dsandler.org

Kevin Burton: Nasty New Trackback Spam. The main technique in this case exploits the fact that TypePad allows HTML in a place where it shouldn’t (an easy fix), but this caught my eye:

3. In the post URL they encode your permalink’s URL so that automated backlink trackers fail since now your URL appears on their site.

This might sound a bit confusing so I’ll show an example.

The trackback they submitted was:

http://foocom/foo.php?www.feedblog.org/2005/08/msn_filter_even.html

Then when you load this URL they automatically create a link to:

http://www.feedblog.org/2005/08/msn_filter_even.html

This is the first attack I’m aware of that specifically attempts to thwart backlink checkers like the Trackback Validator I helped with this past summer. When we started the project, we predicted that trackback spammers would either give up and go home (ha!) or they’d continue with the arms race and develop some kind of dynamic spam page in response.

There are a couple of reasons why I think this means that the spammers have essentially lost:

The spammers now need a stable URL on a server that can (potentially) serve a lot of hits. It’s a slightly greater investment, and any time we can create some financial burden on spammers, it’s a tiny win. More importantly, the URL used in the spam contains a valid backlink. By the metric we described when we released the Validator, this is no longer considered “spam”. Since PageRank is (currently) strictly additive, this means that the spammer can only be increasing your PageRank (and of course you’re doing nothing for his, because you used nofollow, right?). The spam is essentially harmless (and, in practice, difficult for a human to distinguish from a legitimate Trackback).

In a sense, these are the central goals of any anti-spam effort: to increase the costs to spammers, and to decrease the costs (in terms of time, PageRank, money, etc.) to recipients.

2 Responses to “Trackback spammers upping the ante”

financial-help.capitalfirmventure says:

financial-help.capitalfirmventure…

[…] far out site now comment this synopsis http://dsandler.org/wp/archives/2005/11/14/trackback-spammers-upping-the-ante and give comments […]…

dsandler.org ≡ Validator foiled! says:

[…] Well, we were right and not right. I just received some TrackBack spam (probably not coincidentally, on a blog post about trackback spam) that fooled the Validator and yet can’t really be considered to be legitimate. […]


subscribe to dsandler.org

[image]   [image] for faster updates, subscribe with FeedTree

mac software made on premises

toastycode.com: toasty software for the mac pyrotheque: a new (old) fireworks screensaver for the mac
Cuckoo—the bell tolls for your Mac.

twitter/dsandler [RSS]

loading…

elsewhere

research is what grad students do all day my bookmarks are your bookmarks my photos are grainy but help me remember

highlights

Pyromania! the true screen saver story Fall down go boom “Cars†secondo Luigi Cinquecento Food reviews (DNR and Earl of Sandwich) Z520a iTunes remote because the computer is so far away MiniPNG a microscopic graphics library FeedTree 0.7.0 as seen recently on Slashdot OpenBinder is great glue for an operating system Apartment Security (a true story in 3½ panels) Silicon Valley Damashii or, the Yahoo! endgame To appear in the proceedings of IPTPS'05

between the couch cushions

my sketchbook makes occasional appearances [image]feedtree makes rss instantaneous software I made just for you captain jim my 1995 webcomic the soothing green t-shirt a slashdot favorite misclassified under “funny” email is quite likely to be read

strongly connected

erinmak is not to be trifled with pixelknave says moof when upside-down dave is dangerous rod is one groovy mother adam is googling us all amar is not really a pirate angi sees little blue dots harbinger lets you know it's coming jason looks like an idiot in that hat jeff is keeping austin weird regan seems to tolerate jason emann will not abide your IM-speak jim is a stranger in ein anderes Land liscio is pronounced "lee-show" darryl has no need of identifying objects friends as they appear on dsandler.org sportsgirl reports…on all the pro courts

Search

Recent

Archives

dsandler.org is Dan Sandler's website and notebook.

Powered by WordPress and here's why.


You are viewing a mobilized version of this site...
View original page here

Mobilized by Mowser Mowser