<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: KattyBlackyard IP: 89.28.14.35 in massive blog spam attack</title>
	<atom:link href="http://www.securitywatch.co.uk/2009/06/15/kattyblackyard-ip-89281435-in-massive-blog-spam-attack/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securitywatch.co.uk/2009/06/15/kattyblackyard-ip-89281435-in-massive-blog-spam-attack/</link>
	<description>Security News, Security Blog, Security Forums</description>
	<lastBuildDate>Thu, 18 Feb 2010 15:06:15 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Internet Threat</title>
		<link>http://www.securitywatch.co.uk/2009/06/15/kattyblackyard-ip-89281435-in-massive-blog-spam-attack/comment-page-1/#comment-10695</link>
		<dc:creator>Internet Threat</dc:creator>
		<pubDate>Mon, 24 Aug 2009 09:28:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.securitywatch.co.uk/?p=1479#comment-10695</guid>
		<description>Possibly a professional spammer showing a potential client what we can do?</description>
		<content:encoded><![CDATA[<p>Possibly a professional spammer showing a potential client what we can do?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shady</title>
		<link>http://www.securitywatch.co.uk/2009/06/15/kattyblackyard-ip-89281435-in-massive-blog-spam-attack/comment-page-1/#comment-10576</link>
		<dc:creator>Shady</dc:creator>
		<pubDate>Tue, 07 Jul 2009 23:27:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.securitywatch.co.uk/?p=1479#comment-10576</guid>
		<description>Hey Guys,

I actually had spam from this IP but under a different name (KonstantinMiller). Perhaps he/she knows that we&#039;re on to them lol!

It&#039;s good to know that i&#039;m not the only one...</description>
		<content:encoded><![CDATA[<p>Hey Guys,</p>
<p>I actually had spam from this IP but under a different name (KonstantinMiller). Perhaps he/she knows that we&#8217;re on to them lol!</p>
<p>It&#8217;s good to know that i&#8217;m not the only one&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Don</title>
		<link>http://www.securitywatch.co.uk/2009/06/15/kattyblackyard-ip-89281435-in-massive-blog-spam-attack/comment-page-1/#comment-10568</link>
		<dc:creator>Don</dc:creator>
		<pubDate>Mon, 06 Jul 2009 19:25:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.securitywatch.co.uk/?p=1479#comment-10568</guid>
		<description>I have a very small blog, so already I&#039;m intrigued whenever I am notified that a comment has been submitted.  I never have comments automatically published without prior approval - a plus for removing any &quot;instant gratification&quot; that might arise from a perceived score.  This new spam wave is cunning in it&#039;s generic and realistic comments.  Sometimes even the email address looks credible.  The number one thing to always look at is the IP.  Do a simple whois and find out which country it came from.  If you&#039;re like me, chances are, your target audience is for non-repressive, English speaking regions/countries.  So, this would exclude China, Russia, Moldova, etc etc.  Not an automatic indicator, but a very good one if you have a small blog with only a handful of blog posts.  Naturally, a red flag would be the altering of the referrer, and more specifically, the lack of the customary URL parameters normally appended to a true Google search query.  This means, &quot;http://www.google.com/&quot; is not from a relevant search.  Although, it is worth noting that some bots have been known to generate fake Google search URL&#039;s as their referrer using keywords found on the target site itself - very cunning.</description>
		<content:encoded><![CDATA[<p>I have a very small blog, so already I&#8217;m intrigued whenever I am notified that a comment has been submitted.  I never have comments automatically published without prior approval &#8211; a plus for removing any &#8220;instant gratification&#8221; that might arise from a perceived score.  This new spam wave is cunning in it&#8217;s generic and realistic comments.  Sometimes even the email address looks credible.  The number one thing to always look at is the IP.  Do a simple whois and find out which country it came from.  If you&#8217;re like me, chances are, your target audience is for non-repressive, English speaking regions/countries.  So, this would exclude China, Russia, Moldova, etc etc.  Not an automatic indicator, but a very good one if you have a small blog with only a handful of blog posts.  Naturally, a red flag would be the altering of the referrer, and more specifically, the lack of the customary URL parameters normally appended to a true Google search query.  This means, &#8220;http://www.google.com/&#8221; is not from a relevant search.  Although, it is worth noting that some bots have been known to generate fake Google search URL&#8217;s as their referrer using keywords found on the target site itself &#8211; very cunning.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jaca</title>
		<link>http://www.securitywatch.co.uk/2009/06/15/kattyblackyard-ip-89281435-in-massive-blog-spam-attack/comment-page-1/#comment-10566</link>
		<dc:creator>Jaca</dc:creator>
		<pubDate>Mon, 06 Jul 2009 18:47:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.securitywatch.co.uk/?p=1479#comment-10566</guid>
		<description>This is what I got on my blog. I did not aloow it thnx to u.

KonstantinMiller
google.com
konstantine@info1a.cn
89.28.14.35	
Submitted on 2009/07/06 at 7:36pm
Hello. I think the article is really interesting. I am even interested in reading more. How soon will you update your blog?</description>
		<content:encoded><![CDATA[<p>This is what I got on my blog. I did not aloow it thnx to u.</p>
<p>KonstantinMiller<br />
google.com<br />
<a href="mailto:konstantine@info1a.cn">konstantine@info1a.cn</a><br />
89.28.14.35<br />
Submitted on 2009/07/06 at 7:36pm<br />
Hello. I think the article is really interesting. I am even interested in reading more. How soon will you update your blog?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Leonidas Georgiou</title>
		<link>http://www.securitywatch.co.uk/2009/06/15/kattyblackyard-ip-89281435-in-massive-blog-spam-attack/comment-page-1/#comment-10565</link>
		<dc:creator>Leonidas Georgiou</dc:creator>
		<pubDate>Mon, 06 Jul 2009 17:43:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.securitywatch.co.uk/?p=1479#comment-10565</guid>
		<description>QWO9NI I think its good decision what he did.,</description>
		<content:encoded><![CDATA[<p>QWO9NI I think its good decision what he did.,</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Principles</title>
		<link>http://www.securitywatch.co.uk/2009/06/15/kattyblackyard-ip-89281435-in-massive-blog-spam-attack/comment-page-1/#comment-10495</link>
		<dc:creator>Principles</dc:creator>
		<pubDate>Fri, 19 Jun 2009 03:26:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.securitywatch.co.uk/?p=1479#comment-10495</guid>
		<description>I was also confused by those comments initially. i approved a few and then started getting more and more. Super annoying. Won&#039;t make that mistake again.</description>
		<content:encoded><![CDATA[<p>I was also confused by those comments initially. i approved a few and then started getting more and more. Super annoying. Won&#8217;t make that mistake again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://www.securitywatch.co.uk/2009/06/15/kattyblackyard-ip-89281435-in-massive-blog-spam-attack/comment-page-1/#comment-10488</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 17 Jun 2009 03:56:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.securitywatch.co.uk/?p=1479#comment-10488</guid>
		<description>I just saw the IP Whois. Thinking an idea its to block entire range of 89.28.14.0 - 89.28.15.255. Not  like The Republic of Moldova is high on my visitor stats anyway...</description>
		<content:encoded><![CDATA[<p>I just saw the IP Whois. Thinking an idea its to block entire range of 89.28.14.0 &#8211; 89.28.15.255. Not  like The Republic of Moldova is high on my visitor stats anyway&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://www.securitywatch.co.uk/2009/06/15/kattyblackyard-ip-89281435-in-massive-blog-spam-attack/comment-page-1/#comment-10487</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 17 Jun 2009 03:52:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.securitywatch.co.uk/?p=1479#comment-10487</guid>
		<description>I own a blog and had a bout 8 or so comments when I noticed all from same ip 89.28.14.35, which led me here. I also found it strange that Google was listed as website and the same username. I have since used IP deny from all accounts on my server. No body does something this big without a reason. My guess would be mass spam, OR if blogs and forums are accepting the spam, it could show potential security issues with other &#039;careless&#039; settings to send out mass spam via nobody or an unsecured folder of something. IP deny 89.28.14.35 seems to have worked so far. No more of this user on my blogs.</description>
		<content:encoded><![CDATA[<p>I own a blog and had a bout 8 or so comments when I noticed all from same ip 89.28.14.35, which led me here. I also found it strange that Google was listed as website and the same username. I have since used IP deny from all accounts on my server. No body does something this big without a reason. My guess would be mass spam, OR if blogs and forums are accepting the spam, it could show potential security issues with other &#8216;careless&#8217; settings to send out mass spam via nobody or an unsecured folder of something. IP deny 89.28.14.35 seems to have worked so far. No more of this user on my blogs.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dr. Mike Wendell</title>
		<link>http://www.securitywatch.co.uk/2009/06/15/kattyblackyard-ip-89281435-in-massive-blog-spam-attack/comment-page-1/#comment-10486</link>
		<dc:creator>Dr. Mike Wendell</dc:creator>
		<pubDate>Tue, 16 Jun 2009 18:55:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.securitywatch.co.uk/?p=1479#comment-10486</guid>
		<description>Got it as well although we have our routers block off the IP address after getting a few of them from the same IP address within a certain amount of time.   Typepad Antispam caught it fine as well.

The google link is probably a default for whatever software they&#039;re using and they forgot to change it.  Wouldn&#039;t be the first time.</description>
		<content:encoded><![CDATA[<p>Got it as well although we have our routers block off the IP address after getting a few of them from the same IP address within a certain amount of time.   Typepad Antispam caught it fine as well.</p>
<p>The google link is probably a default for whatever software they&#8217;re using and they forgot to change it.  Wouldn&#8217;t be the first time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Madhav Tripathi</title>
		<link>http://www.securitywatch.co.uk/2009/06/15/kattyblackyard-ip-89281435-in-massive-blog-spam-attack/comment-page-1/#comment-10485</link>
		<dc:creator>Madhav Tripathi</dc:creator>
		<pubDate>Tue, 16 Jun 2009 12:38:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.securitywatch.co.uk/?p=1479#comment-10485</guid>
		<description>Hi thanks for writing about this amtter, I am also getting few of nice comments without any link only commenters website which is google and with the same Ip and same email address with different names, so what should I mean of this.</description>
		<content:encoded><![CDATA[<p>Hi thanks for writing about this amtter, I am also getting few of nice comments without any link only commenters website which is google and with the same Ip and same email address with different names, so what should I mean of this.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
