Any bash buffs out there? WordPress update script 2 alpha

Are any of you all good and *nix scripts?

I’ve been working on the next version of the “35 second upgrade” script and I’d like some second eyes on it before I release it officially.. I would like your help in ensuring this method isn’t gonna crash any typical *nix based, non-core-code-customized blogs. I was wondering if some of you might review this script and tell me of any errors or problems you can foresee. I’ve got it working just fine updating my blogs. But, I’d like more of a confidence factor than what I can get just having it work for me and only me.

Current Improvements:
1. Can update any number of directories by just adjusting the array at the top
2. Can pull from other sources. You don’t HAVE to update to the current and can just use it to roll back your code, every night, to your customized WP version.
3. Now works for blogs stored in the “WordPress” directory.
4. Cleans up after itself
5. Error checking
6. Observes tmp directory locations.

Coming soon:
1. File backups
2. SQL backups

If you know anything about scripts, could you give it a review and tell me what you think?

This IS alpha stuff, so use it with that in mind…

Source code follows
Continue reading Any bash buffs out there? WordPress update script 2 alpha

1and1.com Sucks! 1 and 1? Says who?!?!

I came across another rant about 1and1 the other day and thought I’d post something I’d sent off to Michael ages ago. It sums up my thoughts on the subject completely and required very little editing…

1and1.com has labeled themselves “The worlds No. 1 web host [by the number of sites hosted]”. So they are a big target. It is true that they do not hold your hand, but that’s not what I am concerned about. I don’t care if they have crappy extras, in fact the more extras they add, the more stuff I’m paying for that I won’t ever use. What I care about is that they are willing to give you the access rights to add more to your shared server. Right now the ONLY things that I haven’t been able to do with my 1and1 account involve port access. And that simply isn’t possible with a shared server.

You will always find complaints about a company. Sometime they are valid. For 1and1.com, the complaints seem to come from the less technical users who looked for help. I agree that 1and1 isn’t great about explaining how to do new stuff. Three years ago, I was in the same situation, learning… but that’s what is great about the internet, there are many many resources available. That can help you through the rough spots if you’re patient and willing to work on it… I find that hosting at 1and1.com and searching Google works well for me and I’ve had my now account for three years plus.

Dreamhost* has the best help system out there, AFAIK, but their best service plan is $79.99. Through accepting an advertised upgrade deal for existing 1and1 customers, I have way more resources available and pay only ~12% of what a DreamHost customer is paying. I’m getting more resources for my money. I realized the other day that my 1and1 account has space available than what I’ve partitioned my Windows partitions to and that includes the partition I’ve set aside for multimedia. I’ll take my $839 dollars a year savings thank you very much.

*Update – Since the initial writing of this email, DreamHost has radicaly increase their available space available and resources. The prices are now comparable to what I get from 1and1.com. There are trade offs, but by stats alone they basically even out until you look at the extra charges DreamHost has. DreamHost charges a $50 setup fee (It’s like charging an extra $4.16 per month for the first year) and has 100% higher domain registration fees.

I should leave this out and follow the “If you want comments, leave holes in your posts to allow people to reply.” But I know some WILL say “YEAH – but have you ever tried to cancel a service from them?”. Sure, I’ll address that and then THAT you can reply to. EVERY post I’ve seen about this subject has been from someone who’s filled out a form to cancel the service and then not checked on it until 6 months after the fact when they receive the next bill. I’m sorry but if something is important to you, you, yourself, ensure that it is done.

People would have had no problem if they’d:
1. Ensured that the cancel was on record the week before it was due to happen
2. Ensured that the cancel a week later that the cancel took place
3. Ensuring that the 1and1 representatives made notes on their accounts recording each call.
4. Recorded the name/number date and time of each phone call.

1and1 will retroactively refund if you can prove your case. I’ve read about that happening too. I don’t anticipate a problem if and when I cancel. And I CERTAINLY more willing to work toward cancelling a service if it means that I never have to worry about a site I have worked to build isn’t sniped out from underneath me. 1and1’s process doesn’t let that happen and I never have to worry about paying some scoundrel/thief/blackmailer $800 just to get back what is already rightfully mine.

Support is something I know about. I know what an effort is involved for our office to provide the best tech support in our industry. We’ve spent years learning what works and what does not. Mistakes have happened and we’ve learned from each one. When I make a call to any company, a call that matters to me, I’m going to do my best to make that representative take the steps needed to provide me with a good technical support, whether they are trained to do so or not.

Likewise, I realize that we will have customers that we cannot help for whatever reason. I also know that those customers are likely to complain, as loudly as they can, that we have the absolute worst tech support of anybody in the world. All that matters to them is that we could not help them, whether it was an issue on their side or if we did make a mistake. So, I naturally question the most inflammatory posts I read. Mistakes do happen, but all in all it is in the company’s best interest to provide good support. That’s true for where I work and has to be true for 1and1.

Anyway, that’s my take on it.

I guess some people need more help than others (link)…

UPDATE: Oh, look. Here’s another generic “1and1.com Internet Web Hosting Sucks”
article (link) from an SEO guy…

“They are by far the worst hosting company.”

Ummm… He doesn’t mention a single word about their hosting. So, I’ll ignore this part…

“They make it impossible cancel and account, “

OK, he’s upset. Obvioulsy, he’s gonna have some thick thumbs…

“and if you don’t do it correctly they will keep billing you.”

WAIT? WHAT? If you don’t actually cancel the account, the continue to provide you with service? AND they expect to be paid for that?????

No!!!!!

“Think you’ll be ok when your credit card expires don’t worry they will keep billing you and eventually refer you to collections.”

So, he ignored the problem and assumed a business that he had an relationship would simply say “Oh, I don’t care about that money. It doesn’t matter that much. It’s only bad debt. Why collect on that?”

Why in the world would someone be surprised that they would collect upon what they see as a valid debt? Of course it is going to go into their “collections” department and you’ll be sent scary letters! That is evidence that the company is well managed and not that is evil. Just because you don’t feel it is important to follow up where your money goes, you should not assume someone else will be equally lax about where “their” money is.

When you call to speak to a supervisor and tell them to cancel an account you aren’t using anymore and is in collections, they still won’t cancel it.

OK. He had problems with the first cancellation. Don’t you think it would make sense to call and receive confirmation that the account was cancelled successfully? If he did that, I see no evidence of it. I do see that he admits to making a mistake in initial cancelling process. I’d guess that he never verified the cancellation that time either. Obviously, there was a mistake here and 1and1 should have canceled the account, and billed him for only the service up to the day of this “second” cancellation. Hmmm perhaps that’s what they did. It is not clear if the continued debt is the full amount due for that period.

They will however keep sending you an email to an address that no longer is in existence and refer you to their online web form.

So, he didn’t even continue update them with his correct contact information until the situation was finalized??? After all why should he care that they be able to reach him? Maybe he is just to frustrated to type all the details in this article but wait, he can clearly think of all possible search term for his post: (parenthetics mine)

1 & 1 Web Hosting Sucks (um not)
1 & 1 Hosting provider sucks (HA!)
1 & 1 Hosting Sucks (Oh really?)
1&1 Internet Web Hosting Sucks (says who?)
1&1.com sucks (Did you try to protect your money?)
1&1 Control Panel Sucks (HORRAY for those that build their own!)
1&1 Internet Inc FAQ SUCKS (Not really)
1&1 Hosting Reviews (but he never reviewed their services)
Reviews of 1&1 (He still doesn’t offer a review)

From here on he just copy and pastes… yeesh… That’s enough for me…

I think I’ll spend 4.95 to get a domain and then cancel it before the year is out… It would be worth $5 just for the experience… I should make it something like “Wonderful1and1.com” so that people won’t say the name made them cancel it. Hmmm Not a bad idea….

UPDATE: Here’s a nice review of 1and1 (link):

The 1 and 1 services offered to the small and medium enterprise are impressive. Their strength is their excellent value for money, in offering a very large array of services and features with their web hosting products for an extremely low monthly charge.

The 1 and 1 homepage is attractive and is set up to give clear information about their products and services and what they offer. There is a graphic showing very clearly the extras to be had for each package, helping reveal what stands out. This is definitely a plus in deciding which package to choose. The company track record is also clearly stated with financial summaries, and is rock solid.

Looking for a free download of Qualcomm QPST 2.7? Look no further.

I’ve found Qualcomm QPST 2.7 build 215 available for download here.

QPST is a in-house cellphone manufacurer utility program that is used to edit many of the cell phone features that are not editable in any other way.

It was never meant for public consumption, so you can’t buy it anywhere, but it is in wide use. The reason it isn’t for everyone is that it is VERY powerful. You can destroy your phone at the click of a button and your cellular manufacturer will be under no obligation to fix it. If you don’t have a couple hundred dollars available that will allow you to replace your phone at full retail cost, don’t run this program.

You can do most things you might want, like uploading MP3’s to your phone or downloading pictures, through the somewhat safer program BitPIM. That program is available for download from SourceForge at the site http://www.bitpim.org/.

WordPress 2.0.6 Content Summary – Release in days, WordPress 2.1 due Jan 2007

Mark Jaquith, who I will probably forever call Mark Jarquith in my mind because that’s how I first read his name, has announced the Release Candidate version of 2.0.6 on the WP-Testers list. I’ve detailed the contents 2.0.6 in this post. Chances are this release will be come before Christmas. So get your blogs ready for the update. Make sure your files and databases are backed up and you are ready to go… And be sure you are sporting your limited edition WordPress shirt as you do it! (Order now! Operators are standing by!)



digg story

THEN you need to get ready for the 2.1 release… and it’s a biggy. That will have to wait until after the holidays. If I had to wager, I would say it will be out in early January. When 2.0 was released at Christmas time last year, everyone had to scramble to get their translations and converted and since they had time off from work, the spent the holidays tweaking their sites. And that’s not nearly as much fun as doing it on company time! (JOKING!) So, I’ll include more on that later.

You can download the 2.0.6 RC if you want to take an early look at the release:
http://wordpress.org/beta/wordpress-2.0.6-RC1.zip

However, you should know that RC1 will NOT be the same as the final 2.0.6 release. There is a security fix that has been completely under wraps till now. It has only been reported to Security@wordpress.org and has not been reported by the security sites. Because of this, the security fix has not been added to the public betas. It is running on several private sites. Automattic did not want to give the bad boys of the web to attack sites that haven’t upgraded.

All-in-All, 2.0.6 is largely a stability release. The WordPress 2.0 series is now officially on its way to becoming part of the Debian Stable product and as a result, and as discussed in October, patches will continue to be released in 2.0 series for the next 3-5 years.

In this version, the fixes include (priority from highest to lowest):

Ticket Summary
3215 Login & Update functions everything is broken
2987 +/- for bottom boxes on write page acts weird in FF
3267 PHP Error in template-functions-links.php
2681 Error on Inline Uploading after deleting page with attached file
3112 Upload bugs
3367 Single quote around double quote mysql string breaks on OpenVMS HP-PHP
3051 QuickTags now work in Safari browser
3391 Can’t click Labels for Radio Buttons in Moderation Queue
3438 Internationalization by mistake
1540 Date format returned by wp_get_archives is not localizable

Here are some finer details:

Continue reading WordPress 2.0.6 Content Summary – Release in days, WordPress 2.1 due Jan 2007

Windows Vista Deployment Articles to Read

Note: These links were created with the Copy Text as Link tool for IE.

This live post is a collection of articles related to mass deploying Windows Vista. Please feel free to add your own as we all prepare for this. I’ll add and drop articles from here as they seem to be more or less important.

My current Windows XP deployment technique involves Symantec Ghost, SysPrep, and several custom built applications. We ship multiple computers and the most recent CD boots to a network using DHCP and a dynamicly generated computer name to ensure that a single CD can be used by the shipping and service departments to deliver a consistent image to our clients on new and repaired PCs, regardless of the model. This techniqe also involves creating a factory backup of the image after it is fully configured in the event an install goes bad and must be restarted (hasn’t happend yet) and allows for rolling backups of the operating system partitions and drive mirror.

The goal is to have a similarly efficient deployment process when we deploy Vista based machines on a set date in the near future.
Articles listed here may not be strictly related to Imaging, but may also include details describing running different types of programs under Vista in hopes that any problems can be foreseen:

Deployment
Inside Vista’s new image-based install
The simple life
ImageX and WIM Image Format
Deploying Windows Vista
Windows Vista imaging and deployment
Is the Windows Image (WIM) format used by the Microsoft Systems Management Server (SMS) OS Deployment Feature Pack the final version that Windows Vista will use?
WIM image format From Wikipedia
Customizing Windows Vista Deployments
Hackers get Hacked with new Windows Vista or directly here. – hacking article that discusses sysprep and WIM images.
Plan, Build, and Deploy Guide
A Guide To Pain-Free Desktop Deployment

Networking
Every Vista PC to get a domain name
Could Vista actually slow down networks?

Release/Version Details
Windows Vista Product Overview for IT Professionals
Vista goes gold: the frenzy begins
Work PCs to miss out on key Vista features
Tough new rules on Vista “OEM”
Windows without windows: Microsoft goes command-line with Server Core
Windows Vista RC1: you have the right to do … nothing, actually
Vista’s account protection: one click and it’s gone

Software/hardware issues
Vista scoots to new boot, but it’s still kinda rooted (A discussion of Vista’s handling of the MBR)
HOW TO: Dual-boot XP and Vista
HOW TO: Run Vista on Linux/XP
Vista still lacks full nVIDIA support
Microsoft deliberately blocking disc burning software in Vista, claims Alcohol
HOW TO: Install Nero 7 on Vista
Nero runs under Vista (at last!)
HOW TO: Coax retro DOS games to play on Vista
Need to eavesdrop on a network? Try Microsoft’s new free tool.
Activation
Vista RTM cracked by pirates before release
Microsoft closes piracy loophole: mandatory activation for volume licenced Vista

Virtualization
One for all

Older XP technologies
Let’s build!
Roll with it

A very good walk through of Windows Vista

If you haven’t gotten a chance to play with Windows Vista yet, you might want to take a gander at the LifeHacker article on the subject. It’s picture rich, and a pretty thorough overview of what you’ll be getting.

I just got word yesterday to ramp up for deploying our first Vista based products. It’s coming on like a steam train.

Right now, the way I’m looking at it, I’m not likely to upgrade EVER. Something might change my mind some day… some future game I HAVE to have might require DirectX 10 which, right now, is Vista only. That’s not all that likely. I might get a new machine that has it bundled, I guess. Win XP works well enough for me right now and I am already fighting the activation wizard WAY to often….

In fact, I started my prep work for Vista being the only MS OS sold: I reinstalled Suse Linux on my main machine…

Here’s that article: Q&A with Microsoft about Windows Vista

Click to go to the original site.

A few words about the RISKS of WordPress 1.2, 1.5, 2.0 or anything less than 2.0.4

Summary

As the security risks in legacy versions of WordPress become more widely known, the hacking of sites that haven’t updated will become a more common event. Your site about pet rocks or the joys of train spotting may not be at the top of the attack lists, but you probably don’t want to loose everything you’ve ever written either.

Google searches can identify you as a vulnerable site and as simple defacements become boring, the deletion of posts and comments will become an east way to wrack up points on the hacker bragging lists and punish those “stupid enough” not to upgrade.

The danger of having your name on the “Vulnerable Sites” list will only increase.

The general WordPress user may not get a sense of urgency from the release announcements. So, this article will attempt to describe the danger in continuing to rely on old software and trusting it to keep your website safe.

Conclusion

I know… I know!

The conclusion is supposed to come at the end of the article. Yeah, but this message it too important to be at the end!

Here it is: If you are not running WordPress 2.0.5: upgrade today! Based on exploits already publish, available and used on the web, all of the work you’ve put into your blog could be lost.

Right now a large number of people have the knowledge to:
1. Erase any/all of your posts or comments.
2. Replace your admin password with one of their own choosing.
3. Replace files on your system including index.php.
4. Run commands against your database.
5. Grab any file with a known file name from your directory – even php files – even those with your database password.

In short, they have the ability to use your site to do whatever they want WITHOUT you having to click on anything. Now, most of these holes were closed with WordPress 2.0.3, but it still leaves some LARGE holes open even in 2.0.4. There is no reason not to upgrade to a more recent version right now.

If your convinced, great. Go out and download 2.0.5. If your not convinced, read on and these pages will hopefully scare the willies out of you and get you to upgrade!

WordPress 2.0.6 Beta 1 is out

[edit] Sep. 12 2006: 4pm EST: Updated with changes from discussion with Mark Jarquith. Four of these eleven were removed, but I think I will wait for a response from him before taking them off this list.[/edit]

You can download it here…
http://wordpress.org/beta/wordpress-2.0.6-beta1.zip

There aren’t too many changes for this release:

Ticket Summary
1540 Date format returned by wp_get_archives is not localizable
3419 Multiple Authors for 1 article
3377 Atom feed contradicts itself
3391 Can’t click Labels for Radio Buttons in Moderation Queue
2681 Error on Inline Uploading after deleting page with attached file
3112 Upload bugs
3367 Single quote around double quote mysql string breaks on OpenVMS HP-PHP
3375 delay between ping
3390 Better get_page_uri
3415 Update “no wp-config.php” help link
3267 PHP Error in template-functions-links.php
3215 Login & Update functions everything is broken

Here are the details:
Ticket #3215 Login & Update functions everything is broken – PHP can talk to the server in different languages. On servers using the “Fast CGI” language, an error 500 was received when reaching administration pages. The code was rewritten to have special handling for Fast CGI servers.
Ticket #3267 – PHP Error in template-functions-links.php – The error “PHP Fatal error: Call to a member function get_feed_permastruct() on a non-object ” would crop up in server logs. Correcting the order in which parts of memory were freed has solved the problem.
Ticket #3415 Update “no wp-config.php” help link – The page this error linked to no longer existed on WordPress.Org. The link has been fixed.
Ticket #3390 Better get_page_uri – This is mainly an optimization for pages that display complete page heirarchies / navigation menus. The DB is accessed once rather than many times.
Ticket #3375 delay between ping – NO CHANGE MADE. IGNORE.
Ticket #3367 Single quote around double quote mysql string breaks on OpenVMS HP-PHP – When programing in PHP some systems allow strings like this: ‘This is a quote “Yahoo”.’ However that will not run on some implementations. This ticked essentially changed the format to something like this “This is a quote ‘Yahoo’.”
Ticket #3112 Upload bugs – If you uploaded an image to an empty post, an error would be generated. This fix enables empty post to accept uploads.
Ticket #2681 Error on Inline Uploading after deleting page with attached file – If an attachment existed that referred to a page that was deleted, an error occured when uploading the next attachment. This has been fixed.
Ticket #3391 Can’t click Labels for Radio Buttons in Moderation Queue – You had to click on the buttons instead of the labels for the buttons. This is non-standard behaviour and has been corrected.
Ticket #3377 Atom feed contradicts itself – NO CHANGE WAS MADE. IGNORE THIS.
Ticket #1540 Date format returned by wp_get_archives is not localizable – The format of the date returned in the text of this funciton was hard coded to “Month Year”. Now it depends upon your localized configuration.
(Check here for the latest updates http://trac.wordpress.org/milestone/2.0.6)

There are two tickets that remain open that may or may not be included with this release. These are:
#3370 was reported by one user, and we haven’t been able to recreate
the bug or diagnose what’s causing it on his install. That’s still
2.0.6 Milestone in case someone stumbles on the cause… and a fix in
the next day or two. But since it’s just one person, it’s low priority.

#2987 was added to the 2.0.6 Milestone after 2.0.6 Beta 1 went out,
by a Trac user. I’ll test the patch now and see if it works as
intended for 2.0.6 and will either put it in, or push it off for 2.0.7

A final security fix will be implemented in this release. It is a reportedly “minor” security issue. I have no further details at this point.

All in all, these fixes make WordPress compatible with a wider range of hosts. Basicaly, this is a VITAL release if you are having errors with your current version of WordPress. If you aren’t receiving errors, you will not consider this release quite as vital.

How to delete a printer from a command line or from Delphi

The command line for deleting a printer looks like this:

rundll32 printui.dll PrintUIEntry /dn /n\\machine\printer

I could not get that to work for my current situation. So I wrote a Delphi program that did the same.

You can down load it here.
PrinterManipulation.zip

You can use this next source code clip instead of downloading if you like. It assumes there are three buttons on the page and one listbox on a form named Form1. After creating those controls, select all of the pascal source text AFTER the “unit” line and paste this source code over top of it. After that, double click on all of the buttons, compile and you’ll have a peice of running code.

[delphi]
// ****************************************************************************
// u_PrinterManipulation.pas 12/Dec/2006
// Written by Brian Layman
// Visit him at http://www.TheCodeCave.com
//
// A quick program to demonstrate the deletion of a printer.
//
// Usage: PrinterManipulation.exe Just click on the button 1 to populate and
// select a printer off of the list. Use button2 or button3 for two
// different deletion methods. Double clicking the list is the same as
// clicking button3.
//
// History:
// 04/Dec/2006 – BL – Created
//
// ****************************************************************************
interface

uses
Windows, Messages, SysUtils, Classes, Graphics, Controls, Forms, Dialogs,
StdCtrls;

type
TForm1 = class(TForm)
Button1: TButton;
ListBox1: TListBox;
Button2: TButton;
Label1: TLabel;
Button3: TButton;
procedure Button1Click(Sender: TObject);
procedure Button2Click(Sender: TObject);
procedure ListBox1Click(Sender: TObject);
private
{ Private declarations }
public
{ Public declarations }
end; // TForm1

var
Form1: TForm1;

implementation

{$R *.DFM}
uses
WinSpool, Printers;

type
{******************************************************************************
TPrinterDevice
******************************************************************************}
TPrinterDevice = class
Driver, Device, Port: String;
constructor Create(ADriver, ADevice, APort: PChar);
function IsEqual(ADriver, ADevice, APort: PChar): Boolean;
end; // TPrinterDevice

{******************************************************************************
Create
******************************************************************************}
constructor TPrinterDevice.Create(ADriver, ADevice, APort: PChar);
begin // Create
inherited Create;
Driver := ADriver;
Device := ADevice;
Port := APort;
end; // Create

{******************************************************************************
IsEqual
******************************************************************************}
function TPrinterDevice.IsEqual(ADriver, ADevice, APort: PChar): Boolean;
begin // IsEqual
Result := (Device = ADevice) and ((Port = ”) or (Port = APort));
end; // IsEqual

{******************************************************************************
TForm1
******************************************************************************}
{******************************************************************************
Button1Click
******************************************************************************}
procedure TForm1.Button1Click(Sender: TObject);
var
indx: Integer;
begin // Button1Click
ListBox1.Clear;
for indx := 0 to (Printer.Printers.Count – 1)
do ListBox1.Items.Add(Printer.Printers[indx]);
end; // Button1Click

{******************************************************************************
ListBox1Click
******************************************************************************}
procedure TForm1.ListBox1Click(Sender: TObject);
var
hPrinter : Cardinal;
PrinterDef: PRINTER_DEFAULTS;
pPrinterName: PChar;
begin // ListBox1Click
pPrinterName := PChar(ListBox1.Items[ListBox1.Itemindex]);
FillChar(PrinterDef, sizeof(PrinterDef), #0);
PrinterDef.DesiredAccess := PRINTER_ALL_ACCESS;

if (OpenPrinter(pPrinterName, hPrinter, @PrinterDef))
then begin
if DeletePrinter(hPrinter)
then ShowMessage(‘Deletion Succcesful’);
ClosePrinter(hPrinter);
end
else ShowMessage(‘Could not open’);
end; // ListBox1Click

{******************************************************************************
Button2Click
******************************************************************************}
procedure TForm1.Button2Click(Sender: TObject);
var
ADevice: PChar;
PrinterHandle: THandle;
begin // Button2Click
with TPrinterDevice(Printer.Printers.Objects[ListBox1.ItemIndex])
do begin
GetMem(ADevice, Length(Device));
StrCopy(ADevice, PChar(Device));
end;
OpenPrinter(ADevice, PrinterHandle, nil);
if DeletePrinter(PrinterHandle) then ShowMessage(‘Deletion Succcesful’);
ClosePrinter(PrinterHandle);
FreeMem(ADevice);
end; // Button2Click

end.
[/delphi]

Build your own spam filter with PHP and DNSBLs

Have you ever gotten an email asking if want certain parts of your body enlarged, parts that you might not even have? Was the next email you read one asking if you want to loose the inches you’ve recently gained? Did you ever notice how these emails are always from people that you are fairly certain have nothing to do with the contents of the email. Did MTeresa@Vatican.org really send that diet pill email? Have you ever gotten returned or rejected “can’t be delivered” emails from addressed you’ve never ever sent an email to?

I have.

SPAM. It’s HORRIBLE! My email box for Brian@TheCodeCave.com probably gets 3 to 1 spam over real email. I expected that. I put that address out everywhere and don’t protect it. It is meant to be my public address. But the FROM addresses on all that email never indicates who the email is really from. Even the company information inside the email header is faked. The spammers will grab someother name on their spam list and use it as their from address. I’ve had my name put into the from address of emails a few times. It’s an annoying problem, just ask the Nuclear Moose.

Why this can happen is a long story. It all relates back to the fact that SMTP and port 25 were never meant for submitting emails to email servers. SMTP was only meant for server to server communications. However, that’s for a different post. The long and short of it is that everything can be faked except for one thing: the IP address of the server that sent the email.

Because that IP address is accurate, you can use it to tell if the person that sent the email is a spammer. The post tells you a couple ways to do that. And because this is The Code Cave, you get a fully functional php routine to boot.
Continue reading Build your own spam filter with PHP and DNSBLs