We are recently encountering spreading spam activities from the TurkTelekom network in our community sites. This becomes really anoying so we need to deal with this the one way or another.

Our first approach to handle this was to block the TurkTelekom network by a simple reverse dns lookup, but unfortunately, the spammers are now using IP address spaces without reverse dns delegation that are sill residing in the TurkTelekom network according to RIPE. I am not a fan of blocking whole providers out of our community sites but since our abuse requests went unnoticed and there is not really a big chance to hit a real user, I am currently taking into account to use the RIPE database for this job. At ftp://ftp.ripe.net/ripe/dbase/split/ RIPE makes available recent snapshots of their database, so this should not be too hard. If you are experiencing similar activities while not aiming at the turkish market, this might also be an option for you.

Let’s see how this hare and the hedgehog game will end. If it will at all.

Leave a Reply