Eat more 403!
The LazyWeb is figuring out how to improve on my techniques, which is all to the good. Laurabelle has the latest; if you can help her with her current problem, please do (because I want the answer!).
She also has new additions to the list:
jmsimonr|middlecay|neweighweb|targetindustries| zalaszentgrot|zone-b51|
To which I add:
hasslerenterprises|bigyonet|gargzdai|1a1merchantaccounts| neweighweb|darkangelclan|mp-forum|
The pattern appears to be a lull of something like twelve to eighteen hours between a new attack of referrer spam with new domains. Is this a question of somebody losing access, or new instructions going out to the zombified PCs? I dunno.
By the way, I didn’t point this out last time, but it’s possible to turn the User-Agent trick into a 301 redirect as well. For the spammer above:
SetEnvIfNoCase User-Agent ".*(compatible; MSIE 6.0; Windows NT 5.2; .NET CLR 1.1.4322)" BadReferrer=yes
Nothing else need change, if you’ve already got a line denying bad referrers.
I am also within a week of banning NewzCrawler from CavLec altogether. The problem is that NewzCrawler incessantly looks for comment feeds on this site, despite their total nonexistence. I have 410ed and 403ed those feed URLs, but NewzCrawler totally refuses to get the hint—and worse, once it sees a post and surmises it should have a comment feed, it never stops looking for it. I have NewzCrawler users looking for comment feeds from every single post I’ve made since October 2004! This verges on DOSsy behavior.
The NewzCrawler developer is aware of this brokenness, as I’ve read a few different places, and he is also aware that server-log-aware bloggers don’t like it. His response has been “suck it up and deal; you don’t want to damage your readers just because they use my crap software, do you?”
Sorry, dude. I don’t want to punish them because of you, but I’m going to, because I don’t see any alternative given your attitude.
You NewzCrawler users? You have choices. You can figure out how to turn off the comment-feed-seeking, if NewzCrawler lets you do that. (If I see all those bogus hit-attempts disappear, I’ll call off the ban.) You can unsubscribe from CavLec. Or, if you still want to read CavLec, you can find a newsreader or aggregator that doesn’t suck. Totally up to you.
Otherwise, you’re gone a week from today. I’m serious. And you’ll continue to be gone until I see that NewzCrawler has a version out that fixes this bug, at which point I’ll allow the fixed version in.