February 4 th

42

Spammers use Top Commentators vulnerability to hijack top list

Posted by Andy Bailey
2,380 views

Your comments or your life!

Many thanks to Scott from UK MAC.net (a great UK site for Apple Mac’s) for sending me an email about this. He noticed that his name was number 1 on the Top Commentators list on the sidebar but, his name linked to an obvious spam site.

I checked further and two other people had been hijacked, Dearest Pelf and Roger(who ironically, was on the list from his comments about spam comments).

It seems that the Top Commentators plugin remembers the last URL used for a commentator and displays that as an anchor for their name,(it used to use the most used url, don’t know why they changed it) even after deleting and spaminating the spammers url and ip into the blacklist they still showed on the displayed list so I have decided to remove the Top Commentators plugin for now.

I noticed something was up the other day when I received a comment from WitchyPoo but it didn’t look like her normal way of writing and it didn’t have a last blog post (from CommentLuv), the comment made mention of something in the post and the spammer came back to respond to my follow up comment. I just changed the url back to Witchypoos’ site and thought nothing of it.

I have even noticed certain spammers now following links on to other peoples blogs from here and doing the same thing to others.

Be aware of this, look out for comments coming from your regular commentators and make sure they have the correct url or install CommentLuv and look out for comments without a last blog post.

Popularity: 11% [?]

Category : Blog News

Related Posts

  • New CommentLuv Directory Register Today
  • My life in (other peoples) pictures
  • The Wordpress Plugins that I wouldn’t leave behind
  • Excel tip: How to not show zero values for forumla result
  • Stumbled - Stumbleupon Widget for Wordpress 2.2
  • The love/hate relationship I have with coding..
  • FiddyP Contest - Who Wins?

  • Comments

    Opal Tribble - Vegan Momma (35 comments.) February 4, 2008

    I noticed this last year (summertime.) It was before I used that plugin; however, spammers were using names of some of my readers when they commented. It didn’t work. I get emails for every single comment that lands on my website. I delete those that don’t match up.

    Opal Tribble - Vegan Momma’s last blog post..Fun Art For Daughter, Nightmare For Mommy

    Andy Bailey February 4, 2008

    I get over 100 emails a day so it’s hard for me to manually moderate each comment that comes here so I guess I’ll have to keep a sharp eye out!

    Scott (12 comments.) February 4, 2008

    Cool… So I was right then…

    Clever buggers these spammers eh ?

    Scott’s last blog post..Win A Set Of iMaingo iPod Speakers

    Andy Bailey February 4, 2008

    not clever just bloody sneaky!
    thanks for pointing it out!

    roger (7 comments.) February 4, 2008

    uh… wot… no i wasn’t asleep, i was diving :) something happened? ah ok you fixed it, nice, don’t put a top commentator’s list you might get Alan Johnson posting :) Night!

    roger’s last blog post..Get your PADI: Open Water Courses in Hurghada, Join the Underwater Fun for the First Time

    witchypoo (43 comments.) February 4, 2008

    I bow down to your greater wisdom. Top commenters was never a plugin I wanted to use, because of the sidebar real estate issues.

    witchypoo’s last blog post..Knudsen Award for 2008 and a shop

    Andy Bailey February 4, 2008

    roger: lol, isn’t Alan Johnson the UK health secretary? happy sleeping!
    witchypoo: I wanted a way to reward commentators before I implemented CommentLuv, I put some lotto results on the sidebar now instead and moved a couple of things about. now i have to think about what I’m going to put in the bottom bar. I don’t think many people go that far down page so I’ll have a thunk about it.. glad it was the ‘real’ you coming to visit this time!

    Stephan Miller (5 comments.) February 4, 2008

    Yes, I have noticed this. A the first few days on the month is a really heavy time for these spammers. That’s when some site’s top commenters resets.

    Stephan Miller’s last blog post..Nice Little Traffic Update

    Andy Bailey February 4, 2008

    Stephan: how strange, I was just searching for “Stephan Miller blog” and you appear right here! Looking back, I now realize that the beginning of each month has seen spam attempts go right up. SpamKarma2 is able to catch most of them without sending them to moderation, my stats show over 50,000 hits to the post-comment php file for this week already!

    thanks for visiting!

    Stephan Miller (5 comments.) February 4, 2008

    How does this compare to Akismet? I have that now. Is it a replacement or do they work hand in hand?

    Stephan Miller’s last blog post..Nice Little Traffic Update

    Andy Bailey February 4, 2008

    I think they don’t play well together. I’ve only ever used spamkarma2 and I’ve always been happy with it’s performance. Especially since it once caught 2000 spam in a night and only put 3 into moderation, the rest went straight in the bin.

    I’m working on a simple addition to the comment form to foil the autobots but that’s low on the list of the squillion other things I will get to after my latest commercial project.

    Opal Tribble - Vegan Momma (35 comments.) February 4, 2008

    @Andy,

    I get a high amount also at least 300 emails daily. I’ve written about the high volume I receive a few times on my website. Actually I thought the numbers would decrease when I left the corporate setting. In the coporate setting I averaged 150 per day. however it got worse. I learned years ago to just deal with the high volume. Most of my emails are legitmiate email and its usually related to my offline or online my business. I also get solicitors, or people asking me questions about one of my websites.

    Opal Tribble - Vegan Momma’s last blog post..Fun Art For Daughter, Nightmare For Mommy

    clairec23 (3 comments.) February 5, 2008

    None of the top commentator widgets work on my blog so I’ve using the community cloud one instead and it has occurred to me that could happen because I’ve noticed that uses the last url too. If people use the same name, it’s going to get confusing. At some stage I’ll have to take it down too :(
    clairec23’s last blog post..Contest Update

    Bobby Revell (34 comments.) February 5, 2008

    I have the e-mail for moderated comments turned off so I checked all comments in my WP panel, I had to cut down on all e-mail. I have several different e-mail addresses to divide them into categories.

    I have over 5000 normal comments (not spam) I never approved for reasons beyond the scope of this discussion…haha!

    Bobby Revell’s last blog post..Bobby’s Batch #5 - Smart Icy Cool

    Andy Bailey February 5, 2008

    Opal: It’s amazing that you find the time to home-school! I used to get up to 500 emails a day until I turned my catchall off. Unfortunately, almost all the emails I get require a response and it takes literally hours to get through them all and I miss quite a few from friends because I’m too swamped with biz emails.

    Claire: I might make a plugin to do a top commentators but have everything on the dashboard in the admin side and you get to choose who goes on there.. hmm, another one for the list!

    bobby: wow, I see you do get a lot of comments on revellian.com. I see you also manage to replay to every single one too. I have to wait until I get to someone with internet before I can catchup and many times, I end up doing responses when I should be doing paid work!

    roger (7 comments.) February 5, 2008

    you know even after sending out 3000 emails 4 day’s ago nobody has commented on my site :) so i really would be happy for some SPAM :) anyone care to help out a baby blogger i have a wpremix giveaway in exchange for some pr:)

    ps Andy I ‘JUST’ got what fiddyp is :) duh!

    roger’s last blog post..Get your PADI: Open Water Courses in Hurghada, Join the Underwater Fun for the First Time

    Andy Bailey February 5, 2008

    oh dear Roger! You have a great looking site! I think the fact that people have to register to comment will seriously impact your comment count. It’s a real process to register to make a comment on a post on any blog, even when I have something good to add to a post I find it doesn’t happen when I have to go through the whole process of registering. There are lots of blogs I regularly visit that don’t require registration and it’s almost always these ones that I comment on instead…

    Also, I like the idea of doing a PADI course but, where? Hurghada sounds like a nice place but in what country?? maybe a small outline of your countries’ map in your header would make it obvious to the casual observer where you are located..

    just a suggestion, I’m no expert!

    roger (7 comments.) February 5, 2008

    you know i didn’t even know that was set as must be logged in to register, it’s changed now! Thank you for pointing out this glaring oversight!!!!!

    Hurghada is in Egypt but i take your point and will change something!

    roger’s last blog post..Get your PADI: Open Water Courses in Hurghada, Join the Underwater Fun for the First Time

    Opal Tribble - Vegan Momma (35 comments.) February 5, 2008

    Opal: It’s amazing that you find the time to home-school! I used to get up to 500 emails a day until I turned my catchall off. Unfortunately, almost all the emails I get require a response and it takes literally hours to get through them all and I miss quite a few from friends because I’m too swamped with biz emails.

    Homeschooling is great because we don’t have a set time to work. However, most of it is done in the morning, afternoon, and about an hour before bedtime.

    Yes, most of my emails require a response. In the corporate setting all my emails required a response. I don’t even want to tell you how many emails greeted me when I came back from four months maternity leave. My boss emails topped mine. She was very efficient. She received between 200 - 300 emails daily. She managed to respond to most of them and still get her work completed. Yes, she actually worked. ;-) I thought that was amazing. She had that system down.

    The emails that can wait I put them in a folder titled “respond later.” However, I usually try to send a quick note to let them know that I got the email and will get back to them. I’m alerted as soon as an email hits my inbox. At least four times, daily I take a break and respond to my emails. I receive a high amount of emails from readers regarding various topics I’ve written about. Some of them have turned into clients.

    Can it be done? I think it can however finding a system that works for you can be challenging. It took me several months before I got my process under control.

    Opal Tribble - Vegan Momma’s last blog post..Fun Art For Daughter, Nightmare For Mommy

    Andy Bailey February 5, 2008

    roger: ahh, I guess that it doesn’t say that for you every time you see your own site because you are logged in already. I’ll see if I have time to do a website review next week for you and pass on some PR your way…

    Opal: I could learn something from you! I definitely need to process my emails in a procedural fashion like you do. I do try and organize them into separate folders automatically but that just makes me lose them after they have lost their unread status!

    roger (7 comments.) February 5, 2008

    So changed the log in for comment’s and added a little map at the top so hopefully it’s clear it’s Egypt now :) most people arrive by search engine anyway looking for ‘diving red sea’ or such like so they usually know where we are.

    A review would be fantastic!

    If anyone has any SEO advice also some SEO tool’s say it should be easy to get ranking for the diving keyword’s but I’m struggling, any opinion’s on link’s from directory’s? One of the biggest problem’s I have is that I was getting good result’s from google.com but .nl, .de and .co.uk which are my target market’s are not good, i tried changing geographic location but you can only specify one!?

    Sorry Andy turning your thread into a bit of a forum….

    roger’s last blog post..Get your PADI: Open Water Courses in Hurghada, Join the Underwater Fun for the First Time

    Andy Bailey February 5, 2008

    roger: nicely done! immediately obvious where your service is provided now. My advice for SEO (I’m in no ways an expert - or even amateur!) would be to get into as many blog directories as possible.

    I regularly got listed in multiple positions on the first page of google for some keywords on my old blog which helps knock off the competition so try and register your site using your most wanted keywords and phrases.

    You could also have a script to show excerpts of headlines to do with your keywords and phrases and show them somewhere on your sidebar or blog. This is something I did with a lottery site I made for someone and it seemed to work really well because there was a constant supply of up to date and new news containing lottery keywords which helped traffic to the site from search engine queries for the keywords I used. (up to 500 search engine referrals on some nights for it!)

    Let me know two of your most wanted keywords and phrases and I’ll see if I can knock something up to add to your site to do that very thing.

    forum? hmm now there’s an idea! they’re a bit hard work to maintain though and there’s always trolls that ruin things. Happy to answer in the comments though or maybe I can make a page just for questions and keep a FAQ of the most asked ones.

    roger (7 comments.) February 5, 2008

    The base keyword’s I suppose would be English - ‘diving hurghada’ Dutch - ‘duiken hurghada’ and German - ‘tauchen hurghada’,I think the main problem would be that no other person seems to be using RSS in the diving field and if they did then they are a competitor :) or did you mean something else? If you mean taking headlines from a site (i have no clue even how to start this) then sites would be English ‘divernet dot com’ Dutch (dont know will have to check) and German ‘taucher dot net’

    I played around with bbpress for a bit and it was quite good but if you put it on the site I suppose it would be alot of work to keep the spammer’s away!

    Makes me think of a real estate forum i participated in (for a few day’s) where the moderator’s where moderating the comment’s from people because they owned real estate businesses and cut anybody else out who wanted to promote themselves or help people, the sad thing is that the majority of ‘guests’ hadnt a clue! I got accused of mutiny when i tried to voice my opinion of this moderation!

    Sorry off on a tangent there!

    ps get yourself to Hurghada and I’ll give you some free diving, your a star for this help! :)
    roger’s last blog post..Get your PADI: Open Water Courses in Hurghada, Join the Underwater Fun for the First Time

    Stephan Miller (5 comments.) February 5, 2008

    I had a suggestion over a my blog to stop the top commenters spam and it was so simple I felt stupid. Rename the heading of the widget to “Link Love for Commenters” or something similar. It will put a wrench in their whole searching “Top Commenters” technique of finding blogs to spam.

    Stephan Miller’s last blog post..A Stumble Out of Nowhere

    Andy Bailey February 5, 2008

    Roger: I was thinking more on the lines of aggregating a news site for particular keywords and displaying an excerpt for those news items. I don’t think it’s fair to do that to another site as it’s more on the lines of spam scrapers which wouldn’t go down too well!

    I’ll see what I can do with a plugin for grabbing some bbc news for a particular word.

    Thanks for the offer but I get the eeby-jeeby’s when I go underwater and see a fish that isn’t scared of me. Last time I went snorkel swimming I saw a gert big fish that wouldn’t swim away when I waved my hand in front of it. I was still swimming halfway up the beach!!

    Stephan: it’s a good idea but that’ll only stop the people searching for “top commentator”. Comment hijackers will still do the ‘pretend to be someone else’ thing and the top commentator plugin will still show the last used url for an existing comment author. Nice idea though.

    Rhys (8 comments.) February 5, 2008

    I’ve not noticed it, but it makes sense.

    I have quite an uncommon name, and I have noticed that a number of comments and regular readers who comment do so because they share the same name as me. Of course, I’ve put a block on “Rhys” appearing in the top commenters list largely becaue I - like you - comment on my own posts ;).

    These people were getting annoyed, so in the end I asked them to comment under a different name.

    I assume it can work with spammers though, but I always thought it checked the e-mail address before moderation?

    Rhys’s last blog post..Feed Me Till I Want No More

    Andy Bailey February 6, 2008

    Rhys: I think the spammers also use the correct email address, the url is the only thing that changes. the buggers!

    Sharon (88 comments.) February 6, 2008

    Hey Andy.

    I just ban their butts off my sites by blocking their ips and I make sure that I have checked off that the commentator must have an approved comment before it gets approved right away. For extra security, it moderates right away anyone with over one link.

    They are getting way too smart nowadays. Some even post with the appropriate content and a serious comment about that particular post.

    Sharon’s last blog post..The Direct Link Between Better Sex and Being Fit

    Nicole Price (43 comments.) February 6, 2008

    My biggest spam problem is trackback spam. Good for nothing blogs just post a lousy paragraph quoting your contents and link to you. In essence they get a link from a good blog while the blog in question receives a link from a useless site. Besides, if you have dofollow enabled, and he has a nofollow in his links, you are at further loss.

    Nicole Price’s last blog post..Shoes at 80% discount

    Andy Bailey February 6, 2008

    sharon: yes it’s the ones that post relevant comments that are hardest to spot. I generally look for no last blog post and if I see it is a spam I add the site keyword to the list of banned words. It’s getting to be a big list! the price of success !lol

    Nicole: trackback is a nightmare too, I get hundreds of them any moment I mention the word AJAX on any of my articles!

    Sharon (88 comments.) February 8, 2008

    Andy, since it’s the same IP offender that leave messages for everything and anything, I just block their ip instead of the keywords.

    A little bit more effective.

    Actually, too effective that I blocked myself at one time :)

    Blonde roots are showing.

    Sharon’s last blog post..Serial Cheaters - Are They Worth The Time?

    Mark @ TheLocoMono (4 comments.) February 9, 2008

    That’s nice to know about this plug in. I use a different Top Commentator widget but haven’t noticed this being hijacked. I will have to look into this some more. I tried using this plugin you mentioned before but was not satisfied with it.

    Mark @ TheLocoMono’s last blog post..Figured Out TheLocoMono WordPress Theme

    pelf (26 comments.) February 22, 2008

    OK, so you’ve “found” the problem. Any solution yet?

    pelf’s last blog post..Trip to Tioman canceled (and a joke)

    Andy Bailey February 22, 2008

    pelf: I’m sorry to say my solution was to remove it entirely! I am far too busy lately to do any personal coding or else I would have put something together to fix the problem!

    Rick NHS (4 comments.) June 27, 2008

    This has happened to my associates and I on more than one occasion on more than one blog with top commenter plugins. Simply put… it’s unfair.

    If you do hear of a way to prevent this from happening, I’d love to know too (as I’m sure many of your readers would too). Thanks!

    Rick NHSs last blog post..Permian Basin Home Sales Up

    IMFreakz (1 comments.) July 7, 2008

    I think what Stephan Miller do is the simple way to avoid this spammers.

    IMFreakzs last blog post..What Should We Do ?

    Leave a comment

    19 online now
    the most online was 176
    elottery Ajax commentluv
    Sponsors
    available ad space available ad space available ad space available ad space available ad space available ad space