Note, links removed from the text.
Found an interestingly annoying scare tactic while generating backlinks to my site. I was doing the standard manual submission to what seems like an endless supply of web directory sites. When I stumbled across the following directory: http://www.gdotz.com/
When you click on the ‘Submit URL’ link, it takes you to a new WordPress installation page with the ‘Hello World’ post indicating they are upgrading their web directory:. http://www.gdotz.com/blog/site-news/large-upgrade-planned/
Well like any good web-blogger, I decided to leave a comment and welcome them to the world of wordpress. I hit the submit button and it took me to the following fake 403 error page:
————————————
Error 403
We’re sorry, but we could not fulfill your request for /blog/wp-comments-post.php on this server.
Your Internet Protocol address is listed on a blacklist of addresses involved in malicious or illegal activity. See the listing below for more details on specific blacklists and removal procedures.
Your technical support key is: 44cb-4405-1366-73cd
You can use this key to fix this problem yourself.
If you are unable to fix the problem yourself, please contact dotz at gdotz.com and be sure to provide the technical support key shown above.
———————————————
I’m blacklisted? Say What? So I follow the fix this problem yourself link and i’m told:
Technical Support
Your request was intercepted by Bad Behavior, security software which protects the Web site you visited from malicious activity, such as hackers, spam and viruses. We apologize for the inconvenience, but your request matched a profile of suspicious activity. This problem is usually quite easy to fix.
Your request was blocked because of malicious automated requests received from your computer’s IP address.
Your computer’s IP address was determined to have recently sent spam or engaged in malicious activity as reported by a third-party monitoring service. This means your computer is most likely infected with viruses or other malicious software. See below for more information and removal instructions.
This problem may be caused by viruses or spyware on your computer, or by malicious software that pretends to be anti-virus or anti-spyware software. Ensure that you have REAL anti-virus and anti-spyware software on your computer, that they are kept up-to-date, and that you have run a full system scan using each tool. Once your system is cleaned of viruses and spyware, please try your request again.
The free Microsoft Security Essentials provides reasonable protection against a wide variety of malicious software.
This may also occur with old versions of Bad Behavior. If you do not see any blacklist providers listed below, and you are the site administrator, try updating to the latest version of Bad Behavior.
Blacklist Reason(s):
If the above suggestions fail to resolve the problem, click Back and contact the e-mail address you were given for further assistance.
————————————————
Wow…. Number one, I am not a spammer. Number 2, I know I am not infected with viruses. How do i know this? Removing viruses from people’s computers is my job. I clean about a dozen infected computers a day. Malware, adware, rootkits, you name it, Ive seen it. i’m behind 2 firewalls, and i’m pretty sure my computer is clean. So if i am on some kind of blacklist, must be a mistake, so i had a few friends hit the site and submit a comment. Low and behold…we are all apparently spammers or infected with viruses!
Now I didnt dig real deep into why they were using this technique. It was either to generate traffic through fear, or to sell the Bad Behavior application offered by ioerror.us. The site itself seemed pretty legit, but either their application Bad Behavior is just plain broken, or its a malicious attempt to generate business. Surfer Beware! I think I’ll stick with Akismet
Malicious content: http://www.bad-behavior.ioerror.us/
Also note: In the ‘Blacklist Reason(s):’ section, there was no reason listed.



Thx dude for ur article.I was quite scare as well when i read that crap that pops out.I can practically sleep after reading ur article.Heh