Results 1 to 7 of 7
  1. #1
    Join Date
    Feb 2007
    Location
    Florida
    Posts
    1,932

    Question What to do about illegal links from spam bots for users?

    I've got one particular user who runs a blog, and one day my automated file scanner detected a file containing hundreds of links to illegal content (lets just say the word "preteen" appears a lot). I checked the file out and it appears to be a .txt file of all of the comments made to their blog. I have gone through and manually deleted the comments (which are made by spambots) but the next day the same links appear in the same file but from a different bot. This has been going on for the past 8 days and the user has taken no action to prevent this same bot from returning each day.

    I decided to delete comments and chmod the directory to read only to prevent further writes to the file but at what point should the user be held accountable for the illegal links on their account created by spam? I can understand that it's not the user's fault the links are being posted publicly on their site, but they have not taken any action to either remove the spam comments or prevent the spam from continuing.

    The way I see it is regardless if it's being done purposely or not the fact that I have links to illegal content on my server puts both my company, my hardware, and my datacenter at risk. So, as a host, what would you do in my situation? Now consider this user was using your services for free, would your actions be any different? Should I wait for my datacenter or law enforcement to contact me before taking further action?
    -Joe @ Secure Dragon LLC.
    + OpenVZ Powered by Wyvern | KVM | cPanel Hosting | Backup VPSs | LowEndBoxes | DDOS Protection
    + Florida | Colorado | Illinois | California | Oregon | Georgia | New Jersey | Arizona | Texas

  2. #2
    Join Date
    Sep 2007
    Posts
    1,018
    I would be first interested to see if the user is still using and updating the website. Free users seem to just disappear, never to return. Admittedly, I probably have a few free hosting accounts around from "back in the day".

    But in this situation, I think the action you have taken is acceptable in that you are stopping the illegal links from being posted, but still keeping the website online for your user. I would probably find myself hovering over the terminate button, only because he does not seem to monitor his website at all, let alone update it and as you said, its placing a lot of people at risk if the content stays online.

  3. #3
    Join Date
    Feb 2007
    Location
    Florida
    Posts
    1,932
    Well right now the main site has a "under construction" page. Prior to that though the site was getting daily traffic and the user was blogging almost daily. I'm assuming that because the site is under construction they are no longer monitoring their comments but I have sent numerous notices to them about this.
    -Joe @ Secure Dragon LLC.
    + OpenVZ Powered by Wyvern | KVM | cPanel Hosting | Backup VPSs | LowEndBoxes | DDOS Protection
    + Florida | Colorado | Illinois | California | Oregon | Georgia | New Jersey | Arizona | Texas

  4. #4
    Join Date
    Sep 2007
    Posts
    1,018
    In my opinion I believe you have done all you need to do. If and when the user starts using/monitoring their website again, they may notice no one can leave comments and will contact you, but until then the website is otherwise online.

  5. #5
    Have you installed a SPAM comment filter yet? I had the same problem with some of my blogs and the spam filters stopped 99% of the comments as soon as I added them.

    If you are on WordPress, you can use TanTanSpamNoodles
    Download my eBook + Videos: Starting your own successful web hosting company.
    Learn from a web host with 7 years of experience.

  6. #6
    Join Date
    Oct 2007
    Location
    KS
    Posts
    35
    Quote Originally Posted by JWeb2 View Post
    Should I wait for my datacenter or law enforcement to contact me before taking further action?
    No one will contact you because you took down the links and stopped more from being generated, and because abandoned sites filled with spam are common enough they don't generate a lot of interest.

    if you no longer want to host the abandoned, free blog account because it's more trouble than it's worth is certainly your call. it would be easy enough to let people know that inactive free accounts will be deleted after a certain time and give them the opportunity to respond. that's probably what i'd do to avoid the headache in the future with others as well.

  7. #7
    Join Date
    Feb 2007
    Location
    Florida
    Posts
    1,932
    Quote Originally Posted by goddess_dix View Post
    No one will contact you because you took down the links and stopped more from being generated, and because abandoned sites filled with spam are common enough they don't generate a lot of interest.

    if you no longer want to host the abandoned, free blog account because it's more trouble than it's worth is certainly your call. it would be easy enough to let people know that inactive free accounts will be deleted after a certain time and give them the opportunity to respond. that's probably what i'd do to avoid the headache in the future with others as well.
    It's not abandoned though, the user was making regular updates until they decided to redesign the site.

    Quote Originally Posted by dbbrock1 View Post
    Have you installed a SPAM comment filter yet? I had the same problem with some of my blogs and the spam filters stopped 99% of the comments as soon as I added them.

    If you are on WordPress, you can use TanTanSpamNoodles
    I'm not going to start installing plugins on user's sites.
    -Joe @ Secure Dragon LLC.
    + OpenVZ Powered by Wyvern | KVM | cPanel Hosting | Backup VPSs | LowEndBoxes | DDOS Protection
    + Florida | Colorado | Illinois | California | Oregon | Georgia | New Jersey | Arizona | Texas

Similar Threads

  1. spam bots and RSS feeds
    By marcnyc in forum Web Hosting Lounge
    Replies: 3
    Last Post: 01-10-2009, 12:19 AM
  2. Spam Bots?
    By J.M.C in forum Hosting Security and Technology
    Replies: 4
    Last Post: 08-18-2007, 10:47 AM
  3. Spam Bots?
    By Anky in forum Web Design and Content
    Replies: 21
    Last Post: 05-24-2005, 08:57 PM
  4. SSH & Illegal Users
    By mainarea in forum Hosting Security and Technology
    Replies: 17
    Last Post: 08-09-2004, 10:11 AM
  5. Illegal or?. (links?)
    By ned patter in forum Web Hosting Lounge
    Replies: 16
    Last Post: 08-15-2002, 10:23 AM

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •