Spammers use Top Commentators vulnerability to hijack top list

Posted by Andy Bailey at 4 February, 2008, 6:14 pm
44

Your comments or your life!

Many thanks to Scott from UK MAC.net (a great UK site for Apple Mac’s) for sending me an email about this. He noticed that his name was number 1 on the Top Commentators list on the sidebar but, his name linked to an obvious spam site.

I checked further and two other people had been hijacked, Dearest Pelf and Roger(who ironically, was on the list from his comments about spam comments).

It seems that the Top Commentators plugin remembers the last URL used for a commentator and displays that as an anchor for their name,(it used to use the most used url, don’t know why they changed it) even after deleting and spaminating the spammers url and ip into the blacklist they still showed on the displayed list so I have decided to remove the Top Commentators plugin for now.

I noticed something was up the other day when I received a comment from WitchyPoo but it didn’t look like her normal way of writing and it didn’t have a last blog post (from CommentLuv), the comment made mention of something in the post and the spammer came back to respond to my follow up comment. I just changed the url back to Witchypoos’ site and thought nothing of it.

I have even noticed certain spammers now following links on to other peoples blogs from here and doing the same thing to others.

Be aware of this, look out for comments coming from your regular commentators and make sure they have the correct url or install CommentLuv and look out for comments without a last blog post.

Popularity: 10% [?]

Category : Blog News
follow fiddyp on twitter

16 online now
the most online was 176
Sponsors
available ad space available ad space available ad space available ad space available ad space available ad space