Industry guru Dave Taylor answers free tech support questions about a wide variety of business and technical topics, including blogging, Google AdSense, MySpace, Sony PSP, Apple iPod, Mp3 players, management, Linux, SEO, Mac OS X, Facebook, Twitter, LinkedIn and Microsoft Windows.

Minimize blog spam in MovableType?

Dave, I use two different versions of MovableType for my weblogs, one on each of two different servers, and am wondering what your best recommendations are in terms of limiting my comment spam? One is 3.17 and the other is the latest 3.2 release.


Dave's Answer:

By darn good luck, colleague and blog wizard Josh Hallett of Hyku | blog just recently answered a very similar question, and with his kind permission, I quote his excellent answer:

I recently upgraded to MT 3.2 but preferred my anti-spam settings of 3.17. I'll talk a bit about both. Ultimately, however, most comment and trackback spam is run via scripts.

MovableType 3.17

With 3.17 I had three primary tools in use:

MT Blacklist
MTBL was one of the first anti-spam measures and did an excellent job, however it is not compatible with 3.2, I wish it was. MTBL would prevent the majority of stuff making it thru. What was nice is that you never had to deal with it. Sort of an out-of-sight-out-of-mind thing.

SpamLookup
Rather than running a simple blacklist like MTBL SpamLookup runs the comment/trackback thru a series of tests; if the item does not meet a certain threshold then it will not be posted. For example if a post has too many links in it or the IP address of the trackback does not match the IP address of the blog domain the comment will be denied. In combination these two items did a good job.

Occasionally a large comment spam run would make it through because it had one or two URLs or, in the case of one batch, had links to google.com. All these were run via scripts. To stop that brute-force attack I....

Changed the name of the default mt-comments.cgi and mt-tb.cgi
There are a few steps involved with this, but the primary purpose is to defeat the script attacks running against your mt-comments.cgi file. If you look at your log files you'll see that the comment spammers are simply posting directly to the mt-comments.cgi file. Changing the name of the file can help stop this. It was always fun to look at my log files and see a few thousand 404's when a spammer was trying to post to my mt-comments.cgi file.

At best the name-changing step would beat them for a while. With the three things above I enjoyed a few months with no major spam problems. From time-to-time I would get a single post, which upon investigation (via logs, etc..) turned out to be an actual person posting a single item at a time.

All that changed when I upgraded to 3.2

MovableType 3.2

Like I mentioned earlier, MT-Blacklist does not work with version 3.2. Your primary line of defense is MT's built-in SpamLookup system. MTBL used to stop the spam before I saw it, now with 3.2 I see it in the 'Junk' list which I am forced to review frequently. Yes MT will auto-delete this queue, but I still get false-positives.

This is especially true for Trackbacks. It seems that every Trackback I get from TypePad hosted blogs does not make it through. The reason? The IP address of the trackback server does not match the IP address of the blog's domain. It seems like SixApart would have this covered since they wrote both pieces of software.

I have attempted to update the name of my .cgi files but the spam appears just as quickly again. When I say appear I mean in the junk area, so it never makes it to my blog, but it's still there. Since the name-change doesn't work anymore my theory is that there is another way to post trackbacks, perhaps via an API or the scrips have become smart enough to look-up the exact name of the .cgi script on your blog and then post away. My guess is the latter.

Anyway that's what I do for myself and all my clients. I also have a number of specific plugins for MovableType and some custom modifications I have created that make things like tagging very easy for the basic user.

Thank you for your expert insight on this, Josh. I'm in the middle of migrating from this ancient version of MT to the very latest, on a new, faster server, so I'll be able to add my own experiences in this regard soon enough.



Help others find this article at Del.icio.us, Digg, Netscape, Reddit, and Simpy.

Subscribe!

Never miss another useful Q&A article again! Subscribe to AskDaveTaylor with Google Reader.

Comments

What is the process of changing the name of mt-comments.cgi and mt-tb.cgi? I assume after changing the file names there will be changes that need to be made to the existing MT code.

Erik

Posted by: Erik Weibust at October 20, 2005 7:19 PM

When renaming scripts for comments and trackbacks (and others), you need to change the appropriate variable in mt-config.cgi (or mt.cfg before MT 3.2). These are CommentScript and TrackbackScript.

Posted by: Jack Vinson at October 20, 2005 11:02 PM

I have a lot to say, but ...
Starbucks coffee cup I have a lot to say, and questions of my own for that matter, but most of all I'd like to say thank you for all your efforts on this Web site by buying you a chai!

I do have a comment, now that you mention it!









Remember personal info?


Please note that I will never send you any unsolicited commercial email. Ever.

While I'm at it, please note that by submitting a question or comment you're agreeing to my terms of service, which are: you relinquish any subsequent rights of ownership to your material by submitting it on this site.









Uniblue: Free Virus Scan

Search
Find just the answers you seek from among our 1700+ free tech support articles by using our Lijit search engine.


Help!





Subscribe to
Ask Dave Taylor!

Add to Google Reader
Add to My Yahoo!
Subscribe in NewsGator Online

RDF   XML

Free Updates!
Sign up and get free weekly updates and special offers on books, seminars, workshops and more.


Recent Entries
Join the List!
Join my author info mailing list, where you'll learn about my upcoming books, speaking gigs, and more!


Book Links
© 2002 - 2008 by Dave Taylor. All Rights Reserved.

Note: This web site is for the purpose of disseminating information for educational purposes, free of charge, for the benefit of all visitors. We take great care to provide quality information. However, we do not guarantee, and accept no legal liability whatsoever arising from or connected to, the accuracy, reliability, currency or completeness of any material contained on this web site or on any linked site.

[whiteboard marker tray]