Journal FortKnox's Journal: Crapflooding 18

Looks like everyone that has a personal site with blogging/comments is getting crapflooded.

Hopefully you all thought ahead to add in banning ability. Feel free to use the comments in this JE to put in the IPs of all the offenders so everyone else can do an 'ahead' banning.

Sure, they'll use all kinda tools like redirecting pages and such, but there is always a finite number of places they can hit you from. Hopefully, we'll get a full list of IPs here within a couple days for everyone to ban.
  • Here's my ban list. These are the only people I have IP banned, and it's from last night:
    213. 208.67.82
    • more ip's. Brain is a little fried, so I'm not going to do the sed magic on it myself. I'm sure there are repeats. 2004.01.05 2004.01.05 2004.01.05 2004.01.05 2004.01.05 2004.01.05 2004.01.05 2004.01.05 2004.01.06 2004.01.06 2004.01.06 2004.01.06 2
    172 .16.0.2 (I hate this guy!)
  • If you're using MT, you can use a different comment engine... a certain fluffy porcupine has managed to use phpBB as the comments engine. This makes it much more difficult to script a crapflood (and has more robust banning and authentication features to boot!).

    How to integrate phpBB and MT []

  • all the ips are probably compromised machines. anyone with a mind for scripted flooding will know how to search for more.

    but here's the list of ips that flooded me []:
    64.1 75.137.61
    217.37.1 66.65

    I sent a complaint to each of the responsible ISPs and the IFCC [].
  • CloseComments, available from the webside, can be used to stop commenting to all non-recent articles.

    Also, this page [] describes a modification to the mt-comments.cgi script to prevent automated attacks from succeeding.

    • To automate CloseComments, I first bookmarked it. Then I told Mozilla to check it for updates (or make available offline?) at midnight each night. That should load the page, and take the desired action.
    • That method is a band-aid on a cracked dam. It would take a matter of a few minutes for a troll to examine your page's source, grab all the hidden fields and put 'em in the URL.
  • Nobody has messed with
    but then again, I don't really do anything there.

