Inside The Malicious World of Blog Comment Spam

Colin and I have been looking at some interesting blog comment spam for a while. This (rough) paper contains some of our results:

Abstract – This paper describes the code, behavior and infrastructure of a blog comment spam attack. The particular blog spam attack explained here uses HTTP/javascript obfuscation and redirection to pass the victims browser through several websites, ultimately infecting the victims host using a handful of exploits. This paper will also cover some of the techniques and tools used
in analyzing the attack.

We had a previous post about some of this before as well.



Excellent writeup guys. I

Excellent writeup guys. I forwarded it on to many guys on my team. Keep up the good work.