CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Rock Phish
Goto page Previous  1, 2
 
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
newangels

Sergeant
Sergeant


Joined: Sep 06, 2007
Posts: 112


PostPosted: Thu Oct 18, 2007 11:26 am    Post subject:
Reply with quote

Well Now I am completely furious, I received an phishing note in the actual Site mail, the only way this could happen is if you are a member this completely bastard contacted me with this rubbish, I have alerted the website admin and told them to deal with this matter I an not amused, bad enough my gmail account was compromised but this is site mail, its definitely coming from their website.

Message I received below and I cannot even trace it, there is no way to see the original format and report, only the damn user name and his goose is cooked.




Good Day,
I hope my email meets you well. I am in need of your assistance. My name is Capt. Zongo Savimbi,I am in the Engineering military unit here in Luanda Angola,we have about $28 Million US dollars that we have moved to Lome Togo during the war,now we want to move it out of that country.
My partners and I need a good partner someone we can trust. It is legal money.

But we are moving it through diplomatic means, to send it to any country of your choice directly or a bank of your choice using diplomatic courier service.The most important thing is that can we trust you? Once the funds get to you, you take your 30% out and keep our own 70%. Your own part of this deal is to find a safe place where the funds can be sent to. Our own part is sending it to you.
If you are interested i will furnish you with more details. But the whole process is simple and we must keep a low profile at all times.

Waiting for your urgent response.

Regards,
Capt. Zongo Savimbi
captsavimbi@yahoo.it

Back to top
View users profile Send private message
saintau

Trooper
Trooper


Joined: Jun 15, 2007
Posts: 15


PostPosted: Fri Oct 19, 2007 1:32 am    Post subject:
Reply with quote

You posted to an open forum with an email address, a spider pick it up and now your in a spam list.

Nothing can be done about it, other then buying/getting an anti spam system of some kind.

Once in you cant get out.. Sorry.

Back to top
View users profile Send private message
brewt

SIRT Handler
Premium Member

Joined: May 29, 2007
Posts: 792
Location: USA
MIRT Premium

PostPosted: Fri Oct 19, 2007 1:37 am    Post subject:
Reply with quote

saintau wrote:
You posted to an open forum with an email address, a spider pick it up and now your in a spam list.
Apparently you missed the previous post where newangels mentioned setting up a (secret) sneakemail address to supply as an updated email address in the (private) forum profile page.

I agree, however, that once an address is compromised (regardless of how it gets compromised in the first place), it will probably always receive unsolicted email.

That's one of the appeals of forwarding services such as sneakemail/spamgourmet/etc.

Back to top
View users profile Send private message
saintau

Trooper
Trooper


Joined: Jun 15, 2007
Posts: 15


PostPosted: Fri Oct 19, 2007 1:43 am    Post subject:
Reply with quote

I thought the sneakmail account wasn't created till AFTER the first post here.

I suspect that the original email address was the one spider'd.

And the sneak is forwarding to the old address. The spamers sending directly to the address they harvested, not the n ewly created forwarder.

Did I miss read the situation?

Back to top
View users profile Send private message
brewt

SIRT Handler
Premium Member

Joined: May 29, 2007
Posts: 792
Location: USA
MIRT Premium

PostPosted: Fri Oct 19, 2007 3:04 am    Post subject:
Reply with quote

Sounds like you read it about as right as I did.

It is a bit ambiguous.
I assumed that most current complaints were about email arriving in the gmail inbox THROUGH sneakemail, after having been changed.
As I understand it, given the same ambiguity, you assumed that the most current complaints were about spam sent direct to gmail

In any case, email routed through sneakemail gives obvious cues to distinguish it from mail sent directly to the account.
Only newangels can answer the ambiguity.

Back to top
View users profile Send private message
newangels

Sergeant
Sergeant


Joined: Sep 06, 2007
Posts: 112


PostPosted: Sat Oct 20, 2007 12:24 am    Post subject:
Reply with quote

No I did not make another email address as people have been doing this with my advice on Sneakmail and all have been comprised, so there is no point I am turning off all notifications to the website apart from the newsletter in the hope this will stop

The member that phised me via site mail has been kicked out.

Back to top
View users profile Send private message
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1087
Location: USA

PostPosted: Thu Nov 01, 2007 3:36 pm    Post subject:
Reply with quote

What jurisdiction is this forum/site under? Perhaps PIRT can make contact with someone to get this cleaned up?

I dont think the forum/site has been mentioned here yet in plaintext, probably a good thing Wink But maybe one of the PIRT guys could contact newangels regarding this and attempt to make contact with the host of the website...

Whether "they" (the owners of the site) are sending these out, or if there servers are compromised, either way they need to get cleaned up....

Since they are spamming to your sneakemail alias as well, it leads me to believe that the attackers must have access to all e-mail addresses on the site somehow, and are manually updating the list of e-mail addresses on that site daily...

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
newangels

Sergeant
Sergeant


Joined: Sep 06, 2007
Posts: 112


PostPosted: Thu Nov 01, 2007 10:47 pm    Post subject:
Reply with quote

Exactly my thoughts if someone would contact me then I can give them admins email address and they can contact them, as they really need to get cleaned, its not good enough saying you are testing this has been going on since July this year.

I have not opened a new email account as it would not be viable, other people have and within the hour they have been spammed and phised as well.

Its not the owners thats for sure, this site has millions of people traveling through it all year its graphic intensive and due to this people also use the market place to buy 3D and 2D content.

If someone would leave me a private message we can take this further, its like they dont want to admit a problem, as they are a business after all, and most would not admit to this kind of compromise.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds All times are GMT
Goto page Previous  1, 2
Page 2 of 2

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer