Bee

Spam attack via mt-comments.cgi

Vote 0 Votes

Hi,

I'm about to exceed my bandwidth limit due to spam attack through the mt-comments.cgi script. Is there a way to prevent this? Looking at my stats it seems to be coming from China, I've blocked IPs already but it doesn't stop them from accessing my mt-comments.cgi script...

Any help would be appreciated! I'm about to delete my Movable Type setup... :o(

Reported on Movable Type 4.3

6 Replies

| Add a Reply
  • #1 Did you install TypePad AntiSpam?

    #2 Are you blocking IPs via MT's IP blocking or Apache?

  • Hi Mike,

    thanks for your reply!

    Yes TypePad is installed and I'm blocking thru both MT and Apache
    They seem to directly trigger mt-comments.cgi I temporarily renamed it and also disabled commenting but I'm still being attacked (keeping an eye on error log atm).

  • The real issue is your host here. What are they doing to help you?

    I don't know if you are aware of the full process for it, but you can actually tell Movable Type to point to the renamed CGI file like this in mt-config.cgi:

    CommentScript awfasjklflasfdjl.cgi

    Then republish your site and every reference to mt-comments.cgi will be replaced with awfasjklflasfdjl.cgi.

    As far as bandwidth goes, that's ridiculous. I would suggest looking for a host with a more liberal policy toward bandwidth. I use Hosting Matters. They've got a very stable environment and I almost never get hit with spam.

  • They've blocked about 30 IP addresses but that's it. I have no idea what else they could do except for blocking all traffic from China ;)

    Thanks for explaining those adjustments, really appreciate your help with this.

    Bandwidth: almost exceeded 10Gb since beginning of March when the problem started. I never had problems with this host before but might reconsider other options, thanks again for your help and advice! :)

  • You may like to also implement Captcha protection, either using the native captcha method from MT, or the reCaptcha plugin.

    Kind Regards,
    Mihai Bocsaru

    ----------------------------------
    Daily Movable Type Consultant

    Web Development
    Movable Type Consulting
    Six Apart Partner

    http://www.pro-it-service.com/
    ----------------------------------

    Movable Type Demo
    http://www.movabletypedemo.org/
    ----------------------------------

    Open Melody Demo
    http://www.openmelodydemo.org/

  • Is there a way to mark as spam/delete these in bulk? 200 at a time will take a REALLY long time. Not to mention I keep getting an error page.

Add a Reply

If you need to share template code, replace all the "<" signs with "&lt;" or use this utility.

Forum Groups

1774 6167

Last Topic: Template modules by Zielun on Feb 16, 2012

86 302

Last Topic: website entries by masoud on Oct 26, 2011

1434 5088

Last Topic: Maintenance announcement by Nick on Feb 17, 2012

695 2912

Last Topic: Insert Image / File Fails by Russ Miller on Feb 10, 2012

84 291

Last Topic: How to have some other characters in entry basename automatically written by Afshin Haghighatnia on Dec 22, 2011

174 740

Last Topic: Captcha images rendering slowly by ScottM on Feb 12, 2012

190 568

Last Topic: Analytics Reporting by michael webster on Feb 5, 2012

48 210

Last Topic: An idea and also a request by Afshin Haghighatnia on Jun 29, 2011

64 246

Last Topic: jQuery in MT 5.1 still at 1.4 - why? by perlmonkey on May 25, 2011

code.sixapart.com

137 478

Last Topic: Getting a thumbnail with xpath by Peter on Mar 13, 2011

222 720

Last Topic: Custom Field for Asset Not Appearing by android on Feb 9, 2012