#1 (permalink)  
Old 12-29-2009, 03:37 PM
I'm new here!
 
Join Date: Jan 2009
Posts: 2
Default Spam

For this site, I have a unique, randomly generated 10 character (before the "@" sign), mix of numbers and letters e-mail address that has been used onto sign up for the DPS news letter. I have started receiving spam with pornographic images in them on at that e-mail address.

Since it would be almost impossible for a spammer to guess the e-mail address I'm wondering if a spammer has found a way to get e-mail addresses from a DPS server or if a DPS server is infected with a spamming virus of some sort.

Thank you.
Reply With Quote
  #2 (permalink)  
Old 12-29-2009, 03:45 PM
Sime's Avatar
Must. Get. Coffee. Quick.
 
Join Date: May 2007
Location: Melbourne, Australia
Posts: 6,319
Default

I'm not 100% sure and the technical team in the US are not online right now, nor is Darren (Aus) but I will try to find out for you.

So you know, email is sent in plain text with no encoding a lot of the time - for example, when an email from dPS is sent to you notifying you of a thread update etc - there is always the chance that this communication is capture and your email address harvested - I've worked in IT / IT Security for 8 years up until earlier this year and with many "fail safe" put in place have still seen "secure" emails spammed.

Something else to note is that spammers don't sit there typing in email addresses - a lot of the time they use an application that randomly generates email addresses based on host names e.g. dfiuwhd*& and then they just add @gtvone.com (my domain) and hope they get a hit.

Don't reply.

Change the address if you're concerned...

I will come back to you with an answer.

Simon
Reply With Quote
  #3 (permalink)  
Old 12-29-2009, 03:46 PM
Sime's Avatar
Must. Get. Coffee. Quick.
 
Join Date: May 2007
Location: Melbourne, Australia
Posts: 6,319
Default

Oh and something else to note - the newsletter is served and managed by an external company - sorry, I missed that you said newsletter and then noted that you're not an active forum member (1 post)

I will find out.

Simon
Reply With Quote
  #4 (permalink)  
Old 12-29-2009, 04:01 PM
Dodge's Avatar
Online Frivolity Tour 97-
 
Join Date: May 2009
Location: Northumberland, England
Posts: 544
Default

Hope its ok to poke my nose in here,

If it was the DPS server, everyone on the log in register, or at the least the newsletter register would be getting the spam (Dunno if they are, I forgot to sign up).

I would first run your antivirus to make sure your own PC isn't infected with a Malware virus. The two I use are Avira antivirus and Spybot, both are free to download. (I use two as they both trace different things, one antivirus never finds everything, from my experience.

Avira AntiVir Personal - FREE Antivirus
Spybot - Search & Destroy - Free software downloads and software reviews - CNET Download.com


Again, sorry if i'm telling you stuff you already know, Don't know how computer savvy you are though.
Reply With Quote
  #5 (permalink)  
Old 01-06-2010, 03:04 PM
I'm new here!
 
Join Date: Jan 2009
Posts: 2
Default Spam

I work in IT security for my day job. I won't go into details, but my PCs at home and work are both protected.

Yes, I can change my e-mail address and will do so, but I always like to find out how the spammer found my e-mail address.

The odds of a spammer randomly generating the same 10 character randomly generated e-mail address I use only for this website are astronomical. The last few times this happened, the problem has been traced back to a security problem on the server(s) of the companies I gave an e-mail address too. If a 3rd party maintains the newsletter mailings, I'm betting that's where spammers got my e-mail address.
Reply With Quote
  #6 (permalink)  
Old 01-06-2010, 03:09 PM
maxharvard
Guest
 
Posts: n/a
Default

Quote:
Originally Posted by elguapo View Post
I work in IT security for my day job. I won't go into details, but my PCs at home and work are both protected.

Yes, I can change my e-mail address and will do so, but I always like to find out how the spammer found my e-mail address.

The odds of a spammer randomly generating the same 10 character randomly generated e-mail address I use only for this website are astronomical. The last few times this happened, the problem has been traced back to a security problem on the server(s) of the companies I gave an e-mail address too. If a 3rd party maintains the newsletter mailings, I'm betting that's where spammers got my e-mail address.
I wouldn't put it past them to sell your email address to people.

~Eric
Reply With Quote
  #7 (permalink)  
Old 01-07-2010, 03:54 PM
PnwGuy's Avatar
dPS Forum Member
 
Join Date: Dec 2006
Location: Bellevue WA
Posts: 820
Default

Do a search for your email address. If it is listed somewhere on a website it was probably harvested by a spammer.

I know you're an IT guy so this is more for others. Microsoft has a great new free AV program out called Microsoft Security Essentials. Lightweight and solid. I've used it to remove rootkits which can be very difficult to remove.
__________________
Canon 40D, Canon 400D, Canon EF 50mm f/1.8 II, Canon EF-S 10-22mm f/3.5-4.5, Canon EF 24-70 f2.8L, Canon EF 70-200 f/2.8L IS, Canon EF 100-400 f/4.5-5.6L IS, Speedlites and studio gear.

flickr
Reply With Quote
  #8 (permalink)  
Old 01-26-2010, 08:35 PM
I'm new here!
 
Join Date: Sep 2009
Posts: 1
Default

This will be MY first and last posting as well.

I've been getting vicodin and enlargement spams on this address, and at the same time, the same messages have been coming in on another "disposable" address that I generated for another website. That indicates to me that my info has been sold by both websites and is on a cd somewhere making the rounds among the scumbags.

When I tried the "contact us" to get an explanation, I was unable to send a message because the verification code processor wouldn't accept my input.

VERY DISAPPOINTED!

Bye.

Reply With Quote
  #9 (permalink)  
Old 01-26-2010, 09:25 PM
Darren Rowse's Avatar
Administrator
 
Join Date: Dec 2006
Location: Melbourne Australia
Posts: 699
Default

The explanation for this unfortunate spam is that the service we use to provide our newsletters - Aweber - recently reported that they had a security breach. This meant that some of our newsletter subscribers had their email addresses taken by the hackers and now seem to be getting spam.

We're both embarressed and angered by this and have passed on our feedback to Aweber. It turns out that Aweber's security breach was an outsourced thing too.

All I can really say is that I'm very sorry to those who've had their email addresses compromised.

We do value your privacy and have measures in place to keep details secure and to keep this forum free from spam - however we also do need to rely upon other companies for some parts of what we offer (such as newsletters).

By no means would we sell your details to others - that is certainly not in our best interests as a business - and we'll continue to work hard at keeping our site secure.
__________________
Digital Photography School

Canon EOS 5D - Panasonic GF-1 - Canon Powershot S11
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are Off



Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.

What’s Your Preference?

Daily Digest

Each day we send out a quick email to thousands of DPS readers to notify them of updates. This email is just short excerpt of the first few lines of our latest post with a link if you want to read it all. You can unsubscribe from this this service at any time.

This service is provided by a third party (Feedburner) and you can subscribe to it by leaving your email address in the following field and confirming your subscription when you get an email asking you to do so.

Enter your email address for
Daily Updates:

Weekly Summary

For those wanting a weekly summary of what happens on this site this free email newsletter is probably your best option. It includes a summary of the tips posted to the site each week. This newsletter is subscribed to by over 25000 readers (many who also subscribe to the other options above) - come join the community!

To subscribe to this weekly newsletter simply add your email address to the following field and then follow the confirmation prompts. You will be able to unsubscribe at any time.

Enter your email address for
Free Weekly Newsletter:

 
SEO by vBSEO 3.3.0