<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: How Bad Behavior handles false positives</title>
	<atom:link href="http://www.bad-behavior.ioerror.us/2008/12/20/how-bad-behavior-handles-false-positives/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.bad-behavior.ioerror.us/2008/12/20/how-bad-behavior-handles-false-positives/</link>
	<description>Home of the Web's premier link spam killer.</description>
	<lastBuildDate>Fri, 10 Sep 2010 16:15:54 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Michael Hampton</title>
		<link>http://www.bad-behavior.ioerror.us/2008/12/20/how-bad-behavior-handles-false-positives/comment-page-1/#comment-8038</link>
		<dc:creator>Michael Hampton</dc:creator>
		<pubDate>Tue, 17 Mar 2009 19:29:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.bad-behavior.ioerror.us/?p=207#comment-8038</guid>
		<description>If people get a completely blank page, then there was probably a PHP error somewhere, which will be logged in the server&#039;s error log. You might look for it there.</description>
		<content:encoded><![CDATA[<p>If people get a completely blank page, then there was probably a PHP error somewhere, which will be logged in the server&#8217;s error log. You might look for it there.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tigtog</title>
		<link>http://www.bad-behavior.ioerror.us/2008/12/20/how-bad-behavior-handles-false-positives/comment-page-1/#comment-8037</link>
		<dc:creator>tigtog</dc:creator>
		<pubDate>Tue, 17 Mar 2009 19:15:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.bad-behavior.ioerror.us/?p=207#comment-8037</guid>
		<description>The IPs of these people didn&#039;t show up in the PHP-MyAdmin logs either, and there&#039;s now two more reports.  Comment counts for the day are right down, so I&#039;m going to have to disable BB until I can find a resolution.

I&#039;m still on an older version of WordPress because I can still use the Greasemonkey extension Akismet Auntie Spam with it.  It hasn&#039;t been updated for WP 2.7+ and I refuse to wade through spam without it, so unless BB can work to block the spam and still allow commenters I guess I&#039;m stuck without upgrading that blog.</description>
		<content:encoded><![CDATA[<p>The IPs of these people didn&#8217;t show up in the PHP-MyAdmin logs either, and there&#8217;s now two more reports.  Comment counts for the day are right down, so I&#8217;m going to have to disable BB until I can find a resolution.</p>
<p>I&#8217;m still on an older version of WordPress because I can still use the Greasemonkey extension Akismet Auntie Spam with it.  It hasn&#8217;t been updated for WP 2.7+ and I refuse to wade through spam without it, so unless BB can work to block the spam and still allow commenters I guess I&#8217;m stuck without upgrading that blog.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tigtog</title>
		<link>http://www.bad-behavior.ioerror.us/2008/12/20/how-bad-behavior-handles-false-positives/comment-page-1/#comment-8031</link>
		<dc:creator>tigtog</dc:creator>
		<pubDate>Tue, 17 Mar 2009 05:44:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.bad-behavior.ioerror.us/?p=207#comment-8031</guid>
		<description>Hi, just installed BB today.  The spam blocking appears impressive, but the only two people to contact me to say that they can&#039;t see the site are just getting a blank page, no error message or self-help links.

Their IPs are not showing up in the list of blocked IPs in the WordPress management page.

For now I&#039;ve just whitelisted them, until I figure my way around the php-MyAdmin logs.  But why aren&#039;t they getting any diagnostic message?  I&#039;m using WP SuperCache, and I added the code there as instructed, and other people are commenting OK (although not as many as usual).

Any ideas?</description>
		<content:encoded><![CDATA[<p>Hi, just installed BB today.  The spam blocking appears impressive, but the only two people to contact me to say that they can&#8217;t see the site are just getting a blank page, no error message or self-help links.</p>
<p>Their IPs are not showing up in the list of blocked IPs in the WordPress management page.</p>
<p>For now I&#8217;ve just whitelisted them, until I figure my way around the php-MyAdmin logs.  But why aren&#8217;t they getting any diagnostic message?  I&#8217;m using WP SuperCache, and I added the code there as instructed, and other people are commenting OK (although not as many as usual).</p>
<p>Any ideas?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: joe</title>
		<link>http://www.bad-behavior.ioerror.us/2008/12/20/how-bad-behavior-handles-false-positives/comment-page-1/#comment-7979</link>
		<dc:creator>joe</dc:creator>
		<pubDate>Mon, 23 Feb 2009 12:53:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.bad-behavior.ioerror.us/?p=207#comment-7979</guid>
		<description>Just added two robots to the whitelist, which may be interesting to have there by default.

1. Simile (a MIT research project on Semantic Web subjects)
Fixed IP address: &quot;18.51.2.218&quot;, // Simile.MIT.EDU

2. Sincice (a semantic web search engine with their own index robot).
Allowing their UA seems not to work: &quot;SindiceFetcher/0.1 (+http://sindice.com/developers/bot)&quot;,

I noticed the sindice people about the problem, see:

http://forum.sindice.com/showthread.php?p=330#post330</description>
		<content:encoded><![CDATA[<p>Just added two robots to the whitelist, which may be interesting to have there by default.</p>
<p>1. Simile (a MIT research project on Semantic Web subjects)<br />
Fixed IP address: &#8220;18.51.2.218&#8243;, // Simile.MIT.EDU</p>
<p>2. Sincice (a semantic web search engine with their own index robot).<br />
Allowing their UA seems not to work: &#8220;SindiceFetcher/0.1 (+http://sindice.com/developers/bot)&#8221;,</p>
<p>I noticed the sindice people about the problem, see:</p>
<p><a href="http://forum.sindice.com/showthread.php?p=330#post330" rel="nofollow">http://forum.sindice.com/showthread.php?p=330#post330</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sebastian</title>
		<link>http://www.bad-behavior.ioerror.us/2008/12/20/how-bad-behavior-handles-false-positives/comment-page-1/#comment-7976</link>
		<dc:creator>Sebastian</dc:creator>
		<pubDate>Mon, 16 Feb 2009 13:53:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.bad-behavior.ioerror.us/?p=207#comment-7976</guid>
		<description>Hi there,

I just wanted to say thanks! I love BB and it saved me tons of time and resources. It works really well (at least I didn&#039;t get any bad feedback at all so far. 

What I hate are ignorant users or even worse ignorant users that don&#039;t care at all - those who cause the web to drown in SPAM, Botnets and Phishing.

Again, thanks for BB!</description>
		<content:encoded><![CDATA[<p>Hi there,</p>
<p>I just wanted to say thanks! I love BB and it saved me tons of time and resources. It works really well (at least I didn&#8217;t get any bad feedback at all so far. </p>
<p>What I hate are ignorant users or even worse ignorant users that don&#8217;t care at all &#8211; those who cause the web to drown in SPAM, Botnets and Phishing.</p>
<p>Again, thanks for BB!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tamara Burks</title>
		<link>http://www.bad-behavior.ioerror.us/2008/12/20/how-bad-behavior-handles-false-positives/comment-page-1/#comment-7955</link>
		<dc:creator>Tamara Burks</dc:creator>
		<pubDate>Tue, 27 Jan 2009 05:59:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.bad-behavior.ioerror.us/?p=207#comment-7955</guid>
		<description>I tried posting on one site and it gave me a error saying it wouldn&#039;t post because of your software.  then went back and reloaded the page and saw it had gone through. I&#039;m more than a bit confused. I was thinking that maybe that instance of fakealert virus that I had had about a week ago (and had originally thought I was just continually running across a very annoying autoscan) was cleared up. I have a antivirus, winpatrol and I use Glarysoft utilities to repeatedly clean out the temp files so if anything is hiding in there gets cleaned out.</description>
		<content:encoded><![CDATA[<p>I tried posting on one site and it gave me a error saying it wouldn&#8217;t post because of your software.  then went back and reloaded the page and saw it had gone through. I&#8217;m more than a bit confused. I was thinking that maybe that instance of fakealert virus that I had had about a week ago (and had originally thought I was just continually running across a very annoying autoscan) was cleared up. I have a antivirus, winpatrol and I use Glarysoft utilities to repeatedly clean out the temp files so if anything is hiding in there gets cleaned out.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andre</title>
		<link>http://www.bad-behavior.ioerror.us/2008/12/20/how-bad-behavior-handles-false-positives/comment-page-1/#comment-7942</link>
		<dc:creator>Andre</dc:creator>
		<pubDate>Tue, 13 Jan 2009 12:23:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.bad-behavior.ioerror.us/?p=207#comment-7942</guid>
		<description>Sorry, i get a little paranoid. a spamer tray recently to spam the wiki with many IPs, and science den among others i don&#039;t publish my email anymore. And sorry for the double Post. (You can delete my posts if you want.)</description>
		<content:encoded><![CDATA[<p>Sorry, i get a little paranoid. a spamer tray recently to spam the wiki with many IPs, and science den among others i don&#8217;t publish my email anymore. And sorry for the double Post. (You can delete my posts if you want.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Hampton</title>
		<link>http://www.bad-behavior.ioerror.us/2008/12/20/how-bad-behavior-handles-false-positives/comment-page-1/#comment-7941</link>
		<dc:creator>Michael Hampton</dc:creator>
		<pubDate>Mon, 12 Jan 2009 23:20:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.bad-behavior.ioerror.us/?p=207#comment-7941</guid>
		<description>Andre, since you were able to post here, which also uses Bad Behavior, I suspect something is going on with your web server. But since you filled out fake information I can&#039;t go any further.</description>
		<content:encoded><![CDATA[<p>Andre, since you were able to post here, which also uses Bad Behavior, I suspect something is going on with your web server. But since you filled out fake information I can&#8217;t go any further.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andre</title>
		<link>http://www.bad-behavior.ioerror.us/2008/12/20/how-bad-behavior-handles-false-positives/comment-page-1/#comment-7940</link>
		<dc:creator>Andre</dc:creator>
		<pubDate>Mon, 12 Jan 2009 23:07:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.bad-behavior.ioerror.us/?p=207#comment-7940</guid>
		<description>Thanks for your comment, Michael Hampton

Hmmm... Ok...

i use opera, firewale, and the system is regularly virus checked.
the error occurs to if i don&#039;t post any text but abbort the edit.
(i have no idea where this EXPECT is coming from, maybe from the firewall? but so mach i know, EXPECT is ok with HTTP/1.1, true?)

in the code common_tests.inc.php is written:
// Is it claiming to be HTTP/1.0?  Then it shouldn&#039;t do HTTP/1.1 things
...

if the HTTP_EXPECT header is ok in HTTP/1.1, but then the code don&#039;t check this:
if (array_key_exists(&#039;Expect&#039;, $package[&#039;headers_mixed&#039;]) &amp;&amp; stripos($package[&#039;headers_mixed&#039;][&#039;Expect&#039;], &quot;100-continue&quot;) !== FALSE) {
...

in the next check the HTTP/1.1 is checked:
if ($settings[&#039;strict&#039;] &amp;&amp; !strcmp($package[&#039;server_protocol&#039;], &quot;HTTP/1.1&quot;)) {
if (array_key_exists(&#039;Pragma&#039;, $package[&#039;headers_mixed&#039;]) &amp;&amp; strpos($package[&#039;headers_mixed&#039;][&#039;Pragma&#039;], &quot;no-cache&quot;) !== FALSE &amp;&amp; !array_key_exists(&#039;Cache-Control&#039;, $package[&#039;headers_mixed&#039;])) {
...

if it is my software, i have no idea what could cause this problem, there is nothing unusual. where i should search the cause?
(i don&#039;t want abuse this commend place as forum, if everything is ok with the code in your opinion, i will fix it for the wiki with a patch, thanks.)</description>
		<content:encoded><![CDATA[<p>Thanks for your comment, Michael Hampton</p>
<p>Hmmm&#8230; Ok&#8230;</p>
<p>i use opera, firewale, and the system is regularly virus checked.<br />
the error occurs to if i don&#8217;t post any text but abbort the edit.<br />
(i have no idea where this EXPECT is coming from, maybe from the firewall? but so mach i know, EXPECT is ok with HTTP/1.1, true?)</p>
<p>in the code common_tests.inc.php is written:<br />
// Is it claiming to be HTTP/1.0?  Then it shouldn&#8217;t do HTTP/1.1 things<br />
&#8230;</p>
<p>if the HTTP_EXPECT header is ok in HTTP/1.1, but then the code don&#8217;t check this:<br />
if (array_key_exists(&#8216;Expect&#8217;, $package['headers_mixed']) &amp;&amp; stripos($package['headers_mixed']['Expect'], &#8220;100-continue&#8221;) !== FALSE) {<br />
&#8230;</p>
<p>in the next check the HTTP/1.1 is checked:<br />
if ($settings['strict'] &amp;&amp; !strcmp($package['server_protocol'], &#8220;HTTP/1.1&#8243;)) {<br />
if (array_key_exists(&#8216;Pragma&#8217;, $package['headers_mixed']) &amp;&amp; strpos($package['headers_mixed']['Pragma'], &#8220;no-cache&#8221;) !== FALSE &amp;&amp; !array_key_exists(&#8216;Cache-Control&#8217;, $package['headers_mixed'])) {<br />
&#8230;</p>
<p>if it is my software, i have no idea what could cause this problem, there is nothing unusual. where i should search the cause?<br />
(i don&#8217;t want abuse this commend place as forum, if everything is ok with the code in your opinion, i will fix it for the wiki with a patch, thanks.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andre</title>
		<link>http://www.bad-behavior.ioerror.us/2008/12/20/how-bad-behavior-handles-false-positives/comment-page-1/#comment-7939</link>
		<dc:creator>Andre</dc:creator>
		<pubDate>Mon, 12 Jan 2009 23:03:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.bad-behavior.ioerror.us/?p=207#comment-7939</guid>
		<description>Thanks for your comment, Michael Hampton

Hmmm... Ok...

i use opera, firewale, and the system is regularly virus checked.
the error occurs too if i don&#039;t post any text but abbort the edit.
(i have no idea where this EXPECT is coming from, maybe from the firewall? but so mach i know, EXPECT is ok with HTTP/1.1, true?)

in the code common_tests.inc.php is written:
// Is it claiming to be HTTP/1.0?  Then it shouldn&#039;t do HTTP/1.1 things
...

if the HTTP_EXPECT header is ok in HTTP/1.1, but then the code don&#039;t check this:
if (array_key_exists(&#039;Expect&#039;, $package[&#039;headers_mixed&#039;]) &amp;&amp; stripos($package[&#039;headers_mixed&#039;][&#039;Expect&#039;], &quot;100-continue&quot;) !== FALSE) {
...

in the next check the HTTP/1.1 is checked:
if ($settings[&#039;strict&#039;] &amp;&amp; !strcmp($package[&#039;server_protocol&#039;], &quot;HTTP/1.1&quot;)) {
if (array_key_exists(&#039;Pragma&#039;, $package[&#039;headers_mixed&#039;]) &amp;&amp; strpos($package[&#039;headers_mixed&#039;][&#039;Pragma&#039;], &quot;no-cache&quot;) !== FALSE &amp;&amp; !array_key_exists(&#039;Cache-Control&#039;, $package[&#039;headers_mixed&#039;])) {
...

if it is my software, i have no idea what could cause this problem, there is nothing unusual. where i should search the cause?
(i don&#039;t want abuse this commend place as forum, if everything is ok with the code in your opinion, i will fix it for the wiki with a patch, thanks.)</description>
		<content:encoded><![CDATA[<p>Thanks for your comment, Michael Hampton</p>
<p>Hmmm&#8230; Ok&#8230;</p>
<p>i use opera, firewale, and the system is regularly virus checked.<br />
the error occurs too if i don&#8217;t post any text but abbort the edit.<br />
(i have no idea where this EXPECT is coming from, maybe from the firewall? but so mach i know, EXPECT is ok with HTTP/1.1, true?)</p>
<p>in the code common_tests.inc.php is written:<br />
// Is it claiming to be HTTP/1.0?  Then it shouldn&#8217;t do HTTP/1.1 things<br />
&#8230;</p>
<p>if the HTTP_EXPECT header is ok in HTTP/1.1, but then the code don&#8217;t check this:<br />
if (array_key_exists(&#8216;Expect&#8217;, $package['headers_mixed']) &amp;&amp; stripos($package['headers_mixed']['Expect'], &#8220;100-continue&#8221;) !== FALSE) {<br />
&#8230;</p>
<p>in the next check the HTTP/1.1 is checked:<br />
if ($settings['strict'] &amp;&amp; !strcmp($package['server_protocol'], &#8220;HTTP/1.1&#8243;)) {<br />
if (array_key_exists(&#8216;Pragma&#8217;, $package['headers_mixed']) &amp;&amp; strpos($package['headers_mixed']['Pragma'], &#8220;no-cache&#8221;) !== FALSE &amp;&amp; !array_key_exists(&#8216;Cache-Control&#8217;, $package['headers_mixed'])) {<br />
&#8230;</p>
<p>if it is my software, i have no idea what could cause this problem, there is nothing unusual. where i should search the cause?<br />
(i don&#8217;t want abuse this commend place as forum, if everything is ok with the code in your opinion, i will fix it for the wiki with a patch, thanks.)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
