<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: How can I stop referrer log spam?</title>
	<link>http://ask.metafilter.com/12504/How-can-I-stop-referrer-log-spam/</link>
	<description>Comments on Ask MetaFilter post How can I stop referrer log spam?</description>
	<pubDate>Sun, 05 Dec 2004 00:16:53 -0800</pubDate>
	<lastBuildDate>Sun, 05 Dec 2004 00:16:53 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Question: How can I stop referrer log spam?</title>
		<link>http://ask.metafilter.com/12504/How-can-I-stop-referrer-log-spam</link>	
		<description>&quot;&lt;a href=&quot;http://www.adminshop.com/friends.php&quot;&gt;Reffy&lt;/a&gt; is a Windows-based mass referrer spammer.... Reffy comes with a pre-generated list of 3047 active blog websites....&quot; &lt;em&gt;My&lt;/em&gt; blog is on that pre-generated list. These people are spamming my logs and filling my referrer page with crap. Paypal has, unsurprisingly, not responded to reports that they&apos;re being used to transfer money to spammers, and .htaccess deny blacklists are no good when your URL is being distributed to spammers all over the place. So, (1) how do I stop them, and (2) what legal recourse would I possibly have to get my cut of the money they&apos;re making by putting my website URL in their application?</description>
		<guid isPermaLink="false">post:ask.metafilter.com,2004:site.12504</guid>
		<pubDate>Sat, 04 Dec 2004 23:09:55 -0800</pubDate>
		<dc:creator>Anonymous</dc:creator>
		
			<category>spammers</category>
		
			<category>spam</category>
		
			<category>spamming</category>
		
			<category>blog</category>
		
			<category>logs</category>
		
			<category>referrerpage</category>
		
			<category>blocking</category>
		
			<category>stopping</category>
		
			<category>legalrecourse</category>
		
			<category>law</category>
		
	</item> <item>
		<title>By: Nothing</title>
		<link>http://ask.metafilter.com/12504/How-can-I-stop-referrer-log-spam#217840</link>	
		<description>They say they use a &quot;custom http header&quot; to avoid having to download the pages. If it&apos;s different enough  hat you can be fairly certain a regular user wouldn&apos;t send it, you could probably use mod_rewrite to check for this header, and return a 403 Forbidden.  How this would affect your logs would depend on how they&apos;re generated. If they&apos;re server logs, the requests will still show up, but they&apos;ll show up as errors. If you use a script to generate logs, this shoud prevent them from showing up entirely.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.12504-217840</guid>
		<pubDate>Sun, 05 Dec 2004 00:16:53 -0800</pubDate>
		<dc:creator>Nothing</dc:creator>
	</item><item>
		<title>By: ruelle</title>
		<link>http://ask.metafilter.com/12504/How-can-I-stop-referrer-log-spam#217841</link>	
		<description>Good question, anon. &lt;br&gt;
Recently two places i visit have been spammed by these type of comments: &lt;br&gt;
&lt;br&gt;
&lt;small&gt;Cash Advance Loan - email - url &lt;br&gt;
WE MUST ALL HEAR THE UNIVERSAL CALL TO LIKE YOUR NEIGHBOR JUST LIKE YOU LIKE TO BE LIKED YOURSELF.&lt;br&gt;
- George W Bush, Cash Advance Loan http://www.cashadvance.be&lt;br&gt;
24.11.04 @ 14:52:37&lt;br&gt;
Direct TV - email - url &lt;br&gt;
Hummingbirds never remember the words to songs.&lt;br&gt;
Direct TV http://www.direct-tv-com.com&lt;br&gt;
25.11.04 @ 06:43:15&lt;br&gt;
Video Poker - email - url &lt;br&gt;
I CALL UPON ALL NATIONS TO DO EVERYTHING THEY CAN TO STOP THESE TERRORIST KILLERS. THANK YOU. NOW WATCH THIS DRIVE.&lt;br&gt;
- George W Bush,AUGUST 4, 2002, ON VIOLENCE IN THE MIDDLE EAST... AND HIS GOLF GAME Video Poker http://www.video-poker-com.com&lt;br&gt;
27.11.04 @ 10:57:09&lt;br&gt;
Phentermine - email - url &lt;br&gt;
May a Misguided Platypus lay its Eggs in your Jockey Shorts&lt;br&gt;
Phentermine http://online-prescription-pharmacy.com/Phentermine.htm&lt;br&gt;
29.11.04 @ 05:33:45&lt;br&gt;
poker tables - email - url &lt;br&gt;
Let us beware of saying that death is the opposite of life. The living being is only a species of the dead, and a very rare species. by online poker&lt;br&gt;
30.11.04 @ 03:23:12&lt;br&gt;
online poker rooms - email - url &lt;br&gt;
Science is built up with facts, as a house is with stones. But a collection of facts is no more a science than a heap of stones is a house. by texas holdem poker&lt;br&gt;
30.11.04 @ 08:00:00&lt;br&gt;
empirepoker - email - url &lt;br&gt;
It is necessary to the happiness of man that he be mentally faithful to himself. Infidelity does not consist in believing, or in disbelieving, it consists in professing to believe what one does not believe. by empirepoker&lt;br&gt;
30.11.04 @ 08:11:13&lt;br&gt;
gambling - email - url &lt;br&gt;
He who is unable to live in society, or who has no need because he is sufficient for himself, must be either a beast or a god. by online blackjack&lt;br&gt;
30.11.04 @ 12:13:07&lt;br&gt;
poker chips - email - url &lt;br&gt;
Society is indeed a contract...it becomes a partnership not only between those who are living, but between those who are living, those who are dead, and those who are to be born. by world series of poker&lt;br&gt;
30.11.04 @ 17:12:24&lt;br&gt;
texas holdem poker - email - url &lt;br&gt;
I wish to propose for the reader&apos;s favourable consideration a doctrine which may, I fear, appear wildly paradoxical and subversive. The doctrine in question is this: that it is undesirable to believe a proposition when there is no ground whatever for supposing it true. by partypoker&lt;br&gt;
30.11.04 @ 17:16:21&lt;/small&gt;&lt;br&gt;
&lt;br&gt;
Pity you asked this anonymously, I would have been interested in knowing if this inventive &quot;spam-as-comments&quot; is what your site is suffering from.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.12504-217841</guid>
		<pubDate>Sun, 05 Dec 2004 00:18:11 -0800</pubDate>
		<dc:creator>ruelle</dc:creator>
	</item><item>
		<title>By: i_am_joe&apos;s_spleen</title>
		<link>http://ask.metafilter.com/12504/How-can-I-stop-referrer-log-spam#217848</link>	
		<description>My God, that&apos;s evil. It also explains the sudden rise in referrer spam I&apos;ve noticed in my logs.&lt;br&gt;
&lt;br&gt;
The &quot;custom HTTP header&quot; is likely nothing more than a HEAD request, which is a standard HTTP request to ask the server when something was last modified. Blocking HEAD would be bad, most HEAD requests would be legitimate.&lt;br&gt;
&lt;br&gt;
The only thing I can think of is some logic in an Apache module to detect repeated requests from the same host with referrers that aren&apos;t from your site. Unfortunately, that would be error-prone and clunky, and basically we&apos;d end up in the same arms race we have with email spam.&lt;br&gt;
&lt;br&gt;
I&apos;m afraid that REFERER is just broken now - and these wankers (and people like them) broke it. So no, there is no answer to your first question. I am very interested in the second...</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.12504-217848</guid>
		<pubDate>Sun, 05 Dec 2004 00:35:49 -0800</pubDate>
		<dc:creator>i_am_joe&apos;s_spleen</dc:creator>
	</item><item>
		<title>By: i_am_joe&apos;s_spleen</title>
		<link>http://ask.metafilter.com/12504/How-can-I-stop-referrer-log-spam#217851</link>	
		<description>PS: some helpful hints &lt;a href=&quot;http://www.trafficstatistic.com/articles/referrer_spam_protection.html&quot;&gt;here&lt;/a&gt;, but no long term hope in my view.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.12504-217851</guid>
		<pubDate>Sun, 05 Dec 2004 00:39:06 -0800</pubDate>
		<dc:creator>i_am_joe&apos;s_spleen</dc:creator>
	</item><item>
		<title>By: i_am_joe&apos;s_spleen</title>
		<link>http://ask.metafilter.com/12504/How-can-I-stop-referrer-log-spam#217852</link>	
		<description>PPS: I do quite like the idea of the &quot;checkback&quot; described on that page. I might look into that...</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.12504-217852</guid>
		<pubDate>Sun, 05 Dec 2004 00:43:56 -0800</pubDate>
		<dc:creator>i_am_joe&apos;s_spleen</dc:creator>
	</item><item>
		<title>By: shepd</title>
		<link>http://ask.metafilter.com/12504/How-can-I-stop-referrer-log-spam#217854</link>	
		<description>Perhaps someone could be kind enough to update your software so that a human-readable-manchine-unreadable image with a few letters must be entered to submit a comment?&lt;br&gt;
&lt;br&gt;
I wish I could.  :-D</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.12504-217854</guid>
		<pubDate>Sun, 05 Dec 2004 00:49:06 -0800</pubDate>
		<dc:creator>shepd</dc:creator>
	</item><item>
		<title>By: Gnatcho</title>
		<link>http://ask.metafilter.com/12504/How-can-I-stop-referrer-log-spam#217875</link>	
		<description>I still hate the spam I get in my blog (not so active), but it is great fun to find out the source of the copied text.  Once I received an Emma Goldman quotation.&lt;br&gt;
&lt;br&gt;
Along with a link to black jack poker...bleh.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.12504-217875</guid>
		<pubDate>Sun, 05 Dec 2004 05:02:41 -0800</pubDate>
		<dc:creator>Gnatcho</dc:creator>
	</item><item>
		<title>By: frykitty</title>
		<link>http://ask.metafilter.com/12504/How-can-I-stop-referrer-log-spam#217892</link>	
		<description>Just to be clear: my understanding of the question is that this is &lt;i&gt;not&lt;/i&gt; comment spam, but referrer log spam, so suggestions for getting rid of comment spam are not going to be helpful.&lt;br&gt;
&lt;br&gt;
I know someone looking into this, and he led to &lt;a href=&quot;http://vigilant.tv/article/3416/ot-clone-blogs-and-referrer-log-spam&quot;&gt;this page&lt;/a&gt;.  They are suggesting a blacklist-style approach, which doesn&apos;t sound very practical unless it&apos;s automated, but there is lots of info.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.12504-217892</guid>
		<pubDate>Sun, 05 Dec 2004 07:18:08 -0800</pubDate>
		<dc:creator>frykitty</dc:creator>
	</item><item>
		<title>By: cyrusdogstar</title>
		<link>http://ask.metafilter.com/12504/How-can-I-stop-referrer-log-spam#217894</link>	
		<description>Just an FYI for some people who seem to be confusing referral spam with blog comments spam, they are two different beasts.&lt;br&gt;
&lt;br&gt;
Referral spam consists of making a request to one&apos;s webserver and having the &apos;referal&apos; (sic) value of the request be the spamming URL. This value is ostensibly used to keep track of how people get to your site--if I was on MeFi and clicked a link to anonymous.org/blog, then the referal URL logged on anonymous.org&apos;s site would be the URL of that MeFi thread (or the front page if I clicked from there).&lt;br&gt;
&lt;br&gt;
Some blog engines keep lists of referrals on each page as a pseudo-trackback sorta thing; and also, some more savvy web hosts / individuals with servers list web stats online, which also will include the referral URLs.&lt;br&gt;
&lt;br&gt;
So, the point of this referral spam is to get your URL on more and more webpages--either blog referral lists, or webserver stats pages--and thus increase your search engine rankings.&lt;br&gt;
&lt;br&gt;
Blog comment spam is done for the same reason, but is accomplished by spamming comment pages on blogs (making actual comments), instead of just accessing the base blog URL with a modified REFERAL header in the request. Same objective, different method.&lt;br&gt;
&lt;br&gt;
On preview: beaten by &lt;b&gt;frykitty&lt;/b&gt;. But my explanation&apos;s longer! :D</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.12504-217894</guid>
		<pubDate>Sun, 05 Dec 2004 07:25:23 -0800</pubDate>
		<dc:creator>cyrusdogstar</dc:creator>
	</item><item>
		<title>By: ralawrence</title>
		<link>http://ask.metafilter.com/12504/How-can-I-stop-referrer-log-spam#218000</link>	
		<description>How about setting a session cookie when the user visits your page to enter a comment and then check it exists on the submit? Not perfect but will mean their single HTTP request will fail. If you don&apos;t indicate either way then as long as they don&apos;t check the site of everyone they hit then you&apos;ll be okay.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.12504-218000</guid>
		<pubDate>Sun, 05 Dec 2004 11:40:19 -0800</pubDate>
		<dc:creator>ralawrence</dc:creator>
	</item><item>
		<title>By: sbutler</title>
		<link>http://ask.metafilter.com/12504/How-can-I-stop-referrer-log-spam#218065</link>	
		<description>Well, TypePad uses this little bit of HTML at the bottom to track referrers:&lt;br&gt;
&lt;br&gt;
&amp;lt;script type=&quot;text/javascript&quot;&amp;gt;&lt;br&gt;
&amp;lt;!--&lt;br&gt;
document.write(&apos;&amp;lt;img src=&quot;http://www.typepad.com/t/stats?blog_id=37618&amp;amp;amp;page=&apos; + escape(location.href) + &apos;&amp;amp;amp;referrer=&apos; + escape(document.referrer) + &apos;&quot; width=&quot;1&quot; height=&quot;1&quot; alt=&quot;&quot; /&amp;gt;&apos;);&lt;br&gt;
// --&amp;gt;&lt;br&gt;
&amp;lt;/script&amp;gt;&lt;br&gt;
&lt;br&gt;
Sure, it&apos;s a webug, but I doubt the referrer spammers are a) checking for this or b) have JS egines running to execute it. You could probably code up the stats CGI in about ten minutes.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.12504-218065</guid>
		<pubDate>Sun, 05 Dec 2004 13:41:11 -0800</pubDate>
		<dc:creator>sbutler</dc:creator>
	</item>
	</channel>
</rss>
