsky himself. (Or so it seems!) Surely if he sends his advertisers enough vulgar postcards, they may reconsider hiring him to begin with. Just putting it out there&#8230;</p>
<p><a href="http://annoy.com/postcards/" rel="nofollow">http://annoy.com/postcards/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: João Craveiro</title>
		<link>http://specht.com.au/michael/2006/01/27/spam-attack/comment-page-1/#comment-14027</link>
		<dc:creator>João Craveiro</dc:creator>
		<pubDate>Thu, 27 Jul 2006 16:02:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.specht.com.au/michael/2006/01/27/spam-attack/#comment-14027</guid>
		<description>&lt;blockquote&gt;Over the last hour I have been under a comment spam attack from 195.225.177.80. Based on a whois search they seem to be coming from an ISP in the Netherlands, specifically RIPE Network Coordination Centre. Doing some background checking on RIPE I would suggest that it is a user on their network somewhere.&lt;/blockquote&gt;

The IP doesn&#039;t belong to RIPE; what you got from the whois is that that IP&#039;s effective whois information is managed by RIPE --- if you check the RIPE whois database, you&#039;ll get the real information (NETCATHOST, apparently at Ucraine, with an abuse e-mail at netcathost.com, a domain for which &lt;code&gt;dig&lt;/code&gt; returns no answers, not even just MX).

I came here through Google, trying to associate NETCATHOST with comment spam (3 comments a day, 6KB worth of spam links, from IPs belonging to the 195.225.176.0/22 range). Now I have enough ground to add &quot;deny from 195.225.176.0/22&quot; to my .htaccess file.</description>
		<content:encoded><![CDATA[<blockquote><p>Over the last hour I have been under a comment spam attack from 195.225.177.80. Based on a whois search they seem to be coming from an ISP in the Netherlands, specifically RIPE Network Coordination Centre. Doing some background checking on RIPE I would suggest that it is a user on their network somewhere.</p></blockquote>
<p>The IP doesn&#8217;t belong to RIPE; what you got from the whois is that that IP&#8217;s effective whois information is managed by RIPE &#8212; if you check the RIPE whois database, you&#8217;ll get the real information (NETCATHOST, apparently at Ucraine, with an abuse e-mail at netcathost.com, a domain for which <code>dig</code> returns no answers, not even just MX).</p>
<p>I came here through Google, trying to associate NETCATHOST with comment spam (3 comments a day, 6KB worth of spam links, from IPs belonging to the 195.225.176.0/22 range). Now I have enough ground to add &#8220;deny from 195.225.176.0/22&#8243; to my .htaccess file.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: More shameless remarks by Larko &#187; Blog Archive &#187; Honorary spammer</title>
		<link>http://specht.com.au/michael/2006/01/27/spam-attack/comment-page-1/#comment-11337</link>
		<dc:creator>More shameless remarks by Larko &#187; Blog Archive &#187; Honorary spammer</dc:creator>
		<pubDate>Tue, 04 Jul 2006 02:15:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.specht.com.au/michael/2006/01/27/spam-attack/#comment-11337</guid>
		<description>[...] Edit: As could be reasonably assumed, I am far from the only blogger that this particular spammer keeps visiting. Michael in Australia has also noticed them. [...]</description>
		<content:encoded><![CDATA[<p>[...] Edit: As could be reasonably assumed, I am far from the only blogger that this particular spammer keeps visiting. Michael in Australia has also noticed them. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ed costello</title>
		<link>http://specht.com.au/michael/2006/01/27/spam-attack/comment-page-1/#comment-2630</link>
		<dc:creator>ed costello</dc:creator>
		<pubDate>Sat, 28 Jan 2006 16:59:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.specht.com.au/michael/2006/01/27/spam-attack/#comment-2630</guid>
		<description>They make money in a couple of ways.  By getting other sites to link back to them, they build up juice in the various search engines.  They also (depends on the content of the comment spam) use it as a way of driving traffic to their sites since typically the content of the comment gets indexed along with the content of the original post, so search queries which wouldn&#039;t necessarily return either the post or the comment, end up returning the now-spammed post.  Typically they only need a couple of people to click on the link for it to be worthwhile, and unfortunately there are people who will do just that.</description>
		<content:encoded><![CDATA[<p>They make money in a couple of ways.  By getting other sites to link back to them, they build up juice in the various search engines.  They also (depends on the content of the comment spam) use it as a way of driving traffic to their sites since typically the content of the comment gets indexed along with the content of the original post, so search queries which wouldn&#8217;t necessarily return either the post or the comment, end up returning the now-spammed post.  Typically they only need a couple of people to click on the link for it to be worthwhile, and unfortunately there are people who will do just that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gerald Steffens</title>
		<link>http://specht.com.au/michael/2006/01/27/spam-attack/comment-page-1/#comment-2629</link>
		<dc:creator>Gerald Steffens</dc:creator>
		<pubDate>Sat, 28 Jan 2006 14:23:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.specht.com.au/michael/2006/01/27/spam-attack/#comment-2629</guid>
		<description>yesterday the spam attack hit my weblog. it seems as if the idiot is sitting in the Ukraine. at least the attack is initiated by this server at netcasthost. here are the details:

% Information related to &#039;195.225.176.0 - 195.225.179.255&#039;

inetnum:      195.225.176.0 - 195.225.179.255
netname:      NETCATHOST
descr:        NetcatHosting
country:      UA
admin-c:      VS1142-RIPE
tech-c:       VS1142-RIPE
status:       ASSIGNED PI
mnt-by:       RIPE-NCC-HM-PI-MNT
mnt-lower:    RIPE-NCC-HM-PI-MNT
mnt-by:       NETCATHOST-MNT
mnt-routes:   NETCATHOST-MNT
source:       RIPE # Filtered
remarks:      ****************************************
remarks:      * Abuse contacts: abuse@netcathost.com *
remarks:      ****************************************

person:       Vsevolod Stetsinsky
address:      01110, Ukraine, Kiev, 20Á, Solomenskaya street. room 206.
phone:        +38 050 6226676
e-mail:       vs@netcathost.com
nic-hdl:      VS1142-RIPE
source:       RIPE # Filtered

% Information related to &#039;195.225.176.0/22AS31159&#039;

route:        195.225.176.0/22
descr:        NETCATHOST (full block)
origin:       AS31159
mnt-by:       NETCATHOST-MNT
remarks:      ****************************************
remarks:      * Abuse contacts: abuse@netcathost.com *
remarks:      ****************************************
source:       RIPE # Filtered

</description>
		<content:encoded><![CDATA[<p>yesterday the spam attack hit my weblog. it seems as if the idiot is sitting in the Ukraine. at least the attack is initiated by this server at netcasthost. here are the details:</p>
<p>% Information related to &#8216;195.225.176.0 &#8211; 195.225.179.255&#8242;</p>
<p>inetnum:      195.225.176.0 &#8211; 195.225.179.255<br />
netname:      NETCATHOST<br />
descr:        NetcatHosting<br />
country:      UA<br />
admin-c:      VS1142-RIPE<br />
tech-c:       VS1142-RIPE<br />
status:       ASSIGNED PI<br />
mnt-by:       RIPE-NCC-HM-PI-MNT<br />
mnt-lower:    RIPE-NCC-HM-PI-MNT<br />
mnt-by:       NETCATHOST-MNT<br />
mnt-routes:   NETCATHOST-MNT<br />
source:       RIPE # Filtered<br />
remarks:      ****************************************<br />
remarks:      * Abuse contacts: <a href="mailto:abuse@netcathost.com">abuse@netcathost.com</a> *<br />
remarks:      ****************************************</p>
<p>person:       Vsevolod Stetsinsky<br />
address:      01110, Ukraine, Kiev, 20Á, Solomenskaya street. room 206.<br />
phone:        +38 050 6226676<br />
e-mail:       <a href="mailto:vs@netcathost.com">vs@netcathost.com</a><br />
nic-hdl:      VS1142-RIPE<br />
source:       RIPE # Filtered</p>
<p>% Information related to &#8216;195.225.176.0/22AS31159&#8242;</p>
<p>route:        195.225.176.0/22<br />
descr:        NETCATHOST (full block)<br />
origin:       AS31159<br />
mnt-by:       NETCATHOST-MNT<br />
remarks:      ****************************************<br />
remarks:      * Abuse contacts: <a href="mailto:abuse@netcathost.com">abuse@netcathost.com</a> *<br />
remarks:      ****************************************<br />
source:       RIPE # Filtered</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Specht</title>
		<link>http://specht.com.au/michael/2006/01/27/spam-attack/comment-page-1/#comment-2628</link>
		<dc:creator>Michael Specht</dc:creator>
		<pubDate>Sat, 28 Jan 2006 10:31:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.specht.com.au/michael/2006/01/27/spam-attack/#comment-2628</guid>
		<description>I just banned him via .htaccess and now he is gone, gone, gone!

Damm frustrating, I wonder why they bother how much money can be generated via comment spam?</description>
		<content:encoded><![CDATA[<p>I just banned him via .htaccess and now he is gone, gone, gone!</p>
<p>Damm frustrating, I wonder why they bother how much money can be generated via comment spam?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeff</title>
		<link>http://specht.com.au/michael/2006/01/27/spam-attack/comment-page-1/#comment-2627</link>
		<dc:creator>Jeff</dc:creator>
		<pubDate>Sat, 28 Jan 2006 07:50:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.specht.com.au/michael/2006/01/27/spam-attack/#comment-2627</guid>
		<description>Same dipshit has been spamming me for 3 days now. (I found you through a google for the IP 195.225.177.80)

Grrrr...</description>
		<content:encoded><![CDATA[<p>Same dipshit has been spamming me for 3 days now. (I found you through a google for the IP 195.225.177.80)</p>
<p>Grrrr&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Specht</title>
		<link>http://specht.com.au/michael/2006/01/27/spam-attack/comment-page-1/#comment-2540</link>
		<dc:creator>Michael Specht</dc:creator>
		<pubDate>Fri, 27 Jan 2006 05:16:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.specht.com.au/michael/2006/01/27/spam-attack/#comment-2540</guid>
		<description>Yeah I will do that when I get home, and can access my .htaccess file. Thanks for the tip.</description>
		<content:encoded><![CDATA[<p>Yeah I will do that when I get home, and can access my .htaccess file. Thanks for the tip.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ed costello</title>
		<link>http://specht.com.au/michael/2006/01/27/spam-attack/comment-page-1/#comment-2539</link>
		<dc:creator>ed costello</dc:creator>
		<pubDate>Fri, 27 Jan 2006 04:23:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.specht.com.au/michael/2006/01/27/spam-attack/#comment-2539</guid>
		<description>You could add
   deny from 195.225.177.80 
to a .htaccess file either in your server root or your CGI-BIN directory.  This should block all connections from the attacker (alternately, use 195.225.177. leaving off the 80 so that you can trap the attack even if they change the IP).</description>
		<content:encoded><![CDATA[<p>You could add<br />
   deny from 195.225.177.80<br />
to a .htaccess file either in your server root or your CGI-BIN directory.  This should block all connections from the attacker (alternately, use 195.225.177. leaving off the 80 so that you can trap the attack even if they change the IP).</p>
]]></content:encoded>
	</item>
</channel>
</rss>
