Just recieved this email

Discussion in 'Support & Feedback' started by peteinoz2, Dec 30, 2006.

  1. Smyrl

    Smyrl Tomato Republic Staff

    Messages:
    13,740
    Likes Received:
    1,702
    Best Answers:
    78
    Trophy Points:
    510
    #61
    The e-mail was available at one time to DP members unless you chose option to hide it. Some low life harvested e-mail addresses. Shawn has recently gone to a mail form to avoid problems like this.
     
    Smyrl, Dec 31, 2006 IP
  2. Codythebest

    Codythebest Notable Member

    Messages:
    5,764
    Likes Received:
    253
    Best Answers:
    0
    Trophy Points:
    275
    #62
    Yes, it's been sold :cool:
     
    Codythebest, Dec 31, 2006 IP
  3. N_F_S

    N_F_S Active Member

    Messages:
    2,475
    Likes Received:
    56
    Best Answers:
    0
    Trophy Points:
    90
    #63

    He's already illegally sent an email that I'm not interested in. He can collect emails wherever he want unless they don't get any messages from him or from any 3rd parties he sold it to. But that will make his list useless.

    By the way, everyone is saying that you haven't ticked a 'hide my email' box, etc when we register. I can say that I chose to hide it. So it's either someone from DP sold it or he hacked the db.
     
    N_F_S, Dec 31, 2006 IP
  4. digitx

    digitx Guest

    Messages:
    15
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #64
    OK,

    Have not been around for ages.

    When I registered here a year or two ago, I used a unique and specific email address which was linked to this forum.

    This technique allows me to track spam. When we registered our interest last year for a rent-a-car with Avis, that email address was spammed shortly after.

    Anyway, now I am receiving spam from someone named Mike S. to the email address used for these forums. I thought it was being kept private by your forum database admins.

    Contents of email

    It is therefore obvious that someone has got their hands on your database and farmed the email addresses from it.

    Pkease explain how this could have happened.
     
    digitx, Jan 1, 2007 IP
  5. devin

    devin Guest

    Messages:
    4,461
    Likes Received:
    449
    Best Answers:
    0
    Trophy Points:
    0
    #65
    1) did you sumbit your site to those directories?
    2) did someone else submit your site to those directories using your DP address, accidentally or intentionally?

    there has beeen other threads about email addresses being spammed, and shawn has taken some steps.
     
    devin, Jan 1, 2007 IP
  6. Smyrl

    Smyrl Tomato Republic Staff

    Messages:
    13,740
    Likes Received:
    1,702
    Best Answers:
    78
    Trophy Points:
    510
    #66
    Until recently e-mail addresses were viewable to other members unless you chose to hide it. Due to someone scraping addresses DP has gone to a form mail system so users are unable to see anyone's e-mail address. This thread will be merged with other similar threads.
     
    Smyrl, Jan 1, 2007 IP
  7. digitx

    digitx Guest

    Messages:
    15
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #67
    First post:

    Never seen those directories.

    If I did submit to those directories, I would have used an email address specific to them to see if they were selling my email address.

    No, the technique I use allows me to trace who gave away my email address, and in this case, it is Digital Point.

    Second post:

    Never display my email address on forums.

    Guys, I have had no problems with Digital Point managing my email address up until today. So scraping would have delivered similar problems for a long time, as my initial posts are a year or two old.

    It only started today, like 1 hour ago. I always hide my email address, so that is not a valid reason in this case.

    As of today, I have started receiving spam to the exact and only email address we had used to register our account for Digital Point.

    The privacy of my personal information has been compromised because someone has got their hands on the database.
     
    digitx, Jan 1, 2007 IP
  8. koan

    koan Well-Known Member

    Messages:
    607
    Likes Received:
    19
    Best Answers:
    0
    Trophy Points:
    135
    #68
    Well I got this spam too from someone saying they hacked into DP database or something and are reselling email addresses. Bunch of dipshits.. good thing I use alias addresses from sneakemail.. now I can just change it.. but if it was my main email address I would be seriously pissed! grrr.
     
    koan, Jan 4, 2007 IP
  9. peteinoz2

    peteinoz2 Peon

    Messages:
    115
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
  10. WilliamC

    WilliamC Well-Known Member

    Messages:
    252
    Likes Received:
    27
    Best Answers:
    0
    Trophy Points:
    118
    #70
    Pete I already posted his username here in my very first post.

    and I think everyone knows he is a spammer already
     
    WilliamC, Jan 4, 2007 IP
  11. peteinoz2

    peteinoz2 Peon

    Messages:
    115
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #71

    oh.. must of missed it..

    pete
     
    peteinoz2, Jan 4, 2007 IP
  12. WilliamC

    WilliamC Well-Known Member

    Messages:
    252
    Likes Received:
    27
    Best Answers:
    0
    Trophy Points:
    118
    #72
    hehe no worries. we both started threads about this minutes apart, and someone merged them into one thread. My original post is the second one in the merged thread now.
     
    WilliamC, Jan 4, 2007 IP
  13. SEOdir.net

    SEOdir.net Banned

    Messages:
    2,549
    Likes Received:
    105
    Best Answers:
    0
    Trophy Points:
    173
    #73
    SEOdir.net, Jan 6, 2007 IP
  14. timsdd

    timsdd Peon

    Messages:
    21,102
    Likes Received:
    1,019
    Best Answers:
    0
    Trophy Points:
    0
    #74
    timsdd, Jan 6, 2007 IP
  15. Smyrl

    Smyrl Tomato Republic Staff

    Messages:
    13,740
    Likes Received:
    1,702
    Best Answers:
    78
    Trophy Points:
    510
    #75
    Tim the post above yours started out as a thread of its own which was merged with this one.
     
    Smyrl, Jan 6, 2007 IP
  16. timsdd

    timsdd Peon

    Messages:
    21,102
    Likes Received:
    1,019
    Best Answers:
    0
    Trophy Points:
    0
    #76
    I'm sorry!
    See, I should never watch playoff football and post at the same time!! :)
     
    timsdd, Jan 6, 2007 IP
    bnts and Smyrl like this.
  17. Zeeshan_M

    Zeeshan_M Peon

    Messages:
    3
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #77
    Hi,

    I am lurker to DP (not posted except for this 1st post), but I have recently noticed a very large influx of unsolicited commercial mail being sent to my email address assigned for usage by Digital Point and its services (forum and tools).

    I am sure Shawn isn't selling the member's email addresses, but there has to be certainly one or more methods open to abuse which may leak private information about an DP user.

    I logged into my DP forum account and browsed the various 'User control panel' options and saw no obvious settings which may have given out my email address. The only option which I see that could allow a leak was 'Allow vCard Download' option under http://forums.digitalpoint.com/profile.php?do=editoptions, but this was unchecked for my account.

    Looking toward the various tools provided by DP, I noticed the following output email addresses:
    http://www.digitalpoint.com/tools/keywords/?action=password
    http://www.digitalpoint.com/tools/ad-network/?action=password

    When the 'Username' radio button is selected and a valid username is entered, the following message is returned: Your login info has been sent to email-alias@example.com.

    With this in mind, pair the DP forum's member-list (http://forums.digitalpoint.com/members.php) and you can see how a malicious/spammer automate the scraping of email addresses of registered DP members for profit.

    I have noticed other people have addressed this issue before on this forum, but they were shrugged off initially, such as http://forums.digitalpoint.com/showthread.php?p=2004205 and http://forums.digitalpoint.com/showthread.php?p=2018947.

    Shawn addressed an existing issue with vBulletin whereby http://forums.digitalpoint.com/sendmessage.php?do=mailmember&u=N leaked an user's email address.

    I believe a combination of vBulletin and the 'Forgot password' tools written by Shawn let spammers get access to a rich pool of members who are focused on various Web related niches, including my email address :-(

    A brief check of mail received (samples provided at end of post) to my DP account revealed some commonalities:

    Majority of the mail was being sent from a few ADSL connections specifically in Turkey and one from Israel, the IPs were (the checks were done via dig -x ip @whois.ripe.net):

    84.94.13.161
    85.101.255.225
    85.101.99.149
    85.103.38.224
    88.233.127.184
    88.233.23.216
    88.234.18.86

    The mail transfer agent used to deliver the mail from the Turkish IPs seemed to state 'ommo.net' for all connections as its client name. A brief check on Google suggests this is a spam tool's default string.

    In the Israeli connection, 84.94.13.161 spoke to a mail server maintained by a respectable ISP, netvision.net.il. This ISP's server was given the client name of 'PROS1', this is very likely a legitimate machine name given by the spammer to his PC hardware (Windows 'Computer name' value).

    If anyone else has received spam to their DP account, please post a copy of your email headers (you may wish to filter some data for your privacy), Shawn may be able to use this information to locate common IPs which connected to the Web server maintaining forums.digitalpoint.com and locate additional information about the spammer who took DP member email addresses.

    I hope this information helps, I really want Shawn to address these issues as it is annoying to receive spam to what should be otherwise private email addresses which have our daily attention spans.

    Kind regards,
    Zeeshan

    --
    New Frontier Web Solutions
    http://www.nfwebsolutions.com/


    NOTE: I have modified my email address for DP tools to 'temporarily-modified@byzeeshan.example.com' until Shawn can rectify this situation, you may also wish to temporarily modify your email address as this forum thread may alert additional malicious users how to mine email-address data.


    -- START SAMPLE EMAILS --
    Delivery-date: Sun, 24 Dec 2006 23:09:56 +0000
    Received: from [85.101.99.149] (helo=ommo.net)
    	  by 81-[SNIPPED]-33.mail-route.nfwebsolutions.com with smtp ([SNIPPED]) id 1GycTU-0005oF-6R 
    	  for [SNIPPED]; Sun, 24 Dec 2006 23:09:49 +0000
    From: "Meg" <bohemlife@gmail.com>
    Reply-To: bohemlife@yahoo.com
    To: [SNIPPED]
    Date: Mon, 25 Dec 2006 01:09:47 +0200
    Subject: For webmasters ( Super Adult Package ) !!! ATTENTION
    X-Priority: 1
    X-Mailer: Microsoft Outlook Express 5.00.2919.7000
    MIME-Version: 1.0
    Content-Type: text/html; charset="us-ascii"
    Content-Transfer-Encoding: quoted-printable
    [BODY SNIPPED]
    
    --
    Delivery-date: Tue, 26 Dec 2006 22:03:39 +0000
    Received: from [88.234.18.86] (helo=ommo.net)
    	  by by 81-[SNIPPED]-30.mail-route.nfwebsolutions.com with with smtp ([SNIPPED]) id 1GzKM8-0005xw-Ba 
    	  for [SNIPPED]; Tue, 26 Dec 2006 22:01:11 +0000
    From: "webmaster" <coders@aol.com>
    Reply-To: coders2007@yahoo.com
    To: [SNIPPED]
    Date: Wed, 27 Dec 2006 00:01:07 +0200
    Subject: WEBMASTERS !!! THE BEST DEAL FOR YOU ! SUPER SCRIPTS AND E-MAIL LISTS !
    X-Priority: 1
    X-Mailer: Microsoft Outlook Express 5.00.2919.7000
    MIME-Version: 1.0
    Content-Type: text/html; charset="us-ascii"
    Content-Transfer-Encoding: quoted-printable
    [BODY SNIPPED]
    
    --
    Delivery-date: Sun, 31 Dec 2006 01:40:34 +0000
    Received: from [85.101.255.225] (helo=ommo.net)
    	  by 81-[SNIPPED]-33.mail-route.nfwebsolutions.com with smtp ([SNIPPED]) id 1H0pcy-0007bT-Hy 
    	  for [SNIPPED]; Sun, 31 Dec 2006 01:36:45 +0000
    From: "gimme surfers" <gimmesurfers@aol.com>
    Reply-To: support@gimmesurfers.com
    To: [SNIPPED]
    Date: Sun, 31 Dec 2006 03:36:43 +0200
    Subject: Hello
    X-Priority: 1
    X-Mailer: Microsoft Outlook Express 5.00.2919.7000
    MIME-Version: 1.0
    Content-Type: text/html; charset="us-ascii"
    Content-Transfer-Encoding: quoted-printable
    [BODY SNIPPED]
    
    --
    Delivery-date: Mon, 01 Jan 2007 19:44:33 +0000
    Received: from [88.233.127.184] (helo=ommo.net)
    	  by by 81-[SNIPPED]-31.mail-route.nfwebsolutions.com with with smtp ([SNIPPED]) id 1H1T5C-0008SO-GP 
    	  for [SNIPPED]; Mon, 01 Jan 2007 19:44:31 +0000
    From: "Brain" <brain@aol.com>
    Reply-To: bohemlife@yahoo.com
    To: [SNIPPED]
    Date: Mon, 1 Jan 2007 21:44:29 +0200
    Subject: WEBMASTERS ! LAST 1 WEEK !!!!
    X-Priority: 1
    X-Mailer: Microsoft Outlook Express 5.00.2919.7000
    MIME-Version: 1.0
    Content-Type: text/html; charset="us-ascii"
    Content-Transfer-Encoding: quoted-printable
    [BODY SNIPPED]
    
    --
    Delivery-date: Mon, 01 Jan 2007 23:26:37 +0000
    Received: from mxout1.netvision.net.il ([194.90.9.20])
    	  by by 81-[SNIPPED]-30.mail-route.nfwebsolutions.com with with esmtp ([SNIPPED]) id 1H1WUX-0000wD-B9 
    	  for [SNIPPED]; Mon, 01 Jan 2007 23:22:53 +0000
    Received: from PROS1 ([84.94.13.161]) by mxout1.netvision.net.il
     (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
     with ESMTPA id <0JB7007DOQ9AD740@mxout1.netvision.net.il> for
     [SNIPPED]; Tue, 02 Jan 2007 01:22:45 +0200 (IST)
    Date: Tue, 02 Jan 2007 01:12:36 +0200
    From: Mike S <bonus180@netvision.net.il>
    Subject: 2006  Last minute link submission
    To: [SNIPPED]
    Reply-to: Mike S <bonus180@netvision.net.il>
    Message-id: <0JB7007DRQ9VD740@mxout1.netvision.net.il>
    MIME-version: 1.0
    X-Mailer: The Bat! (v3.65.03) Home
    Content-type: text/plain
    Content-transfer-encoding: 7BIT
    X-Priority: 3
    [BODY SNIPPED]
    
    --
    Delivery-date: Thu, 04 Jan 2007 00:34:32 +0000
    Received: from [85.103.38.224] (helo=ommo.net)
    	  by by 81-[SNIPPED]-31.mail-route.nfwebsolutions.com with with smtp ([SNIPPED]) id 1H2GYv-0005Ju-0t 
    	  for [SNIPPED]; Thu, 04 Jan 2007 00:34:30 +0000
    From: "Meg" <meg@gmail.com>
    Reply-To: meg74.msn2@hotmail.com
    To: [SNIPPED]
    Date: Thu, 4 Jan 2007 02:34:26 +0200
    Subject: Targeted E-Mail Lists For Webmasters - Very Cheap -
    X-Priority: 1
    X-Mailer: Microsoft Outlook Express 5.00.2919.7000
    MIME-Version: 1.0
    Content-Type: text/html; charset="us-ascii"
    Content-Transfer-Encoding: quoted-printable
    [BODY SNIPPED]
    
    --
    Delivery-date: Sat, 06 Jan 2007 18:35:51 +0000
    Received: from [88.233.23.216] (helo=ommo.net)
    	  by 81-[SNIPPED]-33.mail-route.nfwebsolutions.com with smtp ([SNIPPED]) id 1H3GO5-0003nB-98 
    	  for [SNIPPED]; Sat, 06 Jan 2007 18:35:28 +0000
    From: "Brain Bulax" <brain@gmail.com>
    Reply-To: meg74.msn2@hotmail.com
    To: [SNIPPED]
    Date: Sat, 6 Jan 2007 20:35:22 +0200
    Subject: GREAT SURPRISE FOR WEBMASTERS ! :))
    X-Priority: 1
    X-Mailer: Microsoft Outlook Express 5.00.2919.7000
    MIME-Version: 1.0
    Content-Type: text/html; charset="us-ascii"
    Content-Transfer-Encoding: quoted-printable
    [BODY SNIPPED]
    Code (markup):
    -- END SAMPLE EMAILS --
     
    Zeeshan_M, Jan 6, 2007 IP
  18. Anita

    Anita Peon

    Messages:
    1,142
    Likes Received:
    51
    Best Answers:
    0
    Trophy Points:
    0
    #78
    Wow, great info Zeeshan. I always use gmail, which seems to catch most of my spam pretty well. I even use my e-mail out in the wild all over the place, and never need to worry much.
     
    Anita, Jan 6, 2007 IP
  19. inworx

    inworx Peon

    Messages:
    4,860
    Likes Received:
    201
    Best Answers:
    0
    Trophy Points:
    0
    #79
    I got the same email 3 times!!!

    How can he collet these emails as emails cant be seen on the forum....
     
    inworx, Jan 7, 2007 IP
  20. rosiee007

    rosiee007 Notable Member

    Messages:
    3,352
    Likes Received:
    179
    Best Answers:
    0
    Trophy Points:
    230
    #80
    I'm still getting these spam emails now, and on a regular basis. Guess he wont stop sending them now, and sell our email addresses on other Webmaster forums also :(
     
    rosiee007, Jan 7, 2007 IP