Chinese LED Trac spam.
May 10th, 2006
There’s a Chinese spammer out there Googling for Trac projects he can submit junk bugs to. The bugs contain page after page of advertising text for a website selling commercial-grade LED displays. The following is from my access_log, showing that this guy manually searches around for Trac ticket submission forms, then fires away.
61.48.126.237 - - [10/May/2006:10:00:24 -0500] "GET /project/report/6 HTTP/1.1" 200 107783 "http://www.google.cn/search?q=NEW+TICKET+Trac&hl=zh-CN&lr=&newwindow=1&start=990&sa=N&filter=0" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
…
61.48.126.237 - - [10/May/2006:10:00:44 -0500] "GET /project/newticket HTTP/1.1" 200 15998 "http://trac.feedtree.net/project/report/6" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
…
61.48.126.237 - - [10/May/2006:10:04:12 -0500] "POST /project HTTP/1.1" 302 14 "http://trac.feedtree.net/project/newticket" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
The spam text, which is entered in every possible field in the bug form, is Chinese (“LED显示屏”, and on and on); it translates to the usual list of key phrases: “color led display, double base color led display, outdoor led display, indoor led display, …” I’ve gotten 4 or 5 of these junk tickets now. Congratulations, 61.48.126.237, you’re the proud recipient of a new deny from rule!
One response
I’m getting the same exact thing in two of my public trac instances. This guy is really annoying. Thanks for the tip!
comment posted at 4:16 am on 02 Jun 2006