mariovaldez.net
http://www.mariovaldez.net/webapps/forums/

I like it, but have two questions...
http://www.mariovaldez.net/webapps/forums/viewtopic.php?f=16&t=243
Page 1 of 1

Author:  Guest [ 27 Aug 2005, 03:16 ]
Post subject:  I like it, but have two questions...

I just installed this spam poison and it looks great. It could be very useful.

I was just wondering two things...

Is there any chance that spammers may be able to find out that your site messed around with their bot, and then launch an attack?

Also, what are the chances of a genuine search engine bot getting snagged?

TIA

Author:  mvaldez [ 02 Sep 2005, 19:37 ]
Post subject:  Spammer retaliation...

Guest:

> just installed this spam poison and it looks
> great. It could be very useful.

Great! :)

> I was just wondering two things...
> Is there any chance that spammers may
> be able to find out that your site messed
> around with their bot, and then launch an
> attack?

Of course there is a chance for spammer retaliation. You can divide spammers in three groups: a) evil spammer, b) blind spammer, and b) clueless spammer.

The Clueless Spammer is a poor fellow who is told that spamming is Ok for doing bussiness and then start doing it. Poor guy. He/She pays for a email harvester software (or worst, pays for an email database) and then start sending spam. This kind of spammer will not even know that the harvested list is messed up. And hopefully, when he/she finds out that Spamming Is Not Right, will stop doing it. I personally know a few good people that were once this kind of spammer (but now they are not).

Blind Spammer is a different beast. He/She is sure spamming is good, that everybody complaining about spam is just trying to destroy his/her bussiness, and that spamming is protected by Free of Speech laws. Go figure. They may think you are "The Enemy" and then may try to attack you. Expect some kind of retaliation from them; mail bombing, more spamming, etc. But they can only know the addresses were from your site if they have the skills, most don't.

Evil Spammer is someone who thinks that spamming may not be right but he/she will do it anyway because abusing the system is ok. Or because money is more important than being a good citizen. Or just for fun. Usually they will not retaliate you because they are too busy sending spam, and sending a ten millions messages is more important even if only 1% of the recipients are good addresses.

Some Evil Spammers don't send emails themselves, but only sell email addresses databases. For them, the most cost-effective way to deal with your site is just to avoid it. That's great for you as all addresses in your site will not be harvested.


I've been using this for a couple of years and nothing bad has happened. I know some friends who use this (or any other) poisoner and they are Ok. I think most harvester won't even know where does the bad addresses came from.


> Also, what are the chances of a
> genuine search engine bot getting
> snagged?

Null. A genuine search engine will obey the NOINDEX metatag and the sentences in the robots.txt file. If a search engine ignore those, they have more important problems than your fake-email pages.


As a final note, the spamming problem will not be solved by simple poisoners like this. I don't know what will happen in the future, but as of today, a good spam filter for your email (like SpamAssassin) is your best bet. Poisoners can help but in a macroecological way (will not help you a lot, but will help everybody a bit).


Regards,

Mario A. Valdez-Ramirez.

Author:  Guest [ 29 Jan 2007, 21:20 ]
Post subject: 

i'd seen cgi script somewhere that implement this delay in the script.

i think, this script also should include some delaying value to make the loading slower and to avoid attack on the script.

when certain scripts is attacked by spambot, it almost like DOS attack and increasing high cpu loads.

Author:  mvaldez [ 30 Jan 2007, 16:52 ]
Post subject:  Delay in script response...

Guest user:

> i'd seen cgi script somewhere that implement this delay in the script.
> i think, this script also should include some delaying value to make
> the loading slower and to avoid attack on the script. when certain
> scripts is attacked by spambot, it almost like DOS attack and
> increasing high cpu loads.


Hi. The PHP Spam poison script also use a delay when being loaded. This delay is random from 10 to 30 seconds (by default). You can modify this sleep time by changing the pwp_minsleeptime and pwp_maxsleeptime variables.


Regards,

Mario A. Valdez-Ramirez.

Page 1 of 1 All times are UTC - 7 hours
Powered by phpBB® Forum Software © phpBB Group
http://www.phpbb.com/