All of a sudden I am getting lots of spammers using my Drupal 6.9 website contact/feedback form to send me messages containing strange links, e.g.:

Bhxr6W <a href="http://ufnqrmcqzcfi.com/">ufnqrmcqzcfi</a>, [url=http://doagwlxaljff.com/]doagwlxaljff[/url], [link=http://yykufvzoevkl.com/]yykufvzoevkl[/link], http://qtnbmsqbwgxk.com/

What are they trying to achieve by this? And what should I be doing to prevent it?

Tony

Comments

nagarajanl’s picture

I am not sure whats going on here...but add spam prevention modules like mollom or captcha to protect further attacks

skwashd’s picture

Status: Active » Closed (works as designed)

This was also posted on gdo - http://groups.drupal.org/node/119944

It looks likes standard spam bot behaviour. They're simply trying to build inbound links. The 3 formats of the URL should work with sites allowing HTML, phpBB or ones which automagically turn URLs into links. In other words they're using a scatter gun approach to make sure they get at least one working link on your site. The bot doesn't really know if it is targeting a contact form or comment form.

As suggested here and on gdo, install an anti spam module such as Mollom.

Please upgrade to the latest stable release to ensure your site is secure. 6.9 is very old and has quite a few known security issues.

kp52’s picture

I get this sort of stuff on contact forms as well, and I have the same question. It's all very well to say what you can do to block the comments - personally I find rejecting anything with "[url" or "http" in the body works very well; even if you want to allow submission of URLs, most humans quote addresses as www.example.com. But the URLs in these junk posts don't seem to be valid - the ones quoted in the OP are not registered, hence it's pointless trying to build inbound links to them.

So what is the spammer's purpose? What do they gain if someone clicks one of these links?
KP

Later: After a bit of googling, I have found a plausible answer - it's to foil stats in spam blockers like SpamAssassin. See http://ezinearticles.com/?Gibberish-Spam-Email---Why-Do-Spammers-Send-It...