dionidium.com

Wayne Burkett's Weblog | Home

You've Been Hit by Reffy!
03:51PM CST December 04, 2004 | Comments [7]

Reffy is a Windows referrer spammer by the fine folks -- bored teenager? -- at AdminShop. Reffy comes pre-loaded with the addresses of over 3000 blogs, one of which, considering recent spam I've received pointing to the AdminShop site, is doubtless mine. They're also responsible for a dubious SEO tool (gauge the "competitivity" of specific search terms) and a mass URL dumper (spread your influence to the "farest reaches of the internet").

On a lighter note, there's Daily Content, a dynamic content generator that lends "professionality to your site." It comes with a collection of "Yo Yama" jokes to get you started. Professionality.

This is really just an excuse to complain about referrer spam and point anyone interested toward my public referrer blacklist, which just got a few domains longer thanks to this unfortunate tool. I recognize that I'm probably shooting myself in the foot by linking to the misguided fools responsible for my spam problem, but pretending they don't exist isn't much of a strategy, either.

#1 | 11:49PM UTC December 04, 2004 | Jonathan M. Hollin
Jonathan M. Hollin

They keep popping up on my referrer logs too. They seem to be using at least two domain names: adminshop.com and xopy.com.

I've started bouncing their requests back to their own domains with a couple of mod_rewrite rules, so I shouldn't see them again unless they're using other domain names too.

#2 | 11:03PM UTC December 05, 2004 | Jacques Distler
Jacques Distler

Hmmm. These Adminshop guys seem pretty mild-mannered compared to the referer-spammers I've been seeing. They use hordes of zombie PCs, and, apparently, some anonymous proxies as well. And they do GETs, rather than HEADs.

I've had to be correspondingly ... ahem... harsher in my response.

#3 | 07:52PM UTC December 06, 2004 | Wayne
Wayne

Jacques, it's true, the AdminShop group is comparatively tame. I've been hit by a referrer from xopy.com twice in three days. Two isn't better than zero, but it could definitely be worse. (I'm slightly more worried about potentially less scrupulous spammers who might shell out the $50 for Reffy and distribute their attack in the way you describe.)

For what it's worth, I'm also aware that a blacklist is a pretty terrible solution to the spam problem, but it does at least keep my public referlog reasonably perversion-free and a heck of a lot less noisy. This second point is important because I still use referrers the old-fashioned way: as a poor man's trackback.

#4 | 10:30AM UTC December 07, 2004 | Kathy K
Kathy K
I figure we should all link them. Maybe get them enough hits to eat up their bandwidth. I've been blocking the referers through htaccess. Some people I 'help out' have been getting some major spam (hitting all the archives) with a bunch of referers ending in '.info'. (Not Reffy... this lot is downloading all the text on the page.) Keep an eye out for them. Things like: http://www.air-travel-e-site.info/ I've been blocking with regex because they have a lot of 'e-site.info' and 'esite.info' and '4u.info' and so forth.
#5 | 03:19PM UTC December 09, 2004 | Tuxedo Jack
Tuxedo Jack

I've been hit hard too - about thirty or forty shots a month, and I've gone up against Odin personally on my board and (I think) won.

As is, I'm forced to use .htaccess to block, and it doesn't really do anything for Reffy.

I hadn't known Xopy was part of it; that explains their showing up in my logs.

As is, can this be considered UCC under the CAN-SPAM act, as we've had no business contact with them?

#6 | 09:45PM UTC December 09, 2004 | Wayne
Wayne

I'd like to share with everyone this nugget of advice from the creator of Reffy (culled from Tuxedo Jack's fora):

By the way, if you don't want my bot to visit you, learn how to use htaccess.

I've also added the domains in this list of AdminShop properties to my blacklist.

#7 | 01:10AM UTC May 04, 2005 | KimmoA
KimmoA
*pretends that this is an automated message but can't get his dirty paws on Reffy*