The Forge Reference Project

 

Topic: Weird spam with forge related addresses?
Started by: Noon
Started on: 9/28/2010
Board: Site Discussion


On 9/28/2010 at 2:30am, Noon wrote:
Weird spam with forge related addresses?

This is odd - I'm getting hundreds of spam e-mails. But the 'To' field has a few names I'm familiar with. I wont say the full e-mail addies, but stuff like sorcerer, lumpley, dindenver, moreno, greyorm, etc at the start and even my own e-mail. This looks like a forge list of e-mails? When the forge was hack crashed awhile back, could someone have simply copied all the e-mail addies as well?

I'm not tech savvy, so I don't know why if they are 'to' these other addresses, they are going to me.

Strange.

Message 30426#280448

Previous & subsequent topics...
...started by Noon
...in which Noon participated
...in Site Discussion
...including keyword:

 (leave blank for none)
...from around 9/28/2010




On 9/28/2010 at 5:08am, Lance D. Allen wrote:
Re: Weird spam with forge related addresses?

I did suddenly start getting a massive amount of spam e-mails myself just this morning, but I didn't recognize any of the addresses.

Message 30426#280451

Previous & subsequent topics...
...started by Lance D. Allen
...in which Lance D. Allen participated
...in Site Discussion
...including keyword:

 (leave blank for none)
...from around 9/28/2010




On 9/28/2010 at 8:01am, masqueradeball wrote:
RE: Re: Weird spam with forge related addresses?

ditto

Message 30426#280454

Previous & subsequent topics...
...started by masqueradeball
...in which masqueradeball participated
...in Site Discussion
...including keyword:

 (leave blank for none)
...from around 9/28/2010




On 9/29/2010 at 6:00am, Sander wrote:
RE: Re: Weird spam with forge related addresses?

I registered here many years ago with an email address unique to this site, and am now starting to get spam to that unique email address. It looks like the forum database has been compromised. This has been happening quite a lot with various forums over the last year. I'd recommend forum admins to update the forum software to the latest version, use stronger passwords for admin access, and ideally to find out exactly how this happened.

Message 30426#280498

Previous & subsequent topics...
...started by Sander
...in which Sander participated
...in Site Discussion
...including keyword:

 (leave blank for none)
...from around 9/29/2010




On 9/29/2010 at 11:48am, lumpley wrote:
RE: Re: Weird spam with forge related addresses?

Thanks for the heads-up. I'm on it.

-Vincent
site admin

Message 30426#280507

Previous & subsequent topics...
...started by lumpley
...in which lumpley participated
...in Site Discussion
...including keyword:

 (leave blank for none)
...from around 9/29/2010




On 10/1/2010 at 9:45am, Artanis wrote:
RE: Re: Weird spam with forge related addresses?

Hi

I was receiving tons of that spam as well on my yahoo account (which is the address given with my Forge account). A recurring pattern in the email subject was "RE:" followed by a single funny character (scientific symbols for male and female, stars, smiley, etc.) Since one or two days I'm not getting these mails any more.

Message 30426#280580

Previous & subsequent topics...
...started by Artanis
...in which Artanis participated
...in Site Discussion
...including keyword:

 (leave blank for none)
...from around 10/1/2010




On 10/1/2010 at 12:23pm, lumpley wrote:
RE: Re: Weird spam with forge related addresses?

Could you all check something for me? Up at the top of the screen, hit "profile," then on the left hit "account related settings." There's an option called "hide email address from public?"

While you've been receiving this spam, has your email address been hidden from the public?

Thanks!

-Vincent

Message 30426#280582

Previous & subsequent topics...
...started by lumpley
...in which lumpley participated
...in Site Discussion
...including keyword:

 (leave blank for none)
...from around 10/1/2010




On 10/1/2010 at 3:28pm, David Artman wrote:
RE: Re: Weird spam with forge related addresses?

I have not hidden the email from public (but I have changed its redirect to head to  my spam account).

What would the email accomplish if hidden? Let's the forum and admins notify us?

Message 30426#280586

Previous & subsequent topics...
...started by David Artman
...in which David Artman participated
...in Site Discussion
...including keyword:

 (leave blank for none)
...from around 10/1/2010




On 10/1/2010 at 3:42pm, lumpley wrote:
RE: Re: Weird spam with forge related addresses?

Yes.

As far as I can tell, the database is secure. The spam is almost certainly just bots trawling users' profile pages.

-Vincent

Message 30426#280587

Previous & subsequent topics...
...started by lumpley
...in which lumpley participated
...in Site Discussion
...including keyword:

 (leave blank for none)
...from around 10/1/2010




On 10/1/2010 at 4:12pm, epweissengruber wrote:
RE: Re: Weird spam with forge related addresses?

Could you make a warning for new members to the site?

Or why not disable the option of having public emails entirely?

Message 30426#280592

Previous & subsequent topics...
...started by epweissengruber
...in which epweissengruber participated
...in Site Discussion
...including keyword:

 (leave blank for none)
...from around 10/1/2010




On 10/1/2010 at 4:19pm, lumpley wrote:
RE: Re: Weird spam with forge related addresses?

Unfortunately, SMF doesn't provide the option to by-default hide users' emails. I might be able to modify the template to take it out.

A warning is a good idea.

-Vincent

Message 30426#280593

Previous & subsequent topics...
...started by lumpley
...in which lumpley participated
...in Site Discussion
...including keyword:

 (leave blank for none)
...from around 10/1/2010




On 10/1/2010 at 8:26pm, C. Edwards wrote:
RE: Re: Weird spam with forge related addresses?

Hey Vincent,

I was receiving the spam as well, and my email address is hidden.

Message 30426#280632

Previous & subsequent topics...
...started by C. Edwards
...in which C. Edwards participated
...in Site Discussion
...including keyword:

 (leave blank for none)
...from around 10/1/2010




On 10/3/2010 at 7:09am, Noon wrote:
RE: Re: Weird spam with forge related addresses?

Mine is checked to hidden as well, and as said, I got the e-mails.

Message 30426#280717

Previous & subsequent topics...
...started by Noon
...in which Noon participated
...in Site Discussion
...including keyword:

 (leave blank for none)
...from around 10/3/2010




On 10/3/2010 at 1:50pm, lumpley wrote:
RE: Re: Weird spam with forge related addresses?

Okay, thanks. I'll keep looking.

-Vincent

Message 30426#280721

Previous & subsequent topics...
...started by lumpley
...in which lumpley participated
...in Site Discussion
...including keyword:

 (leave blank for none)
...from around 10/3/2010




On 10/4/2010 at 12:57am, Noon wrote:
RE: Re: Weird spam with forge related addresses?

I should have mentioned, I stopped recieving mine around the time Christoph's stopped as well. Just in case I gave the impression that I was still getting them.

Message 30426#280734

Previous & subsequent topics...
...started by Noon
...in which Noon participated
...in Site Discussion
...including keyword:

 (leave blank for none)
...from around 10/4/2010




On 10/4/2010 at 2:00pm, Artanis wrote:
RE: Re: Weird spam with forge related addresses?

My email is public and that's fine with me (I accept the risks).

Message 30426#280749

Previous & subsequent topics...
...started by Artanis
...in which Artanis participated
...in Site Discussion
...including keyword:

 (leave blank for none)
...from around 10/4/2010




On 10/7/2010 at 11:40pm, M. J. Young wrote:
RE: Re: Weird spam with forge related addresses?

Vincent, another data point:  my address is not hidden, and I was not getting Forge-related Spam (unless the filters on my account got it and I didn't know it).

--M. J. Young

Message 30426#280890

Previous & subsequent topics...
...started by M. J. Young
...in which M. J. Young participated
...in Site Discussion
...including keyword:

 (leave blank for none)
...from around 10/7/2010




On 10/17/2010 at 10:46pm, Artanis wrote:
RE: Re: Weird spam with forge related addresses?

Hello Vincent

I've started getting some again, starting 00:04 AM central European time (18 October). Latest mail subject is "◇RE: xchnmn2 vrmvqr172" (the funny character is still there, but now what follows is longer).

Message 30426#281179

Previous & subsequent topics...
...started by Artanis
...in which Artanis participated
...in Site Discussion
...including keyword:

 (leave blank for none)
...from around 10/17/2010




On 10/18/2010 at 12:04am, C. Edwards wrote:
RE: Re: Weird spam with forge related addresses?

I received more today as well.

Message 30426#281180

Previous & subsequent topics...
...started by C. Edwards
...in which C. Edwards participated
...in Site Discussion
...including keyword:

 (leave blank for none)
...from around 10/18/2010




On 10/19/2010 at 12:45pm, Seamus wrote:
RE: Re: Weird spam with forge related addresses?

I just started another thread on this, then I noticed this one.

I have been getting them too, and they look like they are connected to forge related emails. I checked the IP of the sender, they are from China. But the names of the emails that sent them look spanish and the subjects have wierd symbols (IP 115.49.94.110, emails ana_esparrago_perez@hotmail.com (etc),

Message 30426#281223

Previous & subsequent topics...
...started by Seamus
...in which Seamus participated
...in Site Discussion
...including keyword:

 (leave blank for none)
...from around 10/19/2010




On 10/20/2010 at 7:51am, Noon wrote:
RE: Re: Weird spam with forge related addresses?

Ya, they've come back with a vengence again. They are mysterious in how they behave and look - someone make an RPG about them...heh

Message 30426#281268

Previous & subsequent topics...
...started by Noon
...in which Noon participated
...in Site Discussion
...including keyword:

 (leave blank for none)
...from around 10/20/2010




On 10/20/2010 at 1:12pm, Seamus wrote:
RE: Re: Weird spam with forge related addresses?

It is a foreign IP so this may be useless, but for anyone who wants to, here is how to report cyber crime (including stuff like this):

http://www.justice.gov/criminal/cybercrime/reporting.htm#cc

Message 30426#281271

Previous & subsequent topics...
...started by Seamus
...in which Seamus participated
...in Site Discussion
...including keyword:

 (leave blank for none)
...from around 10/20/2010




On 10/25/2010 at 10:16am, Artanis wrote:
RE: Re: Weird spam with forge related addresses?

Hello

Mine have stopped again around the 21st. I'll stop reporting on this issue from now on.

Message 30426#281375

Previous & subsequent topics...
...started by Artanis
...in which Artanis participated
...in Site Discussion
...including keyword:

 (leave blank for none)
...from around 10/25/2010