{"id":94,"date":"2009-11-07T15:40:00","date_gmt":"2009-11-07T15:40:00","guid":{"rendered":"http:\/\/www.dresan.com\/blog\/?p=94"},"modified":"2010-07-26T22:46:09","modified_gmt":"2010-07-27T05:46:09","slug":"latest-spam-wtf","status":"publish","type":"post","link":"https:\/\/dresan.com\/blog\/2009\/11\/07\/latest-spam-wtf\/","title":{"rendered":"Latest Spam WTF"},"content":{"rendered":"<p>Some time back I received a spam email that was blank.  This is understandable, actually; probably just someone trying out a list of email addresses.  I also got one containing the cryptic text &#8220;<a href=\"http:\/\/www.dresan.com\/2009\/04\/podmena-traffica-test.html\">podmena traffica test<\/a>&#8220;; this turned out also to be a &#8220;spoofing traffic test&#8221;.  Now I&#8217;ve got a bit of comment spam, which also seemed mysterious, until I dug into it a bit.  From my email:<\/p>\n<blockquote><p>Anonymous has left a new comment on your post &#8220;<a href=\"http:\/\/www.dresan.com\/2009\/03\/why-i-write.html\">Why I Write<\/a>&#8220;:<\/p>\n<p>I can not participate now in discussion &#8211; it is very occupied. I will be released &#8211; I will necessarily express the opinion. [url=DELETED]acheter levitra[\/url] This rather good idea is necessary just by the way<\/p>\n<p>Publish this comment.<\/p>\n<p>Reject this comment.<\/p>\n<p>Moderate comments for this blog.<\/p><\/blockquote>\n<p>The deleted URL is to a French eBay site, &#8220;acheter levitra&#8221; is French for &#8220;buy Levitra,&#8221; which is a brand name of <a href=\"http:\/\/en.wikipedia.org\/wiki\/Vardenafil\">Vardenafil<\/a>, which is, of course, a Viagra clone.  So this is essentially random pseudo-English text with a &#8220;buy Viagra&#8221; link, depending on the 1% of people who click on such links and the 1% of people who buy to pay for the cost of putting this spam on my blog.  Charming.<\/p>\n<p>Comment <span style=\"font-style:italic;\">reeejected<\/span>.<\/p>\n<p>-the Centaur<\/p>\n<p>UPDATE:  I got a similar post of with a less obvious spam form, targeting one of the more popular pages on my blog (can you say pooound cake?):<\/p>\n<blockquote><p>&#8220;I found this site using [url=http:\/\/google.com]google.com[\/url] And i want to thank you for your work. You have done really very good site. Great work, great site! Thank you! Sorry for offtopic&#8221;<\/p><\/blockquote>\n<p>But the [url=XXX]TEXT[\/url] pattern was a dead giveaway.  A search on Google for [<a href=\"http:\/\/www.google.com\/search?q=%22[url%3Dhttp%3A%2F%2Fgoogle.com]google.com[%2Furl]%22\">&#8220;[url=http:\/\/google.com]google.com[\/url]&#8221;<\/a>] &#8211; note that&#8217;s the &#8216;[url&#8230;\/url]&#8217; thing in double quotes; the outermost brackets are the syntax you use to indicate a chunk of text is a query, like [<a href=\"http:\/\/www.google.com\/search?q=centaur\">centaur<\/a>] &#8211; SO anyway, a search on Google for that nonsense revealed that the exact text of that comment has appeared <a href=\" http:\/\/groups.google.com\/group\/marumozhikal\/browse_thread\/thread\/3814b3fbe8907f5b\/232c1808cc6eb3a1?show_docid=232c1808cc6eb3a1\">elsewhere<\/a>.  So this is just more comment spam, trying to see if comments are unmoderated here.<\/p>\n<p>Comment flattering!  But <span style=\"font-style:italic;\">reeejected<\/span>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Some time back I received a spam email that was blank. This is understandable, actually; probably just someone trying out a list of email addresses. I also got one containing&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[11,59,3],"class_list":["post-94","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-development","tag-spam-investigations","tag-webworks","ratio-2-1","entry"],"_links":{"self":[{"href":"https:\/\/dresan.com\/blog\/wp-json\/wp\/v2\/posts\/94","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dresan.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dresan.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dresan.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dresan.com\/blog\/wp-json\/wp\/v2\/comments?post=94"}],"version-history":[{"count":1,"href":"https:\/\/dresan.com\/blog\/wp-json\/wp\/v2\/posts\/94\/revisions"}],"predecessor-version":[{"id":657,"href":"https:\/\/dresan.com\/blog\/wp-json\/wp\/v2\/posts\/94\/revisions\/657"}],"wp:attachment":[{"href":"https:\/\/dresan.com\/blog\/wp-json\/wp\/v2\/media?parent=94"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dresan.com\/blog\/wp-json\/wp\/v2\/categories?post=94"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dresan.com\/blog\/wp-json\/wp\/v2\/tags?post=94"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}