Coping with spam from China

Ralph Ritoch

If you have ever had a WordPress MU, WordPress Multi User, site using buddypress than you will quickly discover that there is software being used in China to automatically locate and spam wordpress multi-user sites.  Within a month you’ll have thousands of users, blogs, and posts, but it will all be spam.  At first I tried deleting the spammers using Wang Guard which was a decent application but the amount of spam was still too much for my little VPS to handle.  I was then able to determine two Class B networks where most of the spam was coming from (175.42 and 175.44). I blocked them with my firewall and that worked for a few days but the spammers simply changed their IP addresses.  I also reported the attack to the ISP who didn’t even have the decency to respond to the complaint.  At this point I realized that WordPress MU with Buddypress is simply too much of a resource hog for creating a multi-user blog site so I decided to shut down the site all together, but first I wanted to put an end to these attackers.

At first I thought I’d send the spammers to whitehouse.gov but I didn’t want to create an international conflict so I did the next best thing. I changed the IP address of my blog site to a government web site in Beijing using WHM DNS settings.  After making the change, and rebooting, my server became immediately responsive again.  Now this is how you deal with these spammers!  Trick the hackers software into having their attack go to their own government.  Chinese government officials may give these hackers a death sentence, but that isn’t my problem.  These hackers have accepted that risk by attacking MY SITE!

To all you hackers reading this, let me tell you, the next time you pull this I won’t be so kind, if a simple DNS change won’t work than I can simply set my firewall to change the destination address to the Chinese government and increase the TTL and there is NOTHING you can do about it.  Attack my sites and be prepared to lose everything!