<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>archGFX &#187; spam</title>
	<atom:link href="http://archgfx.net/tag/spam/feed" rel="self" type="application/rss+xml" />
	<link>http://archgfx.net</link>
	<description>Austin web designer - Adam Freetly</description>
	<lastBuildDate>Thu, 19 Apr 2012 18:01:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>WordPress 2.3.3 Spam Exploit</title>
		<link>http://archgfx.net/blog/2008/geek/blogging/wordpress-233-spam-exploit</link>
		<comments>http://archgfx.net/blog/2008/geek/blogging/wordpress-233-spam-exploit#comments</comments>
		<pubDate>Thu, 27 Mar 2008 16:24:56 +0000</pubDate>
		<dc:creator>adam</dc:creator>
				<category><![CDATA[blogging]]></category>
		<category><![CDATA[dashboard]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://archgfx.net/blog/2008/geek/blogging/wordpress-233-spam-exploit</guid>
		<description><![CDATA[If you run a wordpress blog, you should be reading Blogsecurity. This is the feed I use, that only includes the wordpress advisories. I think it's a damn shame that this feed isn't included in the wordpress planet that's syndicated across everyone's dashboard. Security is far more important than wordcamp. I'm only bringing this up [...]]]></description>
			<content:encoded><![CDATA[<p>If you run a wordpress blog, you should be reading <a href="http://blogsecurity.net/">Blogsecurity</a>.  <a href="http://blogsecurity.net/category/wordpress/feed/">This is the feed I use</a>, that only includes the wordpress advisories. I think it's a damn shame that this feed isn't included in the <a href="http://planet.wordpress.org/">wordpress planet</a> that's syndicated across everyone's dashboard.  Security is far more important than wordcamp.</p>
<p>I'm only bringing this up because there's a <a href="http://smackdown.blogsblogsblogs.com/2008/03/23/new-wordpress-233-exploitvulnerability-adds-spam-directory-wp-content1/">new WordPress 2.3.3 exploit</a> that's as-yet unpatched. So far it seems to only affect blogs with open registration, but no one's yet sure what exploit is being  targetted.   So far the only stopgap solution is to create a directory in <code>wp-content/</code> called <code>1/</code>, and set the permissions to <code>000</code>, using an FTP program:</p>
<p><img src="http://archgfx.net/wp-content/uploads/2008/03/000.JPG" class="center" alt="000" /></p>
<p>While you're in there, you should also make sure your <code>wp-content/</code> directory is set to <code>755</code>, and you should set <code>wp-content/index.php</code> to <code>444</code>, since the exploit seems to replace that file as well.</p>
]]></content:encoded>
			<wfw:commentRss>http://archgfx.net/blog/2008/geek/blogging/wordpress-233-spam-exploit/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Defensio</title>
		<link>http://archgfx.net/blog/2007/geek/blogging/defensio-%c2%b7-outsmarting-evil-spam</link>
		<comments>http://archgfx.net/blog/2007/geek/blogging/defensio-%c2%b7-outsmarting-evil-spam#comments</comments>
		<pubDate>Wed, 07 Nov 2007 17:46:17 +0000</pubDate>
		<dc:creator>adam</dc:creator>
				<category><![CDATA[blogging]]></category>
		<category><![CDATA[akismet]]></category>
		<category><![CDATA[defensio]]></category>
		<category><![CDATA[Plugins]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spam-karma]]></category>

		<guid isPermaLink="false">http://archgfx.net/blog/2007/geek/blogging/defensio-%c2%b7-outsmarting-evil-spam</guid>
		<description><![CDATA[Defensio launched their public beta today. I've been part of the private beta for a couple months now, after openly criticizing Akismet. Defensio is a similar tool, so it does fall prey to the same "wisdom of crowds" weaknesses. Defensio's usability far outstrips SK21 and Akismet2, and the launch of the website improves it a [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://defensio.com/"><img src="http://archgfx.net/wp-content/plugins/defensio//poweredbyd.png" alt="Defensio" /></a></p>
<p><a href="http://defensio.com/">Defensio</a> launched their public beta today.  I've been part of the private beta for a couple months now, after openly criticizing Akismet.  Defensio is a similar tool, so it does fall prey to the same <a href="http://andybeard.eu/2007/02/akismet-the-danger-of-collective-intelligence-and-why-i-dont-use-it.html">"wisdom of crowds" weaknesses</a>.  Defensio's usability far outstrips SK2<a href="#footnote-1-1238" id="footnote-link-1-1238" title="See the footnote.">1</a> and Akismet<a href="#footnote-2-1238" id="footnote-link-2-1238" title="See the footnote.">2</a>, and the launch of the website improves it a bit.  Now there's an <acronym title='Rich Site Summary'><span class='caps'>RSS</span></acronym> feed for my spam.  Granted, that's a little strange, but it's better than SK2's digest emails, which untrain google's filters by passing along spam content inside legitimate emails.  I like having a choice in anti-spam measures, and especially one that's upfront about its accuracy, and that's cognizant of the need to police your own quarantine.  Here's a couple screenshots to give you an idea of what it looks like:</p>
<p><a href="http://archgfx.net/photos/main.php?g2_itemId=349&amp;g2_GALLERYSID=TMP_SESSION_ID_DI_NOISSES_PMT"><img src="http://archgfx.net/photos/main.php?g2_view=core.DownloadItem&amp;g2_itemId=350&amp;g2_GALLERYSID=TMP_SESSION_ID_DI_NOISSES_PMT" alt="Defensio" title="Admin on defensio's site" height="90" width="150" /></a><a href="http://archgfx.net/photos/main.php?g2_itemId=352&amp;g2_GALLERYSID=TMP_SESSION_ID_DI_NOISSES_PMT"><img src="http://archgfx.net/photos/main.php?g2_view=core.DownloadItem&amp;g2_itemId=353&amp;g2_GALLERYSID=TMP_SESSION_ID_DI_NOISSES_PMT" alt="archGFX › Defensio-Spam" title="Local spam quarantine panel" height="112" width="150" /></a></p>
<br /><ol class="footnotes"><li id="footnote-1-1238">gouge my eyes out ugly  <a href="#footnote-link-1-1238"></a></li><li id="footnote-2-1238">requires <a href="http://internetducttape.com/tools/wordpress/akismet-auntie-spam/">plugins upon plugins</a> to be usable  <a href="#footnote-link-2-1238"></a></li></ol>]]></content:encoded>
			<wfw:commentRss>http://archgfx.net/blog/2007/geek/blogging/defensio-%c2%b7-outsmarting-evil-spam/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Ron Paul, Spammer</title>
		<link>http://archgfx.net/blog/2007/geek/blogging/ron-paul-spammer</link>
		<comments>http://archgfx.net/blog/2007/geek/blogging/ron-paul-spammer#comments</comments>
		<pubDate>Sun, 01 Jul 2007 13:25:38 +0000</pubDate>
		<dc:creator>adam</dc:creator>
				<category><![CDATA[blogging]]></category>
		<category><![CDATA[2.0]]></category>
		<category><![CDATA[akismet]]></category>
		<category><![CDATA[digg]]></category>
		<category><![CDATA[gaming]]></category>
		<category><![CDATA[politics]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://archgfx.net/blog/2007/geek/blogging/ron-paul-spammer</guid>
		<description><![CDATA[I'm not voting for ron paul. not just because i'm not voting republican. In the past week, i've recieved half a dozen blog spam comments mentioning his stance on the iraq war, and then linking to his site. Unlike most of the spam comments i recieve, it has a believable name, and proper grammar. For [...]]]></description>
			<content:encoded><![CDATA[<p>I'm not voting for ron paul.  not just because i'm not voting republican.  In the past week, i've recieved half a dozen blog spam comments mentioning his stance on the iraq war, and then linking to his site.  Unlike most of the spam comments i recieve, it has a believable name, and proper grammar.</p>
<p>For a second, i thought it might be an overzealous supporter, leaving a real comment on an unrelated entry (<a href="http://archgfx.net/blog/guidelines">i delete those</a>, but don't feed them to <a href="http://akismet.com">akismet</a>).  Then I looked at the post the comment was attached to: <a href="http://archgfx.net/blog/2002/arch/urbanlab">urbanlab</a>.  The post is unremarkable, save one thing:</p>
<p>It has the lowest post ID on my blog.  Only a bot would dig through my blog that way.  any human would have commented on the most recent post.</p>
<p>So as for the question of whether <a href="http://timothybryce.com/?p=33">Ron Paul is spamming digg</a>?  I have no doubt that he is, and that his "supporters" are using bots to do it, thinking they're doing him a favor.  Although this does put me in the awkward position of <a href="http://www.rushlimbaugh.com/home/daily/site_051607/content/01125110.guest.html">agreeing with rush limbaugh</a>.</p>
<p>web 2.0, meet political graft.  This will be the year that online political polls show up DOA.  unless they start feeding poll results to akismet.</p>
]]></content:encoded>
			<wfw:commentRss>http://archgfx.net/blog/2007/geek/blogging/ron-paul-spammer/feed</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
		<item>
		<title>Save your contact page from spam</title>
		<link>http://archgfx.net/blog/2007/geek/blogging/save-your-contact-page-from-spam</link>
		<comments>http://archgfx.net/blog/2007/geek/blogging/save-your-contact-page-from-spam#comments</comments>
		<pubDate>Thu, 18 Jan 2007 18:59:39 +0000</pubDate>
		<dc:creator>adam</dc:creator>
				<category><![CDATA[blogging]]></category>
		<category><![CDATA[CSS]]></category>
		<category><![CDATA[howto]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://archgfx.net/blog/2007/asides/save-your-contact-page-from-spam</guid>
		<description><![CDATA[there are a couple of different methods for blocking email harvesting bots from your contact page. Some involve javascript and obfuscating the email address. some involve putting the address in an image. my new favorite trick involves both. first, go get your email address turned into escaped HTML characters. Take the code they give you, [...]]]></description>
			<content:encoded><![CDATA[<p>there are a couple of different methods for blocking email harvesting bots from your contact page.  Some involve javascript and obfuscating the email address.  some involve putting the address in an image.  my new favorite trick involves both.<br />
first, go <a href="http://www.golivecentral.com/pages/txttut/scramble.shtml">get your email address turned into escaped <acronym title='HyperText Markup Language'><span class='caps'>HTML</span></acronym> characters</a>.  Take the code they give you, and wrap it in a span with a specific class, and add the same class to the link:</p>
<pre>&lt;span class="jsmail"&gt;&lt;!--
document.write("&lt;a href='mailto:<code><font color="red">put your scrambled address here</font></code>' class='jsmail'&gt; wp-admin [at] archgfx [dot] net&lt;/a&gt;"))
// --&gt; 

&lt;/script&gt;

&lt;/span&gt;</pre>
<p>I also changed the 'contact us!' text to a human readable, but not copyable version of the email address.  Now, <a href="http://safemail.justlikeed.net/">get your email turned into an image</a>, and we're going to use the image in <acronym title='Cascading Style Sheets'><span class='caps'>CSS</span></acronym>, so that even if a real person is browsing the site with javascript disabled, they'll still see the email address:</p>
<pre>
.jsmail {

display: block;

width: 129px;

height: 11px;

background: url('http://safemail.justlikeed.net/e/dd6330802be7d20f41dc95336e2acbfa.png') no-repeat 0 0;

text-indent: -9000px;

}</pre>
<p>i like it.  it's not completely accessible, but it's pretty good.  it's reliable, and it won't be confusing to people with older browsers or strict security settings.  <a href="http://www.archgfx.net/aspnet_client/obfuscated1.html">Here's an example</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://archgfx.net/blog/2007/geek/blogging/save-your-contact-page-from-spam/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Telling Jesus to go to hell</title>
		<link>http://archgfx.net/blog/2006/geek/blogging/telling-jesus-to-go-to-hell</link>
		<comments>http://archgfx.net/blog/2006/geek/blogging/telling-jesus-to-go-to-hell#comments</comments>
		<pubDate>Mon, 11 Dec 2006 16:57:26 +0000</pubDate>
		<dc:creator>adam</dc:creator>
				<category><![CDATA[blogging]]></category>
		<category><![CDATA[automattic]]></category>
		<category><![CDATA[cult of matt]]></category>
		<category><![CDATA[idiocy]]></category>
		<category><![CDATA[jesus]]></category>
		<category><![CDATA[Plugins]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://archgfx.net/blog/2006/asides/telling-jesus-to-go-to-hell</guid>
		<description><![CDATA[alright, Mullenweig, you win. It's finally worth the effort for me to take Owen's advice and installed X-Dashboard. You would have thought that it had been asked for enough times. You would have thought that the recent wp-hackers waffling over the inclusion of widgets would have brought it to mind: WordPress Planet is not core [...]]]></description>
			<content:encoded><![CDATA[<p>alright, <a href="http://photomatt.net" title="*sigh*">Mullenweig</a>, you win.  It's finally worth the effort for me to take <a href="http://asymptomatic.net/2006/09/21/2831/planet-wordpress-and-the-dashboard-feeds/">Owen's advice </a>and installed <a href="http://mattread.com/projects/wp-plugins/x-dashboard/">X-Dashboard</a>.  You would have thought that it had been asked for enough times.  You would have thought that the recent wp-hackers waffling over the inclusion of widgets would have brought it to mind:</p>
<p>WordPress Planet is not core functionality.  It's frilly, extra, bloat.</p>
<p>If you're trying to simplify the wordpress admin area, start here.  I've left the admin panel alone because it's never been worth the effort to hack a core file, or install a plugin to <em>get rid of stuff</em>.  plugins should be for adding functionality.  Now it's worth it because some <a href="http://weblogtoolscollection.com/archives/2006/12/10/discernment-in-the-blogdom-of-god/" title="fucking asshole">idiot jesus freak</a> thinks it's okay to preach at people from the WTC.</p>
<p>Looks like i'll be subscribing to <a href="http://alexking.org">Alex</a>, Owen, and the other developers who have a sense of propriety in my <acronym title='Rich Site Summary'><span class='caps'>RSS</span></acronym> reader now.  I would have thought after the mike little birthday incident, you would have the sense to tell your freaky religious zealot friends to keep their spammy preaching to themselves.</p>
<p><strong>UPDATE:</strong></p>
<p>due to x-Dashboard looking ugly(er) <a href="http://sunburntkamel.archgfx.net/2006/12/17/tiger-admin/" title="recent update">in Tiger Admin</a> (it doesn't use the <code>#zeitgeist</code> div, so the sidebar doesn't float properly),  I hacked <code>/wp-admin/index.php</code> to show feeds from<a href="http://planetwordpress.planetozh.com/" title="alternative wordpress planet.  like mars."> Ozh's Planet wordpress</a>. (he has the good sense to only syndicate the wp-plugins category from WTC, hence, no jesus.</p>
]]></content:encoded>
			<wfw:commentRss>http://archgfx.net/blog/2006/geek/blogging/telling-jesus-to-go-to-hell/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

