Forum Settings
       
Reply To Thread

PM SpamFollow

#1 Dec 01 2008 at 10:36 PM Rating: Decent
****
9,395 posts
Leticia

This is the message.

leticiacoxyvnci wrote:
So, looks like the time has come for me to start using this site. I took a look at your page and well, I liked what I saw.. ;p

So um, my name is Leticia Cox. I think you and I should be friends, cause you seem pretty nice, and maybe even cute! (it's so tough to tell in this digital world :)

anyways, i'd go on forever, but I want to get a response from you.. You should check out my other page on this other site, I'm always on over there: http://www.dating-circle.net/?id=3584&profile=chikbelle (my username is chikbelle). Then maybe we could chat sometime!

talk to you soon


Seems suspicious enough.
____________________________
10k before the site's inevitable death or bust

The World Is Not A Cold Dead Place.
Alan Watts wrote:
I am omnipotent insofar as I am the Universe, but I am not an omnipotent in the role of Alan Watts, only cunning


Eske wrote:
I've always read Driftwood as the straight man in varus' double act. It helps if you read all of his posts in the voice of Droopy Dog.
#2 Dec 02 2008 at 1:27 AM Rating: Excellent
It's outta here. Thanks for the heads up and let us know if you get any more of these.
#3 Dec 12 2008 at 10:13 AM Rating: Decent
21 posts
Hmmm.... I haven't gotten any pm spam, it all just comes straight to my regular e mail. currently deleting 15+ spam messages a day, with no response from info@zam.com or accounts@allakhazam.com. I have e-mailed them everyday for 20 days and counting. I recieve the messages from my account to my account. Example below:
Stop the spam!! I have found some of these messages to have viruses. It seems to be randomly virused. There is always an attachment: SPAMDeli.txt, SpamMe.txt, SpamReMe.txt, SpamYour.txt, SpamReOrder.txt

All in all, these spam messages are getting through the system and my E mail system is not auto deleting these. For thoes that have to ask the question, yes I have controls in place to auto delete spam and other crap. I am not a novice. I have also traced the e mails, points to a location in Indonesia...

My hope here is to have some action done about these e mails.



From: thenewdays@allakhazam.com
To: thenewdays@allakhazam.com
Subject: *****SPAM***** Re: Order status, *****SPAM***** Your order, *****SPAM***** Delivery Status Notification (Failure), *****SPAM***** RE: Message, *****SPAM***** Delivery Status Notification

Spam detection software, running on the system "db.allakhazam.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
the administrator of that system for details.

Content preview: Anti-crisis crazy sale from Spurs would be off target shots
by Zokora. RicardoA penalty by Christiano Ronaldo in the 76th minute was
[...]

Content analysis details: (19.9 points, 5.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
2.0 BAYES_99 BODY: Bayesian spam probability is 99 to 100%
[score: 1.0000]
0.0 MISSING_MID Missing Message-Id: header
0.0 MISSING_DATE Missing Date: header
0.0 HTML_MESSAGE BODY: HTML included in message
1.8 HTML_IMAGE_ONLY_08 BODY: HTML: images with 400-800 bytes of words
0.1 HTML_FONT_LOW_CONTRAST BODY: HTML font color similar to background
1.5 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
2.0 URIBL_BLACK Contains an URL listed in the URIBL blacklist
[URIs: therewisdom.com]
1.9 URIBL_AB_SURBL Contains an URL listed in the AB SURBL blocklist
[URIs: therewisdom.com]
1.5 URIBL_JP_SURBL Contains an URL listed in the JP SURBL blocklist
[URIs: therewisdom.com]
1.5 URIBL_OB_SURBL Contains an URL listed in the OB SURBL blocklist
[URIs: therewisdom.com]
1.1 URIBL_RHS_DOB Contains an URI of a new domain (Day Old Bread)
[URIs: therewisdom.com]
2.0 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
[Blocked - see <http://www.spamcop.net/bl.shtml?200.186.202.101>]
3.0 RCVD_IN_XBL RBL: Received via a relay in Spamhaus XBL
[200.186.202.101 listed in zen.spamhaus.org]
1.5 URIBL_SBL Contains an URL listed in the SBL blocklist
[URIs: therewisdom.com]
0.0 HTML_SHORT_LINK_IMG_1 HTML is very short with a linked image
0.1 RDNS_NONE Delivered to trusted network by a host with no rDNS

The original message was not completely plain text, and may be unsafe to
open with some email clients; in particular, it may contain a virus,
or confirm that your address can receive spam. If you wish to view
it, it may be safer to save it to a file and open it with an editor.



X-Envelope-From: <tenter@allakhazam.com>
X-Envelope-To: <tenter@allakhazam.com>
Received: from alfagomma.it ([200.186.202.101])
by db.allakhazam.com(8.13.8/8.13.8) with SMTP id mBCCrfnR084969
Fri, 12 Dec 2008 04:53:41 -0800 (PST)
(envelope-from <tenter@allakhazam.com>
X-Envelope-To: <thenewdays@allakhazam.com>
To: <thenewdays@allakhazam.com>
Subject: Re: Order status
From: <thenewdays@allakhazam.com>
MIME-Version: 1.0
Importance: High
Content-Type: text/html
#4 Dec 13 2008 at 5:10 AM Rating: Decent
I received this in my PMs today:


From: annadaniel [ Add to Address Book | Add to Ignore List | Report This PM as Spam/Abuse ]
To: Katielynn
Sent: Dec 13, 2008 @ 3:24 AM CST
Read: Dec 13, 2008 @ 4:08 AM CST
Subject: contact us to our private email address.
Message Body: [ Reply | Forward ]
From Mr.Daniel Johnson and sister
Private and Confidential
Abidjan - Côte d'Ivoire
private(dan_johns_anna81@yahoo.fr)


My dear ,

It is our pleasure to contact you for a business
venture which I and my Sister,intend to establish in
your country.Though we have not met with you before
but we believe, one has to risk confiding in someone
to succeed sometimes in life.There is this amount of
FIFTEEN Million US Dollars ($15.000.000.00)which our late Father deposited in a private security company here in Abidjan Capital city of Cote d'Ivoire which he wanted to used for his political ambition in our Country before he was assassinated.

Now I and my sister have decided to invest these money
in your country or anywhere safe enough for security and political reasons.We want you to help us contact the security company here as my late fathers foreign business partner and the beneficiary of the deposited trunk box containing the fund and give them immediate instruction to release and deliver the trunk box to you through their
international diplomatic courier service to your
Country.

As soon as you comfirm the trunk box to your possession, I and my only sister will come over to meet you for the possible investment and continue our education in your country.We will like to invest part of the money into these three investment in your Country but, if there is any other business that is better than our suggestion, wewill be very glad to follow your advice.you can cell me us this +225 07 18 19 43,or private email;(dan_johns_anna81@yahoo.fr)

1). Real estate
2). The transport industry
3). Five star hotel

If you can be of an assistance to us we will be
pleased to offer to you 20% Of the total fund while
the balance will be invested by you.

We await your soonest response.

Respectfully yours,
Mr. Daniel Johnson and sister





#5 Dec 13 2008 at 5:20 AM Rating: Good
AnnaDaniel

From Mr.Daniel Johnson and sister
Private and Confidential
Abidjan - Côte d'Ivoire
private(dan_johns_anna81@yahoo.fr)


My dear ,

It is our pleasure to contact you for a business
venture which I and my Sister,intend to establish in
your country.Though we have not met with you before
but we believe, one has to risk confiding in someone
to succeed sometimes in life.There is this amount of
FIFTEEN Million US Dollars ($15.000.000.00)which our late Father deposited in a private security company here in Abidjan Capital city of Cote d'Ivoire which he wanted to used for his political ambition in our Country before he was assassinated.

Now I and my sister have decided to invest these money
in your country or anywhere safe enough for security and political reasons.We want you to help us contact the security company here as my late fathers foreign business partner and the beneficiary of the deposited trunk box containing the fund and give them immediate instruction to release and deliver the trunk box to you through their
international diplomatic courier service to your
Country.

As soon as you comfirm the trunk box to your possession, I and my only sister will come over to meet you for the possible investment and continue our education in your country.We will like to invest part of the money into these three investment in your Country but, if there is any other business that is better than our suggestion, wewill be very glad to follow your advice.you can cell me us this +225 07 18 19 43,or private email;(dan_johns_anna81@yahoo.fr)

1). Real estate
2). The transport industry
3). Five star hotel

If you can be of an assistance to us we will be
pleased to offer to you 20% Of the total fund while
the balance will be invested by you.

We await your soonest response.

Respectfully yours,
Mr. Daniel Johnson and sister




No seriously this looks TOTALLY legit. I already sent them my SS#, Bank Accounts and address. I should expect my first 1.2 Million to be deposited on Monday. Least thats what KleepKlop told me.
#6 Dec 13 2008 at 7:05 AM Rating: Excellent
Spankatorium Administratix
*****
1oooo posts
thenewdays wrote:
Stuff...


All accounts@allakhazam.com come directly to my mailbox, I have received nothing from you. Info@ goes somewhere else but he would have forwarded it to me. If you are sending every day, it's probably marked spam and is hit by a filter either on the alla server or by my e-mail provider. Considering there are several ways to contact admin and staff, spamming our mailboxes probably wasn't the best way to attempt a solution with this issue.

Now for the issue. Those are spoofed, obviously you know that by checking the headers and finding that they do not come from us. I am not sure what you think we can do about them since they are not from us and we have no control over the sender. Your best bet to stop them from coming to you is to turn off your publicise (yes that is how it is spelled on the site, not everyone uses a z Smiley: rolleyes) e-mail in your account settings and that should stop you from receiving any more unwanted spam or virii laden e-mail.
____________________________

#7 Dec 13 2008 at 9:30 AM Rating: Excellent
Avatar
******
29,919 posts
The most prevelent recent spam attack, the ones that appear to be from "staff@allakhazam" or "anyrandomadminname@allakhazam" are originating out of several servers in China. The attacks are being orchestrated by the same ******** who keep spamming the forum with the "naked wife satalite" crap, and the PM spam from "randomfemalenamewith4extraletters" advertising dating sites.

This is a full on attack, though largely ineffective so far due to the forum protections. They are using a script to generate new accounts. in the last week, my personal banned account count has tripled my total for the entire time I have been an admin.

We are under siege, but we will prevail, because there is one thing these ******** didn't count on:

Wombats!!!
____________________________
Arch Duke Kaolian Drachensborn, lvl 95 Ranger, Unrest Server
Tech support forum | FAQ (Support) | Mobile Zam: http://m.zam.com (Premium only)
Forum Rules
#8 Dec 15 2008 at 5:21 AM Rating: Good
I'm surprised a high profile site like this doesn't use captcha for registration!
#9 Dec 15 2008 at 8:22 AM Rating: Excellent
Bad j00 j00
Avatar
***
2,159 posts
Captcha at best keeps the totally clueless spammers away. At worst it drives away people from using the site. We've done as much as we can to prevent having to resort to captcha over the years. I think you'd be quite surprised at how many attempts there are a week by spammers that are either killed within 30 minutes or just never really become an issue.

Personally I find captcha extremely annoying. Any captcha that isn't easy cracked is also really hard for me to read, personally. I have excellent eyesight but that is not the problem. The problem is that the text is so obfuscated that it takes several attempts to get it right. By this point I'm sufficiently annoyed that I usually give up or never go back.

If you are interested in reading how crackable captcha is, you might be interested in this article.

The lengths that this pm spammer had to go through just to put out the number of PMs they did is rather impressive. It wasn't even close to worth their effort.
#10 Dec 15 2008 at 8:36 AM Rating: Decent
Wow, I never expected them to ship captcha solving out to real people, that must be one hell of a job, especially at $0.08 per 1000 captchas solved!

I do think that they are a pain but I have no problem with them at registration, at posting/pm now that's a different matter!

I think Alla should use these captchas:

Screenshot


Smiley: lol
#11 Dec 15 2008 at 9:30 AM Rating: Excellent
Bad j00 j00
Avatar
***
2,159 posts
Kelnoen the Malevolent wrote:

Screenshot

Smiley: lol


Smiley: cry Smiley: motz Smiley: cry

That's one of the worst captchas I've seen yet.
#12 Dec 15 2008 at 4:42 PM Rating: Excellent
Avatar
******
29,919 posts
Yeah, I've literally banned over 2000 accounts in the last 3 days. for those 2000 accounts, maybe 200 PMs got through to 40 different people give or take.
____________________________
Arch Duke Kaolian Drachensborn, lvl 95 Ranger, Unrest Server
Tech support forum | FAQ (Support) | Mobile Zam: http://m.zam.com (Premium only)
Forum Rules
#13 Dec 15 2008 at 4:58 PM Rating: Excellent
Spankatorium Administratix
*****
1oooo posts
Kao is the shiznit!
____________________________

#14 Dec 16 2008 at 6:57 AM Rating: Decent
Keeper of the Shroud
*****
13,632 posts
Dread Lörd Kaolian wrote:
Yeah, I've literally banned over 2000 accounts in the last 3 days. for those 2000 accounts, maybe 200 PMs got through to 40 different people give or take.


That'll be more impressive when it's over 9000. Ok, I couldn't resist. But, as one of the people that got one of these messages, I'd just like to take this opportunity to thank you all for the hard work. I'm nowhere near fool enough to fall for one of their silly attempts, but it's nice to know that you guys are taking it seriously.
Reply To Thread

Colors Smileys Quote OriginalQuote Checked Help

 

Recent Visitors: 31 All times are in CST
Anonymous Guests (31)