<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule">
<channel>
    <title>JaBbA's Hut - SPAM</title>
    <link>http://jalcorn.net/weblog/</link>
    <description>White Hat Liberal Geek Dad</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.2.1 - http://www.s9y.org/</generator>
    <pubDate>Mon, 09 Oct 2006 15:15:04 GMT</pubDate>

    <image>
        <url>http://jalcorn.net/weblog/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: JaBbA's Hut - SPAM - White Hat Liberal Geek Dad</title>
        <link>http://jalcorn.net/weblog/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>Columbus Day SPAM Attack</title>
    <link>http://jalcorn.net/weblog/archives/1041-Columbus-Day-SPAM-Attack.html</link>
            <category>SPAM</category>
    
    <comments>http://jalcorn.net/weblog/archives/1041-Columbus-Day-SPAM-Attack.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=1041</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=1041</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    The last few months, the mailware writers have been taking advantage of the fact that even security people like to take their weekends off to blast the Internet with their latest and greatest creations.&lt;br /&gt;
&lt;br /&gt;
&lt;a class=&#039;serendipity_image_link&#039; href=&#039;http://jalcorn.net/weblog/uploads/spamgraph.png&#039;&gt;&lt;img width=&quot;110&quot; height=&quot;69&quot; border=&quot;0&quot; hspace=&quot;5&quot; align=&quot;left&quot; src=&quot;http://jalcorn.net/weblog/uploads/spamgraph.serendipityThumb.png&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;Apparently, the pump-and-dump SPAMmers have decided to use the same tactic, and thought maybe the Columbus day weekend might be a good time to do it.&lt;br /&gt;
&lt;br /&gt;
At work, my usual volume of SPAM on a Sunday is about 90,000 emails.  Here&#039;s my current graph.  That huge spike at the end - 204,000 email on Sunday.&lt;br /&gt;
&lt;br /&gt;
Where are they coming from?  Delivery failures.  We&#039;ve become the spoofed From: line for some spammer out there.  And &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2lzYy5zYW5zLm9yZy9kaWFyeS5waHA/c3RvcnlpZD0xNzY2&amp;amp;entry_id=1041&quot;  onmouseover=&quot;window.status=&#039;http://isc.sans.org/diary.php?storyid=1766&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;ISC Diary&quot;&gt;we&#039;re not the only ones&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
It&#039;s getting nasty out there.&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Mon, 09 Oct 2006 11:15:04 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/1041-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>how fast will they use it?</title>
    <link>http://jalcorn.net/weblog/archives/983-how-fast-will-they-use-it.html</link>
            <category>SPAM</category>
    
    <comments>http://jalcorn.net/weblog/archives/983-how-fast-will-they-use-it.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=983</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=983</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    &lt;a href=&#039;http://jalcorn.net/weblog/uploads/gawab.jpeg&#039;&gt;&lt;img width=&quot;110&quot; height=&quot;93&quot; border=&quot;0&quot; hspace=&quot;5&quot; align=&quot;left&quot; src=&quot;http://jalcorn.net/weblog/uploads/gawab.serendipityThumb.jpeg&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;I found a pump-and-dump spam in my folders that had an email address to stop being on their list.&lt;br /&gt;
&lt;br /&gt;
So I sent an email from a new address at 7:26pm to that address.&lt;br /&gt;
&lt;br /&gt;
Any bets on how fast they start spamming the new address?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Thu, 20 Apr 2006 19:25:56 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/983-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Spam King Busted</title>
    <link>http://jalcorn.net/weblog/archives/968-Spam-King-Busted.html</link>
            <category>SPAM</category>
    
    <comments>http://jalcorn.net/weblog/archives/968-Spam-King-Busted.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=968</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=968</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    &lt;div class=&quot;serendipity_imageComment_left&quot; style=&quot;width: 88px&quot;&gt;&lt;div class=&quot;serendipity_imageComment_img&quot;&gt;&lt;img width=&quot;88&quot; height=&quot;110&quot; border=&quot;0&quot; hspace=&quot;5&quot; align=&quot;left&quot; src=&quot;http://jalcorn.net/weblog/uploads/spamking.serendipityThumb.jpg&quot; alt=&quot;&quot;  /&gt;&lt;/div&gt;&lt;div class=&quot;serendipity_imageComment_txt&quot;&gt;Yeah, this is what a spammer looks like&lt;/div&gt;&lt;/div&gt;The Secret Service is &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5zcGFtZGFpbHluZXdzLmNvbS9wdWJsaXNoL1NwYW1fa2luZ19BZGFtX1ZpdGFsZV9idXN0ZWRfYnlfVVNfU2VjcmV0X1NlcnZpY2UuYXNw&amp;amp;entry_id=968&quot; title=&quot;http://www.spamdailynews.com/publish/Spam_king_Adam_Vitale_busted_by_US_Secret_Service.asp&quot;  onmouseover=&quot;window.status=&#039;http://www.spamdailynews.com/publish/Spam_king_Adam_Vitale_busted_by_US_Secret_Service.asp&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;on the case&lt;/a&gt;....&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt; Adam Vitale, aka Batch1 aka Baxter, 25, of Boynton Beach, FL, and his partner Todd Moeller, aka M3rk, of New Jersey, are accused of sending nearly 50,000 pieces of spam e-mail to more than 1.2 million AOL subscribers.&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
Yeah, 50,000 emails is nothing, but it&#039;s enough to put these scumbags behind bars.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Tue, 28 Feb 2006 16:37:01 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/968-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Referrer Spam Solution</title>
    <link>http://jalcorn.net/weblog/archives/928-Referrer-Spam-Solution.html</link>
            <category>S9y</category>
            <category>SPAM</category>
    
    <comments>http://jalcorn.net/weblog/archives/928-Referrer-Spam-Solution.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=928</wfw:comment>

    <slash:comments>5</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=928</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    The referrer SPAM has just gotten worse and worse.  I see thousands of hits on my blog from zombies with references to various {xanax|cialis|viagra|phentenermine}, casino and porn websites.&lt;br /&gt;
&lt;br /&gt;
I finally tooka  little time and put in a blocking mechanism which seems to effectively stop them at the door - it&#039;s going to be like a SPAM filter, in that I&#039;ll need to keep tweaking it, but so far so good.  If you need my solution, contact me. (I&#039;m obviously not going to publicly comment on my actual solution).&lt;br /&gt;
&lt;br /&gt;
But here&#039;s the somewhat scary part.  Many of the refererring domains are subdomains of names that seem completely unrelated.  That&#039;s not unusual - somehow I doubt that Jackie Zhao really runs a &quot;blackfilmmakermag.com&quot; website. (He doesn&#039;t.  It&#039;s a gambling advertising domain).  But at least one of them seems to be a legitimate site - did they sell access to their domain name, or has their DNS been hacked?&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;&lt;br /&gt;
Registrant:&lt;br /&gt;
   Mike Di Sabatino&lt;br /&gt;
   *** deleted ****&lt;br /&gt;
   Camarillo, CA 93011&lt;br /&gt;
   United States&lt;br /&gt;
&lt;br /&gt;
   Registrar: DOTSTER&lt;br /&gt;
   Domain Name: SUPERBIKECLUB.COM&lt;br /&gt;
      Created on: 15-MAR-00&lt;br /&gt;
      Expires on: 15-MAR-06&lt;br /&gt;
      Last Updated on: 13-MAR-05&lt;br /&gt;
&lt;br /&gt;
   Administrative Contact:&lt;br /&gt;
      DiSabatino, Michael  ******deleted*******&lt;br /&gt;
      **** deleted ******&lt;br /&gt;
      Camarillo, CA  93011&lt;br /&gt;
      US&lt;br /&gt;
      ****deleted****&lt;br /&gt;
      ****deleted****&lt;br /&gt;
&lt;br /&gt;
   Domain servers in listed order:&lt;br /&gt;
      NS1.SJ1.NORTHSKY.COM&lt;br /&gt;
      NS2.SJ1.NORTHSKY.COM&lt;br /&gt;
&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
Northsky.com, check your servers!  Michael, do you really want to be associated with buy-hydrocodone-online.superbikeclub.com ?????? 
    </content:encoded>

    <pubDate>Tue, 11 Oct 2005 12:12:36 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/928-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>German SPAM? Or Virus</title>
    <link>http://jalcorn.net/weblog/archives/884-German-SPAM-Or-Virus.html</link>
            <category>SPAM</category>
            <category>Viruses</category>
    
    <comments>http://jalcorn.net/weblog/archives/884-German-SPAM-Or-Virus.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=884</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=884</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Actually, a little of both.&lt;br /&gt;
&lt;br /&gt;
At some point, you&#039;ll get a German email today.  It will either be a short message with a link:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;Lese selbst:&lt;br /&gt;
http://www.npd.de/npd_info/deutschland/2005/d0405-39.html&lt;br /&gt;
&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
Or a long tract:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;In den fruehen Abendstunden des 13. Februar 1945 gegen 21:41 Uhr&lt;br /&gt;
heulten die Sirenen der Lazarettstadt Dresden das erste mal auf. Die Bewohner der Elbmetropole machten sich zu der Zeit noch keine Sorgen, da Dresden als Stadt ohne Bewaffnung und ohne militaerischen Nutzen bekannt war und von ca. 1,2 Millionen Frauen, Kindern und Greisen bewohnt wurde.&lt;br /&gt;
&lt;br /&gt;
Gegen 22:09 Uhr gab der Rundfunk durch, daÃ die alliierten Bomberverbaende ihren Kurs geaendert haben und nun auf Dresden zufliegen. Kurz darauf befanden sich 244 britische Bomber am Himmel der deutschen Kulturstadt. Drei Stunden nach dieser ersten Angriffswelle - es befanden sich bereits alle verfuegbaren Rettungsmannschaften, Sanitaeter und Feuerwehmaenner in Dresden - verdunkelten weitere 500 Bomber den Himmel.&lt;br /&gt;
Am naechsten Tag folgte die letzte Angriffswelle mit erneut 300 US-B-17-Bombern. Zwischen 12:12 Uhr und 12:21 Uhr warfen diese 783 Tonnen Bomben ab. - Das entspricht mehr als 85 Tonnen pro Minute. Nach dem Abwerfen setzten die US-Bomber zum Tiefflug an und beschossen Fluechtende mit ihren Bordwaffen. In diesen drei Angriffsschlaegen, die insgesamt 14 Stunden andauerten, warfen die &quot;Befreier&quot; 650.000 Brandbomben und 200.000 Sprengbomben ab, welche einen Feuersturm von ueber 1000 Grad in der Stadt erzeugten. Obwohl Dresden weder Flugabwehr, noch Ruestungsindustrie oder aehnliche kriegswichtige Ziele besass wurden weit mehr als 350.000 unschuldige deutsche Zivilisten in diesen zwei Tagen kaltbluetig ermordet.&lt;br /&gt;
&lt;br /&gt;
Keiner der schuldigen Alliierten wurde jemals fuer dieses brutale Kriegsverbrechen auch nur angeklagt und die Massenmedien und die bundesdeutsche Regierung schweigen diese Taten tot und sehen es nicht als noetig an den Opfern zu gedenken.!&lt;br /&gt;
&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
It&#039;s an artifact of the Sober-Q Virus.  Apparently, the virus targets European users with copies of itself, but targets the whole world with a political message related to the anniversary of the end of WWII and upcoming elections.&lt;br /&gt;
&lt;br /&gt;
Don&#039;t trust the fact that US users seem to get only email.  Delete the German emails immediately, in case it morphs to sending malware to everyone.&lt;br /&gt;
&lt;br /&gt;
More info at &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2lzYy5zYW5zLm9yZy9kaWFyeS5waHA/ZGF0ZT0yMDA1LTA1LTE1&amp;amp;entry_id=884&quot; title=&quot;http://isc.sans.org/diary.php?date=2005-05-15&quot;  onmouseover=&quot;window.status=&#039;http://isc.sans.org/diary.php?date=2005-05-15&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;SANS&lt;/a&gt; 
    </content:encoded>

    <pubDate>Mon, 16 May 2005 12:26:24 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/884-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>They're still trying</title>
    <link>http://jalcorn.net/weblog/archives/542-Theyre-still-trying.html</link>
            <category>S9y</category>
            <category>SPAM</category>
    
    <comments>http://jalcorn.net/weblog/archives/542-Theyre-still-trying.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=542</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=542</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    The Trackback SPAMmers are still trying.  After their blast didn&#039;t work, they tried a trickle this morning - just one attempt every few minutes.  Still didn&#039;t work, trackback moderation is on.&lt;br /&gt;
&lt;br /&gt;
So just a couple minutes ago, I get the following moderation message:&lt;br /&gt;
&lt;div class=&quot;code&quot;&gt;A new comment has been posted on your blog &quot;JaBbA&#039;s Rants&quot;, in the entry entitled &quot;What the meaning of.....is&quot;.&lt;br /&gt;
Link to entry: http://jalcorn.net/politics/archives/2-What-the-meaning-of.....is.html&lt;br /&gt;
&lt;br /&gt;
Requires review: Yes (Auto-moderation after X days)&lt;br /&gt;
User IP-address: 66.171.183.222&lt;br /&gt;
User Name: texas holdem&lt;br /&gt;
User Email: umuwb@ae65cf3638579985c6c77e30b1e722abb.com&lt;br /&gt;
User website: http://www.tigerspice.com&lt;br /&gt;
&lt;br /&gt;
Comments: &lt;br /&gt;
Vertigo is anguish to the extent that I am afraid not of falling over the precipice, but of throwing myself over. by online poker&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
I dunno - were they thinking that if they hid the poker reference in a random sentence I&#039;d allow the trackback?&lt;br /&gt;
&lt;br /&gt;
Serendipity is wonderful.   
    </content:encoded>

    <pubDate>Fri, 04 Feb 2005 17:03:41 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/542-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Unintended Consequences</title>
    <link>http://jalcorn.net/weblog/archives/541-Unintended-Consequences.html</link>
            <category>SPAM</category>
    
    <comments>http://jalcorn.net/weblog/archives/541-Unintended-Consequences.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=541</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=541</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    I came across a SPAM blocking issue today that could be about to make life very difficult for spam fighters.&lt;br /&gt;
&lt;br /&gt;
At this time, the SPAMmers seem to be ahead in the war against CipherTrust&#039;s IronMail appliance.  It still blocks over 80% of the incoming SPAM, but hundreds of SPAMs are getting through, achieving SPAM scores similar to &#039;ham&#039; email.  I&#039;ve had to lower my threshold for hand-administration of incoming email, increasing the workload at least 3x what it was before, because of all the SPAM complaints.&lt;br /&gt;
&lt;br /&gt;
One of my strategies for mitigating this was to have an email address where users could forward any received SPAM. (We use Lotus Notes, so the automated reporting tools built into the appliance don&#039;t work, because Notes destroys the header information.  There&#039;s many good things about Notes  - SMTP mail handling is probably the biggest Bad Thing (tm)).  I take emails sent to this mailbox, export them as text and run them through a perl script with parses out all the URLs, then insert those domains as SPAM.  Any email coming in subsequently with those domains gets a +100, guaranteeing that it will get dropped as SPAM.  It&#039;s been somewhat effective, although the SPAMmers are changing domains constantly, but I&#039;m stopping an average of 1000+ more emails per day with this strategy.&lt;br /&gt;
&lt;br /&gt;
But today, I got a shock.  tinyurl.com appeared in my list. &lt;br /&gt;
&lt;br /&gt;
For those of you that don&#039;t know, tinyurl.com is one of the most useful tools on the net - take one of those monster URLs that get munged by email clients, feed it to tinyurl, and you get a URL easily sent via email.&lt;br /&gt;
&lt;br /&gt;
But now it&#039;s being abused by SPAMmers.  I&#039;m not blocking the domain yet, but I&#039;ll have to keep an eye on this development.  &lt;br /&gt;
&lt;br /&gt;
TinyURL needs to put in a &#039;captcha&#039; to stop automated use of their tool.  It will make it slightly less convenient, but it might just be enough to stop the spammers, whose high volume of data will make it less useful to get URLs by hand.&lt;br /&gt;
&lt;br /&gt;
Are you listening, TinyURL? 
    </content:encoded>

    <pubDate>Wed, 02 Feb 2005 11:57:14 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/541-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>S9y 0.8 Effectively stopped a SPAM attack</title>
    <link>http://jalcorn.net/weblog/archives/540-S9y-0.8-Effectively-stopped-a-SPAM-attack.html</link>
            <category>S9y</category>
            <category>SPAM</category>
    
    <comments>http://jalcorn.net/weblog/archives/540-S9y-0.8-Effectively-stopped-a-SPAM-attack.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=540</wfw:comment>

    <slash:comments>1</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=540</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    &lt;div class=&quot;serendipity_imageComment_left&quot; style=&quot;width: 110px&quot;&gt;&lt;div class=&quot;serendipity_imageComment_img&quot;&gt;&lt;a href=&#039;http://jalcorn.net/weblog/uploads/trackbackspam.png&#039;&gt;&lt;img width=&quot;110&quot; height=&quot;84&quot; border=&quot;0&quot; hspace=&quot;5&quot; align=&quot;left&quot; src=&quot;http://jalcorn.net/weblog/uploads/trackbackspam.serendipityThumb.png&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;serendipity_imageComment_txt&quot;&gt;S9y&#039;s comment administration&lt;/div&gt;&lt;/div&gt;This morning I woke up to more than 100 messages from my blog that trackbacks had been created.  And the developers list confirmed - all the blogs had been hit by the same spammer.&lt;br /&gt;
&lt;br /&gt;
A Spammer had figured out the Trackback API, and an online casino had paid to be advertised.&lt;br /&gt;
&lt;br /&gt;
The good news? We use &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5zOXkub3JnLw==&amp;amp;entry_id=540&quot; title=&quot;http://www.s9y.org/&quot;  onmouseover=&quot;window.status=&#039;http://www.s9y.org/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Serendipity&lt;/a&gt;.  And the spammer is going to have to refund the casino&#039;s money.&lt;br /&gt;
&lt;br /&gt;
Not a single trackback actually appeared on my blog.  It took me about 4 minutes to go through and delete all the trackbacks using the backend administration, and another minute to delete all the emails.&lt;br /&gt;
&lt;br /&gt;
There&#039;s a lot of talk about how to solve this.  My feeling, though, is that they didn&#039;t get any advertisement.  It took just a couple minutes - and I have some idea for some small interface tweaks that could make cleaning up after this even faster.  So right now, I&#039;m happy with the solution in place.&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2Jsb2cua29laG50b3BwLmRlL2FyY2hpdmVzLzY2OC1UcmFja2JhY2stU3BhbS5odG1s&amp;amp;entry_id=540&quot; title=&quot;http://blog.koehntopp.de/archives/668-Trackback-Spam.html&quot;  onmouseover=&quot;window.status=&#039;http://blog.koehntopp.de/archives/668-Trackback-Spam.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Kristian&lt;/a&gt;, &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5yZWRzcGxhc2guZGUvYmxvZy9hcmNoaXZlcy80MzItVHJhY2tiYWNrLVNwYW0uaHRtbA==&amp;amp;entry_id=540&quot; title=&quot;http://www.redsplash.de/blog/archives/432-Trackback-Spam.html&quot;  onmouseover=&quot;window.status=&#039;http://www.redsplash.de/blog/archives/432-Trackback-Spam.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Christian&lt;/a&gt;, &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5zZWJhc3RpYW4tYmVyZ21hbm4uZGUvYmxvZy9hcmNoaXZlcy80NTYtVHJhY2tiYWNrLVNwYW0uaHRtbA==&amp;amp;entry_id=540&quot; title=&quot;http://www.sebastian-bergmann.de/blog/archives/456-Trackback-Spam.html&quot;  onmouseover=&quot;window.status=&#039;http://www.sebastian-bergmann.de/blog/archives/456-Trackback-Spam.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Sebastian&lt;/a&gt; and &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2Jsb2cuZHJlYW1jb2Rlci5kay9hcmNoaXZlcy8yODktVHJhY2tiYWNrLXNwYW0taGl0cy5odG1s&amp;amp;entry_id=540&quot; title=&quot;http://blog.dreamcoder.dk/archives/289-Trackback-spam-hits.html&quot;  onmouseover=&quot;window.status=&#039;http://blog.dreamcoder.dk/archives/289-Trackback-spam-hits.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Tom&lt;/a&gt; also blogged about this, and Kristian implemented a patch that would stop at least the most common of these. 
    </content:encoded>

    <pubDate>Tue, 01 Feb 2005 10:12:33 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/540-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>SPF Update: Beware...</title>
    <link>http://jalcorn.net/weblog/archives/506-SPF-Update-Beware....html</link>
            <category>Geek</category>
            <category>SPAM</category>
    
    <comments>http://jalcorn.net/weblog/archives/506-SPF-Update-Beware....html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=506</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=506</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Well, I&#039;ve been having just tons of SPF fun.&lt;br /&gt;
&lt;br /&gt;
Some is good:&lt;br /&gt;
&lt;br /&gt;
&lt;div class=code&gt;Nov 30 22:28:53 bigfoot postfix/smtpd[20736]: NOQUEUE: reject: RCPT from c-24-16-134-128.client.comcast.net[24.16.134.128]: 554 &amp;lt;spamcatcher@jalcorn.net&amp;gt;: Recipient address rejected: Please see http://spf.pobox.com/why.html? sender=spamcatcher%40jalcorn.net&amp;ip=24.16.134.128&amp;receiver=bigfoot; from=&amp;lt;spamcatcher@jalcorn.net&amp;gt; to=&amp;lt;spamcatcher@jalcorn.net&amp;gt; proto=SMTP helo=&amp;lt;c-24-16-134-128.client.comcast.net&amp;gt;&amp;lt;/code&amp;gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
No, I didn&#039;t send that.  It&#039;s SPAM, and it would have made it through the SPAM filters without SPF.  Excellent!&lt;br /&gt;
&lt;br /&gt;
Some is indifferent:&lt;br /&gt;
&lt;br /&gt;
&lt;div class=code&gt;Nov 30 18:05:03 bigfoot postfix/smtpd[18180]: NOQUEUE: reject: RCPT from lale.tr.net[195.155.1.6]: 554 &amp;lt;spamcatcher@jalcorn.net&amp;gt;: Recipient address rejected: Please see http://spf.pobox.com/why.html? sender=r.jarvispx%40azzit.de&amp;ip=195.155.1.6&amp;receiver=bigfoot; from=&amp;lt;r.jarvispx@azzit.de&amp;gt; to=&amp;lt;spamcatcher@jalcorn.net&amp;gt; proto=ESMTP helo=&amp;lt;lale.trnet.com&amp;gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
trnet.com is my old domain, and the Turkish ISP that bought it from me is forwarding my old address to me.  I only get SPAM from it now, but I probably shouldn&#039;t be rejecting it. Lesson learned: make sure you know where ALL your valid forwarders are, not just your relayers.&lt;br /&gt;
&lt;br /&gt;
Some is bad:&lt;br /&gt;
&lt;br /&gt;
&lt;div class=code&gt;Dec  1 07:24:27 bigfoot postfix/smtpd[26770]: NOQUEUE: reject: RCPT from mta13.adelphia.net[68.168.78.44]: 554 &amp;lt;spamcatcher@groovysecurity.com&amp;gt;: Recipient address rejected: Please see http://spf.pobox.com/why.html? sender=spamcatcher%40jalcorn.net&amp;ip=68.168.78.44&amp;receiver=bigfoot; from=&amp;lt;spamcatcher@jalcorn.net&amp;gt; to=&amp;lt;spamcatcher@groovysecurity.com&amp;gt; proto=ESMTP helo=&amp;lt;mta13.adelphia.net&amp;gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
This is me trying to send to someone else on my own mail server.  the entries a:mail.adelphia.net and mx:adelphia.net don&#039;t work, because adelphia uses many different servers for OUTBOUND email but they&#039;re not on the mx list.  I tried include:adelphia.net but the results are inconclusive - luckily, adelphia DOES publish the following SPF record:&lt;br /&gt;
&lt;br /&gt;
&lt;div class=code&gt;adelphia.net.           3600    IN      TXT     &quot;v=spf1 mx ip4:68.168.78.0/24 -all&quot;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
so this should work.   
    </content:encoded>

    <pubDate>Wed, 01 Dec 2004 09:31:32 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/506-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Finally, SPF</title>
    <link>http://jalcorn.net/weblog/archives/504-Finally,-SPF.html</link>
            <category>Geek</category>
            <category>SPAM</category>
    
    <comments>http://jalcorn.net/weblog/archives/504-Finally,-SPF.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=504</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=504</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Well, it took a little doing, but I finally have my mail server implementing a SPF rejection policy.  No more SPAM from myself!  When someone other than me sends a email from my domain, this is what happens:&lt;br /&gt;
&lt;br /&gt;
&lt;div class=code&gt; Nov 30 16:41:06 bigfoot postfix/smtpd[17058]: NOQUEUE: reject: RCPT from notescom.lincolnelectric.com[99.99.99.99]: 554 &amp;lt;spamcatcher@jalcorn.net&amp;gt;: Recipient address rejected: Please see http://spf.pobox.com/why.html?sender = spamcatcher%40jalcorn.net&amp;ip=99.99.99.99&amp;receiver=bigfoot; from=&amp;lt;spamcatcher@jalcorn.net&amp;gt; to=&amp;lt;spamcatcher@jalcorn.net&amp;gt; proto=SMTP helo=&amp;lt;safemail.com&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;br /&gt;
and the sender gets DENIED:&lt;br /&gt;
&lt;a href=&#039;http://jalcorn.net/weblog/uploads/spfreject.png&#039;&gt;&lt;img width=&quot;500&quot; height=&quot;140&quot; border=&quot;0&quot; hspace=&quot;5&quot; align=&quot;left&quot; src=&quot;http://jalcorn.net/weblog/uploads/spfreject.png&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
My setup is in the extended entry....&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;&lt;a href=&quot;http://jalcorn.net/weblog/archives/504-Finally,-SPF.html#extended&quot;&gt;Continue reading &quot;Finally, SPF&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Tue, 30 Nov 2004 16:48:56 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/504-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>MS license is killing Anti-Spam</title>
    <link>http://jalcorn.net/weblog/archives/443-MS-license-is-killing-Anti-Spam.html</link>
            <category>SPAM</category>
    
    <comments>http://jalcorn.net/weblog/archives/443-MS-license-is-killing-Anti-Spam.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=443</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=443</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Apache has &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL25ld3MubmV0Y3JhZnQuY29tL2FyY2hpdmVzLzIwMDQvMDkvMDIvYXBhY2hlX3JlamVjdHNfc2VuZGVyX2lkX3Byb3Bvc2FsLmh0bWw=&amp;amp;entry_id=443&quot; title=&quot;http://news.netcraft.com/archives/2004/09/02/apache_rejects_sender_id_proposal.html&quot;  onmouseover=&quot;window.status=&#039;http://news.netcraft.com/archives/2004/09/02/apache_rejects_sender_id_proposal.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;rejected Sender ID&lt;/a&gt; because Microsoft&#039;s License on the technology that they injected into it would stop Open Source implementations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Wed, 08 Sep 2004 14:44:30 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/443-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>ARG</title>
    <link>http://jalcorn.net/weblog/archives/439-ARG.html</link>
            <category>S9y</category>
            <category>SPAM</category>
    
    <comments>http://jalcorn.net/weblog/archives/439-ARG.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=439</wfw:comment>

    <slash:comments>1</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=439</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    I just got hit with Blog SPAM.&lt;br /&gt;
&lt;br /&gt;
Not just a couple.  TWO HUNDERED comments about 2am today.  Luckily, the CVS version of S9y I&#039;m using allows me to moderate comments, so I&#039;m turning that on.&lt;br /&gt;
&lt;br /&gt;
Damn fake drug vendors.  Scourge of the earth, I tell you. 
    </content:encoded>

    <pubDate>Fri, 03 Sep 2004 08:35:20 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/439-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Operation Slam Spam</title>
    <link>http://jalcorn.net/weblog/archives/430-Operation-Slam-Spam.html</link>
            <category>SPAM</category>
    
    <comments>http://jalcorn.net/weblog/archives/430-Operation-Slam-Spam.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=430</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=430</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    The Justice Department is announcing &quot;&lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy51c2F0b2RheS5jb20vdGVjaC9uZXdzL3RlY2hwb2xpY3kvMjAwNC0wOC0yNS1zcGFtLWNyYWNrZG93bl94Lmh0bQ==&amp;amp;entry_id=430&quot; title=&quot;http://www.usatoday.com/tech/news/techpolicy/2004-08-25-spam-crackdown_x.htm&quot;  onmouseover=&quot;window.status=&#039;http://www.usatoday.com/tech/news/techpolicy/2004-08-25-spam-crackdown_x.htm&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Operation Slam Spam&lt;/a&gt;&quot;, a yearlong effort to arrest and prosecute Spammers, Phishers and other online cons.  Apparently, stings have been set up to identify the people involved and gather the proof, and the arrests are coming soon.&lt;br /&gt;
&lt;br /&gt;
Here&#039;s hoping, although they haven&#039;t shown any ability to follow up on this kind of stuff so far. 
    </content:encoded>

    <pubDate>Thu, 26 Aug 2004 08:49:58 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/430-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>SPF, coming soon</title>
    <link>http://jalcorn.net/weblog/archives/418-SPF,-coming-soon.html</link>
            <category>SPAM</category>
    
    <comments>http://jalcorn.net/weblog/archives/418-SPF,-coming-soon.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=418</wfw:comment>

    <slash:comments>1</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=418</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    There&#039;s a good article on the current state of SPAM over at &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL25ld3MubmV0Y3JhZnQuY29tL2FyY2hpdmVzLzIwMDQvMDgvMDUvZ29vZGJ5ZV9zcGFtX2J1dF9hdF93aGF0X3ByaWNlLmh0bWw=&amp;amp;entry_id=418&quot; title=&quot;http://news.netcraft.com/archives/2004/08/05/goodbye_spam_but_at_what_price.html&quot;  onmouseover=&quot;window.status=&#039;http://news.netcraft.com/archives/2004/08/05/goodbye_spam_but_at_what_price.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt; Netcraft&lt;/a&gt;.  SPF, as outlined in the article, looks very promising (I&#039;ll be setting it up both at home and at work) but I doubt that it will reach critical mass any time soon.  Unfortuntely, but not unexpected, Microsoft has a &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5pZXRmLm9yZy9pbnRlcm5ldC1kcmFmdHMvZHJhZnQtYXRraW5zb24tY2FsbGVyaWQtMDAudHh0&amp;amp;entry_id=418&quot; title=&quot;http://www.ietf.org/internet-drafts/draft-atkinson-callerid-00.txt&quot;  onmouseover=&quot;window.status=&#039;http://www.ietf.org/internet-drafts/draft-atkinson-callerid-00.txt&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;different idea&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
The ideas have supposedly been combined as &quot;&lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5taWNyb3NvZnQuY29tL21zY29ycC90d2MvcHJpdmFjeS9zcGFtX3NlbmRlcmlkLm1zcHg=&amp;amp;entry_id=418&quot; title=&quot;http://www.microsoft.com/mscorp/twc/privacy/spam_senderid.mspx&quot;  onmouseover=&quot;window.status=&#039;http://www.microsoft.com/mscorp/twc/privacy/spam_senderid.mspx&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Sender ID&lt;/a&gt;&quot;, but there&#039;s a big difference between SPF and Sender ID - Sender ID is encumbered by a Microsoft license. 
    </content:encoded>

    <pubDate>Mon, 09 Aug 2004 10:48:39 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/418-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>I come not to bury Caesar, but to praise him</title>
    <link>http://jalcorn.net/weblog/archives/411-I-come-not-to-bury-Caesar,-but-to-praise-him.html</link>
            <category>SPAM</category>
    
    <comments>http://jalcorn.net/weblog/archives/411-I-come-not-to-bury-Caesar,-but-to-praise-him.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=411</wfw:comment>

    <slash:comments>1</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=411</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    OK, I don&#039;t have much good to say about Microsoft, but they did &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5ud2Z1c2lvbi5jb20vbmV3cy8yMDA0LzA3MTVtaWNyb3dpbnMuaHRtbD9mc3JjPXJzcy1zZWN1cml0eQ==&amp;amp;entry_id=411&quot; title=&quot;http://www.nwfusion.com/news/2004/0715microwins.html?fsrc=rss-security&quot;  onmouseover=&quot;window.status=&#039;http://www.nwfusion.com/news/2004/0715microwins.html?fsrc=rss-security&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;nail a SPAMmer for $4M&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
A drop in the bucket - and the SPAMmer wasn&#039;t one of the big ones.  But it&#039;s a start.&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Fri, 16 Jul 2004 09:43:42 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/411-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>

</channel>
</rss>