<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/1.5.2" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
>

<channel>
	<title>Trackback Spam Resources</title>
	<link>http://seclab.cs.rice.edu/proj/trackback</link>
	<description>Taking TrackBack back.</description>
	<pubDate>Wed, 17 May 2006 20:48:57 +0000</pubDate>
	<generator>http://wordpress.org/?v=1.5.2</generator>
	<language>en</language>

		<item>
		<title>New version 0.7.</title>
		<link>http://seclab.cs.rice.edu/proj/trackback/2006/05/17/new-version-07/</link>
		<comments>http://seclab.cs.rice.edu/proj/trackback/2006/05/17/new-version-07/#comments</comments>
		<pubDate>Wed, 17 May 2006 20:48:57 +0000</pubDate>
		<dc:creator>dsandler</dc:creator>
		
	<category>Releases</category>
		<guid>http://seclab.cs.rice.edu/proj/trackback/2006/05/17/new-version-07/</guid>
		<description><![CDATA[	We&#8217;ve just released version 0.7 of the Validator; this is a strongly recommended upgrade for all our current users.  We have improved the reliability and robustness of almost all aspects of the plugin, including spam classification, administration, and data reporting.  Go grab version 0.7 and be free of TrackBack spam!

]]></description>
			<content:encoded><![CDATA[	<p>We&#8217;ve just released version 0.7 of the Validator; this is a <em>strongly recommended upgrade</em> for all our current users.  We have improved the reliability and robustness of almost all aspects of the plugin, including spam classification, administration, and data reporting.  Go <a href="http://seclab.cs.rice.edu/proj/trackback/trackback-validator-plugin/">grab version 0.7</a> and be free of TrackBack spam!
</p>
]]></content:encoded>
			<wfw:commentRSS>http://seclab.cs.rice.edu/proj/trackback/2006/05/17/new-version-07/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>Trackback Validator plugin v0.6</title>
		<link>http://seclab.cs.rice.edu/proj/trackback/2005/11/19/trackback-validator-plugin-v06/</link>
		<comments>http://seclab.cs.rice.edu/proj/trackback/2005/11/19/trackback-validator-plugin-v06/#comments</comments>
		<pubDate>Sat, 19 Nov 2005 22:06:45 +0000</pubDate>
		<dc:creator>creepy</dc:creator>
		
	<category>Prevention</category>
	<category>Releases</category>
		<guid>http://seclab.cs.rice.edu/proj/trackback/2005/11/19/trackback-validator-plugin-v06/</guid>
		<description><![CDATA[	A new version of the Trackback Validator plugin is available! Download it here.
	New features include:

Added a simple check against spammers&#8217; dynamic link pages.
	Simplified the data submission process.

]]></description>
			<content:encoded><![CDATA[	<p>A new version of the Trackback Validator plugin is available! Download it <a href="http://seclab.cs.rice.edu/proj/trackback/trackback-validator-plugin/">here</a>.</p>
	<p>New features include:
<ul>
<li>Added a simple check against spammers&#8217; dynamic link pages.</li>
	<li>Simplified the data submission process.</li>
</ul>
]]></content:encoded>
			<wfw:commentRSS>http://seclab.cs.rice.edu/proj/trackback/2005/11/19/trackback-validator-plugin-v06/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>MovableType hit hard by TB spammers</title>
		<link>http://seclab.cs.rice.edu/proj/trackback/2005/09/05/movabletype-hit-hard-by-tb-spammers/</link>
		<comments>http://seclab.cs.rice.edu/proj/trackback/2005/09/05/movabletype-hit-hard-by-tb-spammers/#comments</comments>
		<pubDate>Mon, 05 Sep 2005 17:49:27 +0000</pubDate>
		<dc:creator>dsandler</dc:creator>
		
	<category>Links</category>
	<category>Attacks</category>
		<guid>http://seclab.cs.rice.edu/proj/trackback/2005/09/05/movabletype-hit-hard-by-tb-spammers/</guid>
		<description><![CDATA[	It appears that a vulnerability has been found in Movable Type allowing Trackback spammers free reign to sneak links in without rel=&#8221;nofollow&#8221;.  (I haven&#8217;t yet found details of the exact attack being used.)

]]></description>
			<content:encoded><![CDATA[	<p>It appears that a vulnerability has been found in Movable Type <a href="http://www.platinax.co.uk/blogs/brian/archives/2005/09/trackback_spamm.html">allowing Trackback spammers free reign</a> to sneak links in without <tt>rel=&#8221;nofollow&#8221;</tt>.  (I haven&#8217;t yet found details of the exact attack being used.)
</p>
]]></content:encoded>
			<wfw:commentRSS>http://seclab.cs.rice.edu/proj/trackback/2005/09/05/movabletype-hit-hard-by-tb-spammers/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>Trackback Validator plugin v0.5</title>
		<link>http://seclab.cs.rice.edu/proj/trackback/2005/08/24/trackback-validator-plugin-v05/</link>
		<comments>http://seclab.cs.rice.edu/proj/trackback/2005/08/24/trackback-validator-plugin-v05/#comments</comments>
		<pubDate>Wed, 24 Aug 2005 18:01:43 +0000</pubDate>
		<dc:creator>dsandler</dc:creator>
		
	<category>Prevention</category>
	<category>Releases</category>
		<guid>http://seclab.cs.rice.edu/proj/trackback/2005/08/24/trackback-validator-plugin-v05/</guid>
		<description><![CDATA[	
Here&#8217;s a slightly edited version of the message I sent to wp-hackers today:

	
	
The first public version (v0.5) of the WP Trackback Validator is now available from the following URL:

	
http://idli.cs.rice.edu/~dsandler/trackback/trackback-validator-plugin/
	
The idea behind the Validator, which is under development by students in the Rice University Computer Security Lab, is simple: Trackback URLs that point to pages that [...]]]></description>
			<content:encoded><![CDATA[	<p>
Here&#8217;s a slightly edited version of the message I sent to <a href="http://lists.automattic.com/mailman/listinfo/wp-hackers">wp-hackers</a> today:
</p>
	<blockquote>
	<p>
The first public version (v0.5) of the WP Trackback Validator is now available from the following URL:
</p>
	<p>
<a href="http://idli.cs.rice.edu/~dsandler/trackback/trackback-validator-plugin/">http://idli.cs.rice.edu/~dsandler/trackback/trackback-validator-plugin/</a></p>
	<p>
The idea behind the Validator, which is under development by students in the Rice University Computer Security Lab, is simple: <strong>Trackback URLs that point to pages that <em>don&#8217;t</em> link back to your blog are bogus.</strong>  It&#8217;s an easy test to perform, and one that no current Trackback spammer is bothering to try to defeat; since we&#8217;ve started using this plugin on our personal WP blogs, our Trackback spam rate has dropped to zero.
</p>
	<p>
This test is already present in some other anti-spam plugins, typically included among a hodgepodge of other content-based schemes and rules.  If you&#8217;re looking for something lightweight that does one job extremely well, please check out the Validator.
</p>
	<p>
The point of the project, in addition to helping to combat Trackback spam, is to collect <em>data.</em>  We&#8217;re interested in the kinds of spams people get, from which sources, at what rate, etc.  We&#8217;d like to see if, once everyone starts applying the simple reverse-link check, the spammers step up their assault.  In order to help us, the Validator distribution comes with a small shell script which will send us a profile of the spam you&#8217;ve caught recently.
</p>
	<p>
So, in short, to save Trackback from an <a href="http://jeremy.zawodny.com/blog/archives/005049.html">untimely death</a>, try out the <a href="http://idli.cs.rice.edu/~dsandler/trackback/trackback-validator-plugin/">Trackback Validator plugin</a>, and send us back some data.  In the meantime, enjoy spam-free Trackbacks on your WordPress site.
</p>
	</blockquote>
]]></content:encoded>
			<wfw:commentRSS>http://seclab.cs.rice.edu/proj/trackback/2005/08/24/trackback-validator-plugin-v05/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>State of the art: spam blogs and spam Pingbacks</title>
		<link>http://seclab.cs.rice.edu/proj/trackback/2005/08/16/state-of-the-art-spam-blogs-and-spam-pingbacks/</link>
		<comments>http://seclab.cs.rice.edu/proj/trackback/2005/08/16/state-of-the-art-spam-blogs-and-spam-pingbacks/#comments</comments>
		<pubDate>Tue, 16 Aug 2005 17:10:08 +0000</pubDate>
		<dc:creator>dsandler</dc:creator>
		
	<category>Links</category>
	<category>Attacks</category>
		<guid>http://seclab.cs.rice.edu/proj/trackback/2005/08/16/state-of-the-art-spam-blogs-and-spam-pingbacks/</guid>
		<description><![CDATA[	
Nice writeup of the current trends in spam blogs and RSS content theft.

	
	The last six months has seen a massive rise in content theft blogs and spam blogs, and there’s one thing these blogs usually have in common, and that’s the whole “Blog and Ping” thing &#8230; Blog and Ping is a online marketing term [...]]]></description>
			<content:encoded><![CDATA[	<p>
Nice <a href="http://www.blogherald.com/2005/08/16/understanding-blog-and-ping/">writeup</a> of the current trends in spam blogs and RSS content theft.
</p>
	<blockquote cite="http://www.blogherald.com/2005/08/16/understanding-blog-and-ping/" title="Understanding Blog and Ping">
	<p>The last six months has seen a massive rise in content theft blogs and spam blogs, and there’s one thing these blogs usually have in common, and that’s the whole “Blog and Ping” thing &#8230; Blog and Ping is a online marketing term applied to a system that utilizes blogs and pings (short for pingback) to deliver content and/ or sites for indexing in search engines with the ultimate aim of profit.</p>
	<p>[&#8230;]</p>
	<p>
Already some in the SEO industry are saying that Blog and Ping is dead due to the massive increase in users, content theft sites and spam blogs. If you’re getting any benefit out of Blog and Ping now, you won’t be for much longer because already some search engines are talking about excluding your sites.</p>
	</blockquote>
]]></content:encoded>
			<wfw:commentRSS>http://seclab.cs.rice.edu/proj/trackback/2005/08/16/state-of-the-art-spam-blogs-and-spam-pingbacks/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>Attack profile for WordPress sites</title>
		<link>http://seclab.cs.rice.edu/proj/trackback/2005/07/25/attack-profile-for-wordpress-sites/</link>
		<comments>http://seclab.cs.rice.edu/proj/trackback/2005/07/25/attack-profile-for-wordpress-sites/#comments</comments>
		<pubDate>Mon, 25 Jul 2005 21:07:33 +0000</pubDate>
		<dc:creator>dsandler</dc:creator>
		
	<category>Links</category>
	<category>Prevention</category>
	<category>Attacks</category>
		<guid>http://seclab.cs.rice.edu/proj/trackback/2005/07/25/attack-profile-for-wordpress-sites/</guid>
		<description><![CDATA[	Scott Buchanan explains one of the mechanisms by which WordPress sites are attacked by trackback spammers (circa March 2005):
	
The spam &#8216;bot will iteratively request &#8220;index.php?p=[n],&#8221; where n is incremented each time.  After each successful request, it will then send a trackback to &#8220;wp-trackback.php&#8221; for entry number n.

	
To remedy this, Scott wrote a TB Spam [...]]]></description>
			<content:encoded><![CDATA[	<p>Scott Buchanan explains one of the mechanisms by which <a href="http://blog.mytechaid.com/archives/2005/03/09/wordpress-trackback-spam-solution/">WordPress sites are attacked by trackback spammers</a> (circa March 2005):</p>
	<blockquote cite="http://blog.mytechaid.com/archives/2005/03/09/wordpress-trackback-spam-solution/" title="WordPress Trackback Spam Solution"><p>
The spam &#8216;bot will iteratively request &#8220;<code>index.php?p=[n]</code>,&#8221; where n is incremented each time.  After each successful request, it will then send a trackback to &#8220;<code>wp-trackback.php</code>&#8221; for entry number n.
</p></blockquote>
	<p>
To remedy this, Scott wrote a TB Spam Blocker plugin (downloadable from the link above) which patches this particular hole.  From the plugin&#8217;s included <tt>readme.txt</tt>:</p>
	<blockquote><p><tt>This plugin will modify the WordPress permalink generator to include a mod_rewrite rule that blocks direct access to wp-trackback.php.  (It still allows redirected access through cruft-free URLs.  Legitimate trackbacks will use the redirected URL, as that will be what appears on your blog.)<br />
</tt></p></blockquote>
	<p>
A simple fix, though as soon as the spam bots are updated to use the cruft-free trackback URLs (by crawling the site), this solution will stop working.
</p>
]]></content:encoded>
			<wfw:commentRSS>http://seclab.cs.rice.edu/proj/trackback/2005/07/25/attack-profile-for-wordpress-sites/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>WP Hashcash</title>
		<link>http://seclab.cs.rice.edu/proj/trackback/2005/06/16/wp-hashcash/</link>
		<comments>http://seclab.cs.rice.edu/proj/trackback/2005/06/16/wp-hashcash/#comments</comments>
		<pubDate>Thu, 16 Jun 2005 18:55:53 +0000</pubDate>
		<dc:creator>dsandler</dc:creator>
		
	<category>Links</category>
	<category>Prevention</category>
		<guid>http://seclab.cs.rice.edu/proj/trackback/2005/06/16/wp-hashcash/</guid>
		<description><![CDATA[	
Not a trackback spam solution, of course, but WP Hashcash is a cute defense against comment spam by requiring a proof of work from the client.  
	
Of course, as soon as comment spammers bake a JavaScript engine into their spambots, it&#8217;s all over, so Hashcash isn&#8217;t really breaking out of the &#8220;arms race&#8221; model [...]]]></description>
			<content:encoded><![CDATA[	<p>
Not a trackback spam solution, of course, but <a href="http://elliottback.com/wp/archives/2004/11/29/spam-stopgap-extreme/">WP Hashcash</a> is a cute defense against comment spam by requiring a proof of work from the client.  </p>
	<p>
Of course, as soon as comment spammers bake a JavaScript engine into their spambots, it&#8217;s all over, so Hashcash isn&#8217;t really breaking out of the &#8220;arms race&#8221; model of spam prevention.  (But it does represent an impressively large leap in that race, so it&#8217;s likely to be quite effective for a while.)
</p>
]]></content:encoded>
			<wfw:commentRSS>http://seclab.cs.rice.edu/proj/trackback/2005/06/16/wp-hashcash/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>Tragedy</title>
		<link>http://seclab.cs.rice.edu/proj/trackback/2005/06/16/tragedy/</link>
		<comments>http://seclab.cs.rice.edu/proj/trackback/2005/06/16/tragedy/#comments</comments>
		<pubDate>Thu, 16 Jun 2005 16:03:06 +0000</pubDate>
		<dc:creator>dsandler</dc:creator>
		
	<category>Links</category>
		<guid>http://seclab.cs.rice.edu/proj/trackback/2005/06/16/tragedy/</guid>
		<description><![CDATA[	Funny: Trackback: A Tragedy In 3 Acts.  Jason Lefkowitz offers a tongue-in-cheek play set at SixApart, as well as some slightly more sober analysis of how we got where we are today:
	
When your technology is open to abuse, silence is deadly.  You might think that 6A, as the authors of the spec, would [...]]]></description>
			<content:encoded><![CDATA[	<p>Funny: <a href="http://www.antseyeview.com/archives/001653.html">Trackback: A Tragedy In 3 Acts</a>.  Jason Lefkowitz offers a tongue-in-cheek play set at SixApart, as well as some slightly more sober analysis of how we got where we are today:</p>
	<blockquote cite="http://www.antseyeview.com/archives/001653.html" title="Ant's Eye View"><p>
When your technology is open to abuse, silence is deadly.</strong>  You might think that 6A, as the authors of the spec, would have made notice of the deep problems with TrackBack and been on top of finding solutions.  Such is not the case: <a href="http://www.movabletype.org/trackback/">the official TrackBack blog</a> hasn&#8217;t been updated in nearly a year, and their Professional Network lumps TrackBack spam in with comment spam and advises use of tools like MT-Blacklist for both.  The result is a perception that no fix is coming, which leads <a href="http://akma.disseminary.org/archives/2005/02/trackback_is_br.html">people</a> <a href="http://www.plasticbag.org/archives/2005/04/trackback_is_dead_are_comments_dead_too.shtml">to</a> <a href="http://weblog.burningbird.net/archives/2005/02/06/some-things-arent-worth-saving/">abandon</a> <a href="http://i.never.nu/article/2399/">ship</a> rather than wait for a fix they think will never come.
</p></blockquote>
]]></content:encoded>
			<wfw:commentRSS>http://seclab.cs.rice.edu/proj/trackback/2005/06/16/tragedy/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>Interview with a Link Spammer</title>
		<link>http://seclab.cs.rice.edu/proj/trackback/2005/06/16/interview-with-a-link-spammer/</link>
		<comments>http://seclab.cs.rice.edu/proj/trackback/2005/06/16/interview-with-a-link-spammer/#comments</comments>
		<pubDate>Thu, 16 Jun 2005 15:38:44 +0000</pubDate>
		<dc:creator>dsandler</dc:creator>
		
	<category>Links</category>
	<category>Attacks</category>
		<guid>http://seclab.cs.rice.edu/proj/trackback/2005/06/16/interview-with-a-link-spammer/</guid>
		<description><![CDATA[	From earlier this year, an interview with a link spammer in The Register.  (TB is mentioned as a fallback for when comment-based link spamming becomes too difficult.)

]]></description>
			<content:encoded><![CDATA[	<p>From earlier this year, an <a href="http://www.theregister.co.uk/2005/01/31/link_spamer_interview/">interview with a link spammer</a> in The Register.  (TB is mentioned as a fallback for when comment-based link spamming becomes too difficult.)
</p>
]]></content:encoded>
			<wfw:commentRSS>http://seclab.cs.rice.edu/proj/trackback/2005/06/16/interview-with-a-link-spammer/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>Bought and sold.</title>
		<link>http://seclab.cs.rice.edu/proj/trackback/2005/05/25/bought-and-sold/</link>
		<comments>http://seclab.cs.rice.edu/proj/trackback/2005/05/25/bought-and-sold/#comments</comments>
		<pubDate>Wed, 25 May 2005 20:20:44 +0000</pubDate>
		<dc:creator>dsandler</dc:creator>
		
	<category>Links</category>
	<category>Attacks</category>
		<guid>http://seclab.cs.rice.edu/proj/trackback/2005/05/25/bought-and-sold/</guid>
		<description><![CDATA[	Judging by some of the recent articles on SpamHuntress (another site dedicated to analysis and eradication of spam, including trackback spam), there are indeed lists of vulnerable weblogs floating around the Internet—just like the lists of live addresses that email spammers buy and sell. Update: More SpamHuntress links, including her catalog of TB spam solutions [...]]]></description>
			<content:encoded><![CDATA[	<p>Judging by some of the <a href="http://spamhuntress.com/2005/05/25/our-bulgarians/">recent articles</a> on <a href="http://spamhuntress.com/">SpamHuntress</a> (another site dedicated to analysis and eradication of spam, including <a href="http://spamhuntress.com/category/trackback-spam/">trackback spam</a>), there are indeed lists of vulnerable weblogs floating around the Internet—just like the lists of live addresses that email spammers buy and sell. <b>Update:</b> More SpamHuntress links, including her <a href="http://spamhuntress.com/trackback-spam-solutions/">catalog of TB spam solutions</a> and the new <a href="http://spamhuntress.com/wiki/Main_Page">Spamhuntress Wiki</a>, which includes some very interesting <a href="http://spamhuntress.com/wiki/Link_spammer_pages">spammer profiles</a>.</p>
]]></content:encoded>
			<wfw:commentRSS>http://seclab.cs.rice.edu/proj/trackback/2005/05/25/bought-and-sold/feed/</wfw:commentRSS>
	</item>
	</channel>
</rss>
