Random Gobbledeygook Trackbacks? (7 posts)

  1. TheRoss
    Posted 11 years ago #

    I've gotten several nonsense trackbacks within the last few hours, like this:

    Website: uuau (IP: , D5E08A5E.kabel.telenet.be)
    URI : http://utyxbiioaeuvwx.com/
    <trackback />lqegnuwau

    Website: exxa (IP: , pcp09353364pcs.tsclos01.al.comcast.net)
    URI : http://jzsunuvwx.com/
    <trackback />esvouafoh

    Website: ebuyaaoe (IP: , dhcp065-025-158-097.columbus.rr.com)
    URI : http://jzsunuvwx.com/
    <trackback />zyjryqj

    Website: joqzudzz (IP: , c-24-98-139-116.atl.client2.attbi.com)
    URI : http://jzsunuvwx.com/
    <trackback />qqifexa

    Has anyone seen a pattern like this before? Is my blog being "felt out" in preperation for a larger attack?

  2. I missed this post, and instead replied in this one. Sorry!

  3. mork
    Posted 11 years ago #

    Yes. Your blog is being felt out. I was getting this same junk for a while. I think they do it to every blog (automated of course) and then search for the random junk to compile a list of vulnerable blogs that they sucesfully commented.

    I was fairly active in deleting those random things as they came.. but just today I got whacked with a massive attack of them - this time they contained real links and keywords and such to adult oriented sites.

    My solution so far has been to get rid of trackbacks all together for the time being.

  4. Lee Penney
    Posted 11 years ago #

    The same thing happened to me as happened to Mork, first junk, now adult stuff, I've had about 8-10 comments in the last hour.

  5. Tek
    Posted 11 years ago #

    Me too!

  6. tcloer
    Posted 11 years ago #

    Same with me. Some nonsense postings and today then the brute force attack started.

    For now, i have installed this >> http://mudbomb.com/archives/2005/01/05/trackback-spam-stopper-for-wordpress/ - it leaves a zero byte wp-trackback.php and moves its functionality to another file. Since, no trackback spam has come through (but this was just 30 minutes ago, so i'm not yet sure about it)...

  7. Matthias
    Posted 11 years ago #

    I received three gobbledygook comments today. Not trackbacks, just plain old comments. Here's a sample:

    Author : Griffin (IP: , h0008a10058bc.ne.client2.attbi.com)
    E-mail : griffin46@teiopafrjit.com
    URI : http://uhnyrxeuiop.com/
    Whois : http://ws.arin.net/cgi-bin/whois.pl?queryinput=

    <a href="http://uobifrobewqwer.com/">syahqivseul</a> poiuyt http://ghjklopxezaa/

    Weird, huh, that broken URL. They all contained the word "poiuyt", perhaps that's the string they use to identify my site? Added it to the blacklist just to see what happens. Also set approved=0 in the trackback file to prevent the trackback spam y'all mentioned, and turned on comment moderation for the night. I'll see how it looks tomorrow.

Topic Closed

This topic has been closed to new replies.

About this Topic


No tags yet.