Movable Type servers come tumbling down
By Adam Gaffin, NetworkWorld.com, 12/17/04
To paraphrase Charlton Heston: "Get your stinking paws off me, you damned dirty spammers."
Recent days have seen a growing crescendo of Movable Type servers either slowing to the point of unusability or being shut down by their hosts because of a couple of bugs in the way the latest version of Movable Type attempts to block spam in comments to posting - bugs that became evident only when spammers dramatically escalated the sheer volume of messages they try to post on MT systems (oh, for the days when comment spammers hand-posted their messages, instead of using zombie armies of Trojan-infested home computers to spew thousands of them).
Reid Stott offers an example:
"... I’ve had to restore permissions on MT for a friend who got shut down at Pair due to comment spam, and the server my site is on at TextDrive has been taken down (briefly) twice in the past week or so by thousands of MT processes run amuck. And we’re talking industrial strength web servers ...
A Boston blogger writes:
I had some trouble today - seems there was a Comment Spam attack, which caused my installation of MT and MTBLacklist to crash the hosting server.
So, my domains were suspended.
Help is on the way, according to Jay Allen, who wrote MT-Blacklist and who now works full time for Six Apart:
We are currently testing these fixes both in-house and with a number of web hosts who were among the first affected by the problem. We will have these fixes released to you as soon as the testing is complete. There is no higher priority to us than making sure that our customers and their websites are protected from the effects of these malicious attacks.
His note also explains the bugs, if you're interested.
TrackBack
Back to Compendium
Comments
Been there, done this. The spam recently has been coming in so fast (i.e. every 5-10 seconds), it causes a DOS-like attack on my webhost. It's incredible there are such inconsiderate people in the world.
To be honest, this fix is long overdue. It is well known that mt-comments is a CPU hog. I also wonder if these fixes will apply to MovableType 2.661, the last fully free version that is still the most popular version out there. Doesn't Compendium use MT as well?
Posted by: quanta on December 17, 2004 10:46 AM
Post a comment