Merchant Account Forum

Site Zones >>> | Home | Top Merchant Account Recommendations | Merchant Account Reviews | Merchant Account Articles | Merchant Account Updates | Selecting The Right Merchant Account | Newsletter | Discussion Forum | Merchant Account Affiliate Programs | Contact Us | About Us | Recommended Resources | Links |
Join our free newsletter >>>Your Name: Your Email: [ more info ]

My Top Merchant Account Providers

Best All-In-One Ecommerce Package

Best Shopping Cart

Best US Merchant Account

Best International Merchant Account

Best UK Merchant Account

If you don't mind the limitations of third-party UK merchant account services there are still options to accept payments in £sterling.

Best Third Party Merchant Account

Best Casino/Gaming Merchant Account

Best Adult Merchant Account

Best Travel Merchant Account

[Not sure sure which of these internet merchant accounts you need? ]

Most Visited Merchant Account Articles

After 5 years of searching, what I believe is the absolute best International merchant account provider available

Merchant account fee calculator

Problems with merchant accounts for non-US merchants

Read about our favourite shopping cart and business automation software, and why we're using it ourselves for our newest site

The easiest, cheapest way to run an affiliate program if you're based outside the USA

Accept credit cards on your site in the next 15 minutes with this great 3rd party credit card processing company

The complete introduction to online merchant accounts

Totally new to ecommerce? Then check out this amazing value all-in-one package

New - Merchant account ebook review center

The mechanics of making and selling an ebook for profit

Understanding the terminology used by merchant account providers

Maximizing the success of your affiliate program for Clickbank merchants

My experiences as a Paypal merchant

Discover which autoresponder I use month after month to boost sales without lifting a finger

Looking for top value? What extra merchant product services can you find for your money?

New Spam Threat Hits 90,000 Sites - Is Yours Next?

On Tuesday I received 423 emails from an unknown spammer attacking my site.

On Wednesday I received 789 emails from the same spammer.

Action had to be taken.

The emails were copies of posts to my discussion forum - the typical spammers posts - keyword stuffing, numerous hyperlinks to junk sites crammed with even more keywords.

It was clear I was being hit by one spammer, with an automated script, for a number of telltale reasons:

1) Nobody could post 789 posts to a forum in 24 hours manually

2) All posts were from random .co.za email addresses (South African domains, but likely false)

3) All posts pointed to very similar spammy sites obviously made with the same auto-generation software

4) Checking various domains promoted within these posts in WHOIS showed they were all owned by a certain guy in Paris

I carefully combed my forum for these junk posts but couldn't see anything out of the ordinary. So I checked for posts by .co.za email addresses, or French IPs but couldn't see a problem anywhere.

Where were they coming from, and where were the posts?

To help me in my quest I did a search on Google for the text that began every email which read:

"The following was posted in the on

But couldn't find any links that were any help.

So next I investigated the content of the emails for common factors and found the following Javascript snippet began every message body:

"var defDoor"... before launching into other Javascript elements, followed by the keywords and links.

I wonder...

A quick search on Google and two factors astonished me...

1) Google showed up 92,600 pages with this code on, of which every one I checked matched the exact spam posts I was seeing in style and content. So we were dealing with a professional of some magnitude.

2) They were all on forums, but not the one I used, but WWWBoard as available from http://www.scriptarchive.com/wwwboard.html

A quick search with my FTP software through the bowels of my admittedly large site that has been online for 5 years or so and has seen more reworkings than Pamela Anderson showed I *had* got WWWBoard installed on my site but had stopped using it years ago in place of my current forum software.

I had completely forgotten about it, and there were the hundreds of spam posts sitting there on my server!

Obviously I don't use the script so instantly deleted it and the spamming stopped dead overnight but if I'm one of over 90,000 victims this guy has duped then a little advice is necessary:

1) Appreciate that there are security floors to WWWBoard and you either need to watch your forum very carefully or consider switching to another script.

2) Don't leave old scripts sitting around on your server waiting for spammers to abuse them. Use them, or delete them.

3) Try to avoid using obvious folders for scripts. Whilst I didn't link to my old forum from anywhere on the site, it was in an obvious folder so a spammer (or a script) could easily have guessed it.

4) Realise that security threats are very real if you get reasonable traffic and take steps *in advance* to minimize the risk to your own site.

=======================================================
Richard Adams is the founder of Merchant Account Forum, one of the net's most popular merchant account advice sites.
=======================================================

Privacy Policy | Site Map


| UK Merchant Accounts | International Merchant Accounts |
| US Merchant Accounts | NY Merchant Accounts |
| Online Merchant Accounts | Internet Merchant Accounts |

© 2001 - 2005
MerchantAccountForum.com
All rights reserved.

Merchant Account Freebies

For Business Owners...

Free Ebook - Answers To 44 Real-Life Merchant Account Questions

Free Merchant Account "Buy Now" Buttons To Spice Up Your Site

Free Dynamic Content To Attract The Search Engines - Get Regularly Updated Information Straight To Your Site On The Subject Of Merchant Accounts

Free Articles You Can Reprint At Your Site And Profit From

Get A Free Link From Our High-Traffic Site

Join Our Free Monthly Business-Building Newsletter

For Payment Processing Companies...

Join Our Merchant Account Advisor Committee