Warning: The death of anonymous commenting on popular weblogs

keywords:

Clancy's Drupal site, CultureCat, is down right now because comment spammers have effectively committed a DoS attack against the server. So many spam bots were attempting to post anonymous comments that the entire server hosted by OpenSourceHost was being taken down. For the time being, OSH has had to block access to her domain until the wave of spamming dies.

In the meantime, we have turned off anonymous commenting and the spam module on Clancy's site in anticipation of when it comes back up. It seems that anonymous commenting is done for any popular weblog if this is the end result. After all, no amount of spam blocking can stop a massive DoS attack from spammers.

Other Drupal and similar weblog application users may want to watch out for this. For the last few days, Clancy was having to delete a few thousand comment spams per day. Apparently that number accelerated upward today. Comment spam from IP addresses in the hundreds according to the server logs. If you find you are getting ever increasing comment spam and reaching those limits, probably time to turn off anonymous commenting or risk taking down your whole host and losing complete access to your site for a few days waiting for the spammers to give up.

Short of blocking IP addresses in Apache based on some shared blacklist between servers, I can't imagine any easy workaround to save anonymous commenting unless there is a Drupal configurable throttle function for comments. Even then, this would prevent anyone else from posting comments.