ExpressionEngine CMS
Open, Free, Amazing

Thread

This is an archived forum and the content is probably no longer relevant, but is provided here for posterity.

The active forums are here.

Search Spam Drop-Off

August 09, 2007 11:02am

Subscribe [0]
  • #1 / Aug 09, 2007 11:02am

    ParisJC

    150 posts

    I’ve noticed a marked decrease - as in to almost none - in search spam so far this month. Was there something in the latest build to help protect against that? I suppose it’s possible the spammers are just taking a vacation, but ...  😝

  • #2 / Aug 09, 2007 11:36am

    Daniel Walton

    553 posts

    Hopefully they have all been removed by the authorities and are currently having their testicles squeezed in rather large, rusty, iron vices that tend to stick when tightened.

  • #3 / Aug 09, 2007 1:34pm

    Paul Burdick

    480 posts

    We did make some changes in 1.5.2 that made all search terms converted into safe output because there were users using the Query module to output the terms directly without any sanitizing or HTML conversion, which was being done automatically in the Control Panel when those terms were displayed.  That was many months ago, and typically spammers have not cared whenever we have added new security stuff and just keep on hammering away blindly.

  • #4 / Aug 09, 2007 1:40pm

    ParisJC

    150 posts

    We had been getting hit pretty heavily with them for months, so this month’s drastic decrease really stood out. We’ll just enjoy it while it lasts!

  • #5 / Aug 10, 2007 4:54am

    JT Thompson

    745 posts

    can someone help me here? What exactly is search spam? I’ve never looked at anything like this so I’m completely ignorant.

  • #6 / Aug 10, 2007 10:35am

    ParisJC

    150 posts

    Hi, JT.

    I’m probably not really up on all the tech end of it, but the “search spam” I’m talking about generally consists of spammy messages - URLs, etc. - submitted by bots to sites’ search forms so that they will appear in lists of most-searched-for phrases. Some sites show those lists publicly, I hear.

    They’re generally pretty ugly, and I can’t see how they’d possibly be enticing to a reader. But I guess even a small percentage of clicks is profit for the spammers.

    We don’t show the list publicly, but I use it privately to keep track of what folks look for and how they do it. It helps me determine how useful the navigation is or isn’t, and to make adjustments.

    I’d show you a copy of some of it, but not a single one now appears in my search log.  😊 Hope that holds for a while.

  • #7 / Aug 10, 2007 10:43am

    JT Thompson

    745 posts

    Ahhh.. Nope I know exactly what you mean now. Thanks!

  • #8 / Oct 05, 2007 4:36pm

    Trend Hunter

    81 posts

    I get a ton of search spam as well..

    1. Is there a way for EE to just ‘dismiss’ searches that have URLs in them?
    2. The spamers are sending the search code directly, because the length is much longer than the text field in search box will allow.  Is there a way to just change whatever location is ‘receiving’ the search, which would mean their request will be filtered out?

  • #9 / Oct 05, 2007 5:08pm

    Lisa Wess

    20502 posts

    You might like to have a look at spam proofing your installation.

  • #10 / Oct 05, 2007 9:11pm

    Paul Burdick

    480 posts

    1.  No, not by default, but one could write an extension to do so.

    2.  You can Remove and Install the Search moduel and that will create new Action IDs for the search submission forms.  Honestly though, it would be a simple thing for the spammers to work around this.

  • #11 / Nov 06, 2007 2:46pm

    Trend Hunter

    81 posts

    The search spam is becomming a rather big deal, knocking my site offline.

    I am getting attacks where different IP addresses all search for the same term in the same minute (seconds?).  If the search term was able to use a cached query or filter out the dups, it could really save my site.  Otherwise it is actually causing my site to fail…

  • #12 / Nov 06, 2007 2:48pm

    Paul Burdick

    480 posts

    Are you using the Blacklist with the .htaccess blocking?

  • #13 / Nov 06, 2007 3:19pm

    Trend Hunter

    81 posts

    I am using the blacklist, but the seach attacks are coming from different IPs…

  • #14 / Nov 06, 2007 3:24pm

    Paul Burdick

    480 posts

    Yes, and the same thing happens for Comments, Trackbacks, and Referrer Spam.  And one cannot exactly deny duplicate searches on a site.

  • #15 / Nov 06, 2007 3:27pm

    Trend Hunter

    81 posts

    Can the searches be cached?  (or are they?)

.(JavaScript must be enabled to view this email address)

ExpressionEngine News!

#eecms, #events, #releases