He has spammed my site a few times now, I have removed the spam and tried to backtrack him for abuse reports...
He think he spammed me from although he masks his spam from many different IP's, I see some strange behaviour from another IP in the apache log.
this is an excerpt from ONE spam post... - - [20/Jun/2007:03:55:45 +0200] "GET /modules/news/article.php?storyid=28 HTTP/1.1" 200 10547 "http://www.imagine3d.org/modules/news/article.php?storyid=28" "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)" - - [20/Jun/2007:03:55:46 +0200] "GET /modules/news/comment_new.php?com_itemid=28 HTTP/1.1" 200 34074 "http://www.imagine3d.org/modules/news/comment_new.php?com_itemid=28" "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5
.0)" - - [20/Jun/2007:03:55:55 +0200] "POST /modules/news/comment_post.php HTTP/1.0" 200 779 "http://www.imagine3d.org/modules/news/comment_post.php" "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)" - - [20/Jun/2007:03:56:00 +0200] "POST /modules/news/comment_post.php HTTP/1.0" 200 779 "http://www.imagine3d.org/modules/news/comment_post.php" "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)"
basically you see him accessing the article from and then posting two comments from which is a fake address...
His ISP has left no comment...
this pattern repeats for every spam on my site btw, access from .67 post from a fake a few seconds after
The user was registred as zxc10109 with email
zxc10109@felissilvestriscatus.info and weburl same as mentioned before
added info... He has already tried to access my site a few times since the block... I hope I havent blocked an innocent user, but such is luck...
.67 and .69 used for GET and POST logins from .70
all posts from random addresses...