<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Contact Spam</title>
	<atom:link href="http://ma.tt/2004/09/contact-spam/feed/" rel="self" type="application/rss+xml" />
	<link>http://ma.tt/2004/09/contact-spam/</link>
	<description>Unlucky in Cards</description>
	<lastBuildDate>Sat, 26 May 2012 13:00:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4-beta4-20941</generator>
	<item>
		<title>By: Tibo</title>
		<link>http://ma.tt/2004/09/contact-spam/#comment-46924</link>
		<dc:creator>Tibo</dc:creator>
		<pubDate>Fri, 03 Feb 2006 14:29:56 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2004/09/28/contact-spam/#comment-46924</guid>
		<description>A bit of documentation + solution

http://www.anders.com/cms/75/Crack.Attempt/Spam.Relay

http://www.anders.com/projects/sysadmin/formPostHijacking/

http://ryanduff.net/?p=369</description>
		<content:encoded><![CDATA[<p>A bit of documentation + solution</p>
<p><a href="http://www.anders.com/cms/75/Crack.Attempt/Spam.Relay" rel="nofollow">http://www.anders.com/cms/75/Crack.Attempt/Spam.Relay</a></p>
<p><a href="http://www.anders.com/projects/sysadmin/formPostHijacking/" rel="nofollow">http://www.anders.com/projects/sysadmin/formPostHijacking/</a></p>
<p><a href="http://ryanduff.net/?p=369" rel="nofollow">http://ryanduff.net/?p=369</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: EoN604</title>
		<link>http://ma.tt/2004/09/contact-spam/#comment-43740</link>
		<dc:creator>EoN604</dc:creator>
		<pubDate>Mon, 23 Jan 2006 00:13:59 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2004/09/28/contact-spam/#comment-43740</guid>
		<description>Captchas ARE a perfectly acceptable solution.  As the administrator of a very busy forum, my contact page gets absolutely flooded with spambot messages.  I suspect that the people complaining about Captchas are people who have never been on the receiving end of spam such as this.

More importantly, and quite simply, you won&#039;t find any more effective solution than Captchas.</description>
		<content:encoded><![CDATA[<p>Captchas ARE a perfectly acceptable solution.  As the administrator of a very busy forum, my contact page gets absolutely flooded with spambot messages.  I suspect that the people complaining about Captchas are people who have never been on the receiving end of spam such as this.</p>
<p>More importantly, and quite simply, you won&#8217;t find any more effective solution than Captchas.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Farheen</title>
		<link>http://ma.tt/2004/09/contact-spam/#comment-14551</link>
		<dc:creator>Farheen</dc:creator>
		<pubDate>Wed, 02 Feb 2005 11:45:04 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2004/09/28/contact-spam/#comment-14551</guid>
		<description>I don&#039;t understand, what&#039;s the problem with the please type in the code image verification thing.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t understand, what&#8217;s the problem with the please type in the code image verification thing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephan Segraves</title>
		<link>http://ma.tt/2004/09/contact-spam/#comment-7720</link>
		<dc:creator>Stephan Segraves</dc:creator>
		<pubDate>Thu, 30 Sep 2004 17:45:18 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2004/09/28/contact-spam/#comment-7720</guid>
		<description>Matt,

Have you thought about something along the lines of what you use to stop comment spam? When someone uses the form store their IP and timestamp in a temporary table (for a couple of hours) and if they try to contact you a certain amount of times in that given time period they are turned away. I guess the only downside to this would be legitimate users trying to contact you a lot.

&lt;a href=&quot;http://simon.incutio.com&quot; title=&quot;Simon Willison&quot;&gt;Simon&lt;/a&gt; does something interesting by having a form reveal his actual e-mail address. That&#039;s always an option I guess.</description>
		<content:encoded><![CDATA[<p>Matt,</p>
<p>Have you thought about something along the lines of what you use to stop comment spam? When someone uses the form store their IP and timestamp in a temporary table (for a couple of hours) and if they try to contact you a certain amount of times in that given time period they are turned away. I guess the only downside to this would be legitimate users trying to contact you a lot.</p>
<p><a href="http://simon.incutio.com" title="Simon Willison">Simon</a> does something interesting by having a form reveal his actual e-mail address. That&#8217;s always an option I guess.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Burkhardt</title>
		<link>http://ma.tt/2004/09/contact-spam/#comment-7717</link>
		<dc:creator>Chris Burkhardt</dc:creator>
		<pubDate>Thu, 30 Sep 2004 05:30:02 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2004/09/28/contact-spam/#comment-7717</guid>
		<description>The way to make graphical captchas more accessible is to offer an audible alternative... but still not a very friendly solution.</description>
		<content:encoded><![CDATA[<p>The way to make graphical captchas more accessible is to offer an audible alternative&#8230; but still not a very friendly solution.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Simon</title>
		<link>http://ma.tt/2004/09/contact-spam/#comment-7708</link>
		<dc:creator>Simon</dc:creator>
		<pubDate>Wed, 29 Sep 2004 12:11:47 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2004/09/28/contact-spam/#comment-7708</guid>
		<description>Image based captchas (&quot;type the number or word you see in the image above&quot;) are not an acceptable solution. 

They aren&#039;t accessible, and if you make them accessible with an alt tag you lose the advantage. They&#039;re also a big &lt;acronym title=&quot;pain in the arse&quot;&gt;pita&lt;/acronym&gt;.</description>
		<content:encoded><![CDATA[<p>Image based captchas (&#8220;type the number or word you see in the image above&#8221;) are not an acceptable solution. </p>
<p>They aren&#8217;t accessible, and if you make them accessible with an alt tag you lose the advantage. They&#8217;re also a big <acronym title="pain in the arse">pita</acronym>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Wubben</title>
		<link>http://ma.tt/2004/09/contact-spam/#comment-7707</link>
		<dc:creator>Mark Wubben</dc:creator>
		<pubDate>Wed, 29 Sep 2004 10:40:34 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2004/09/28/contact-spam/#comment-7707</guid>
		<description>On a contact form you don&#039;t care about manual spam, it&#039;s just a funky e-mail. Spambots which post to the form directly will probably not do anything with the content you return. So, you could send out a unique hash every hour, if users wait too long to submit the form you can let them resubmit it with a new hash. Spambots won&#039;t resubmit, nor is the chance big that they&#039;ll have the unique value, as it changes often.

(Yes, this is very similar to the idea posted in the hackers mailing list some days ago.)</description>
		<content:encoded><![CDATA[<p>On a contact form you don&#8217;t care about manual spam, it&#8217;s just a funky e-mail. Spambots which post to the form directly will probably not do anything with the content you return. So, you could send out a unique hash every hour, if users wait too long to submit the form you can let them resubmit it with a new hash. Spambots won&#8217;t resubmit, nor is the chance big that they&#8217;ll have the unique value, as it changes often.</p>
<p>(Yes, this is very similar to the idea posted in the hackers mailing list some days ago.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ayush</title>
		<link>http://ma.tt/2004/09/contact-spam/#comment-7702</link>
		<dc:creator>Ayush</dc:creator>
		<pubDate>Wed, 29 Sep 2004 01:40:56 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2004/09/28/contact-spam/#comment-7702</guid>
		<description>Try implementing this:
http://www.devshed.com/c/a/PHP/Security-Images-in-PHP/

It asks the user to type in what is displayed in a randomly generated image. Make it generate a two-letter word (small enough so people don&#039;t get irritated) and say goodbye to the bots.</description>
		<content:encoded><![CDATA[<p>Try implementing this:<br />
<a href="http://www.devshed.com/c/a/PHP/Security-Images-in-PHP/" rel="nofollow">http://www.devshed.com/c/a/PHP/Security-Images-in-PHP/</a></p>
<p>It asks the user to type in what is displayed in a randomly generated image. Make it generate a two-letter word (small enough so people don&#8217;t get irritated) and say goodbye to the bots.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dale</title>
		<link>http://ma.tt/2004/09/contact-spam/#comment-7701</link>
		<dc:creator>Dale</dc:creator>
		<pubDate>Wed, 29 Sep 2004 00:20:46 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2004/09/28/contact-spam/#comment-7701</guid>
		<description>Tried to send a trackback here but it failed. Not sure if it is my problem or here :&#124;

Anyway:
http://blog.dalegroup.net/archive/blog/newsid/142</description>
		<content:encoded><![CDATA[<p>Tried to send a trackback here but it failed. Not sure if it is my problem or here <img src='http://s.ma.tt/blog/wp-includes/images/smilies/icon_neutral.gif' alt=':|' class='wp-smiley' /> </p>
<p>Anyway:<br />
<a href="http://blog.dalegroup.net/archive/blog/newsid/142" rel="nofollow">http://blog.dalegroup.net/archive/blog/newsid/142</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://ma.tt/2004/09/contact-spam/#comment-7697</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Tue, 28 Sep 2004 22:51:23 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2004/09/28/contact-spam/#comment-7697</guid>
		<description>Danny, the contact form goes to a whitelisted address that skips my spam filters specifically for people who are having trouble getting through otherwise. I&#039;ve been getting so much spam lately my filters have become much more aggressive.</description>
		<content:encoded><![CDATA[<p>Danny, the contact form goes to a whitelisted address that skips my spam filters specifically for people who are having trouble getting through otherwise. I&#8217;ve been getting so much spam lately my filters have become much more aggressive.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeff Minard</title>
		<link>http://ma.tt/2004/09/contact-spam/#comment-7696</link>
		<dc:creator>Jeff Minard</dc:creator>
		<pubDate>Tue, 28 Sep 2004 22:28:41 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2004/09/28/contact-spam/#comment-7696</guid>
		<description>Captcha&#039;s are annoying. Perhaps you could so something like include a timestamp on the generation of the form in a hidden field. This way you can say, if the form submission is older than 5-10 minutes, you could then present a captcha to the user to verify the submission.

This would be countered in the future, but it would last well for a time. :D

You could also try an array of rotating field names, or tying the fieldname in with a date/time stamp, etc etc.</description>
		<content:encoded><![CDATA[<p>Captcha&#8217;s are annoying. Perhaps you could so something like include a timestamp on the generation of the form in a hidden field. This way you can say, if the form submission is older than 5-10 minutes, you could then present a captcha to the user to verify the submission.</p>
<p>This would be countered in the future, but it would last well for a time. <img src='http://s.ma.tt/blog/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p>You could also try an array of rotating field names, or tying the fieldname in with a date/time stamp, etc etc.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Benjamin</title>
		<link>http://ma.tt/2004/09/contact-spam/#comment-7695</link>
		<dc:creator>Benjamin</dc:creator>
		<pubDate>Tue, 28 Sep 2004 22:25:36 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2004/09/28/contact-spam/#comment-7695</guid>
		<description>The random image would deter visitors, at least on the comment form. It might be a good idea for the contact form, though.</description>
		<content:encoded><![CDATA[<p>The random image would deter visitors, at least on the comment form. It might be a good idea for the contact form, though.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Narada</title>
		<link>http://ma.tt/2004/09/contact-spam/#comment-7694</link>
		<dc:creator>Narada</dc:creator>
		<pubDate>Tue, 28 Sep 2004 20:17:42 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2004/09/28/contact-spam/#comment-7694</guid>
		<description>I&#039;m probably stating or restating the obvious here.  Have a random image the text of which must be typed in to use the form.  This would be good for the wordpress comment forms as well.  What do you think of this solution?</description>
		<content:encoded><![CDATA[<p>I&#8217;m probably stating or restating the obvious here.  Have a random image the text of which must be typed in to use the form.  This would be good for the wordpress comment forms as well.  What do you think of this solution?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Danny Howard</title>
		<link>http://ma.tt/2004/09/contact-spam/#comment-7693</link>
		<dc:creator>Danny Howard</dc:creator>
		<pubDate>Tue, 28 Sep 2004 19:27:34 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2004/09/28/contact-spam/#comment-7693</guid>
		<description>Well, I get the impression this form sends an e-mail.

Which goes through e-mail.

Which goes through you spam filter.

Which filters out spam.

Which begs the question: who cares?

-danny</description>
		<content:encoded><![CDATA[<p>Well, I get the impression this form sends an e-mail.</p>
<p>Which goes through e-mail.</p>
<p>Which goes through you spam filter.</p>
<p>Which filters out spam.</p>
<p>Which begs the question: who cares?</p>
<p>-danny</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sara</title>
		<link>http://ma.tt/2004/09/contact-spam/#comment-7692</link>
		<dc:creator>Sara</dc:creator>
		<pubDate>Tue, 28 Sep 2004 19:20:09 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2004/09/28/contact-spam/#comment-7692</guid>
		<description>I&#039;m sorry that&#039;s happening to you Matt. I have been lucky with my contact form so far!</description>
		<content:encoded><![CDATA[<p>I&#8217;m sorry that&#8217;s happening to you Matt. I have been lucky with my contact form so far!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Abe</title>
		<link>http://ma.tt/2004/09/contact-spam/#comment-7691</link>
		<dc:creator>Abe</dc:creator>
		<pubDate>Tue, 28 Sep 2004 18:04:05 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2004/09/28/contact-spam/#comment-7691</guid>
		<description>Hi Matt,

I&#039;m curious: What do you see in the referer and user-agent fields of your access logs for spammer posts?  Are they posting with some kind of bot, or are they manually entering the spam?

One preventative measure would be to verify that the referer page is what you expect - but of course this wouldn&#039;t work if they&#039;re actually visiting the page with a browser and hand pasting their message.

Abe</description>
		<content:encoded><![CDATA[<p>Hi Matt,</p>
<p>I&#8217;m curious: What do you see in the referer and user-agent fields of your access logs for spammer posts?  Are they posting with some kind of bot, or are they manually entering the spam?</p>
<p>One preventative measure would be to verify that the referer page is what you expect &#8211; but of course this wouldn&#8217;t work if they&#8217;re actually visiting the page with a browser and hand pasting their message.</p>
<p>Abe</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bryan</title>
		<link>http://ma.tt/2004/09/contact-spam/#comment-7689</link>
		<dc:creator>Bryan</dc:creator>
		<pubDate>Tue, 28 Sep 2004 17:23:03 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2004/09/28/contact-spam/#comment-7689</guid>
		<description>Could you perhaps create &lt;a href=&quot;http://www.btvillarin.com/contact.php&quot;&gt;a self-contained PHP contact form&lt;/a&gt;? On my main site, I haven&#039;t gotten hit. Sorry if you&#039;ve already tried that - I&#039;m just throwin&#039; stuff out. :)</description>
		<content:encoded><![CDATA[<p>Could you perhaps create <a href="http://www.btvillarin.com/contact.php">a self-contained PHP contact form</a>? On my main site, I haven&#8217;t gotten hit. Sorry if you&#8217;ve already tried that &#8211; I&#8217;m just throwin&#8217; stuff out. <img src='http://s.ma.tt/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Moncur</title>
		<link>http://ma.tt/2004/09/contact-spam/#comment-7688</link>
		<dc:creator>Michael Moncur</dc:creator>
		<pubDate>Tue, 28 Sep 2004 17:17:49 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2004/09/28/contact-spam/#comment-7688</guid>
		<description>This happens to me occasionally with my various contact forms. Spammers aren&#039;t known for their brains, and apparently they think their message is reaching more than just me.

Once a spammer gets a hold of one, I change the names of the scripts and variables and they disappear. Sometimes I have to change the URL. In those cases it usually means I&#039;ve showed up on a Google search for something like &quot;contact&quot; or &quot;send email&quot;.

I suppose it won&#039;t be long before we start seeing CAPTCHAS on personal contact forms...</description>
		<content:encoded><![CDATA[<p>This happens to me occasionally with my various contact forms. Spammers aren&#8217;t known for their brains, and apparently they think their message is reaching more than just me.</p>
<p>Once a spammer gets a hold of one, I change the names of the scripts and variables and they disappear. Sometimes I have to change the URL. In those cases it usually means I&#8217;ve showed up on a Google search for something like &#8220;contact&#8221; or &#8220;send email&#8221;.</p>
<p>I suppose it won&#8217;t be long before we start seeing CAPTCHAS on personal contact forms&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Wubben</title>
		<link>http://ma.tt/2004/09/contact-spam/#comment-7687</link>
		<dc:creator>Mark Wubben</dc:creator>
		<pubDate>Tue, 28 Sep 2004 16:57:05 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2004/09/28/contact-spam/#comment-7687</guid>
		<description>Which means we need a general solution for POST request spam.

Interesting.</description>
		<content:encoded><![CDATA[<p>Which means we need a general solution for POST request spam.</p>
<p>Interesting.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

