MovableType users must upgrade to v3.14
On Dec. 15th, Employees.org was brought to a crawl. "Comment Spammers" were trying to load up MovableType blogs via the mt-comments.cgi script. While programs like MT-Blacklist help keep the content out of the blogs, there are problems in all versions of MovableType prior to v3.14 that still allow the server resources to be severely impacted.
As a result, any installation of MovableType on employees.org MUST be version 3.14 or later. Details on MT3 can be found here:
MT3 is now free for personal, limited use. Previously it was not, but that is no longer a reason for not upgrading. Note the "Limited Free Version" available here:
Note that tricks like renaming mt-comments.cgi in older MovableType installations no longer work as the Comment Spammers have taught their tools to scrap pages to find the CGI script name. At this point, we must insist on upgraded installations.
We realize that this is a busy time of the year and will give folks reasonable time to upgrade their MovableType installations. However, if Willers is found to be attacked again by a the Comment Spammers via a users old MovableType installation, we will likely disable the user's blog with no warning.
If you have an old MT installation that you no longer care about, please delete it now.