Author Topic: I'm receiving SPAM(fb) photos from your website  (Read 4131 times)

billvelek

  • Guest
I'm receiving SPAM(fb) photos from your website
« on: November 04, 2006, 02:14:20 PM »
I received an email that purported to be from your site, so I followed a copy of links and ended up with pornography.  I'm confident that the email was not sent by you, but figured you would want to know about it.  Here is the souce code from the entire message, including header:

From - Wed Nov 01 04:30:57 2006
X-UIDL: <9283f2e1e46459e6087f7bbfab6a3229-p97@beersmith.com>
X-Mozilla-Status: 0005
X-Mozilla-Status2: 00000000
X-Symantec-TimeoutProtection: 0
Return-Path: <root@beersmith.com>
Received: from ispmxaamta02-gx.windstream.net ([69.36.164.3])
          by ispmxmta02-srv.windstream.net with ESMTP
          id <20061101102408.FYTJ23266.ispmxmta02-srv.windstream.net@ispmxaamta02-gx.windstream.net>
          for <my email addy deleted for this post>; Wed, 1 Nov 2006 04:24:08 -0600
Received: from beersmith.com ([69.36.164.3])
          by ispmxaamta02-gx.windstream.net with ESMTP
          id <20061101102408.RVLQ14291.ispmxaamta02-gx.windstream.net@beersmith.com>
          for <my email addy deleted for this post>; Wed, 1 Nov 2006 04:24:08 -0600
Received: (from root@localhost)
   by beersmith.com (8.11.6/8.11.6) id kA1AO5O10941;
   Wed, 1 Nov 2006 03:24:05 -0700
To: <my email addy deleted for this post>
Subject: New Personal Message: IMPORTANT NEWS AND INFORMATION!!!
From: "BeerSmith Community" <beersmith@beersmith.com>
Date: Wed, 01 Nov 2006 10:23:31 +0000
Message-ID: <9283f2e1e46459e6087f7bbfab6a3229-p97@beersmith.com>
X-Mailer: SMF
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

You have just been sent a personal message by AmyH on BeerSmith Community.

IMPORTANT: Remember, this is just a notification. Please do not reply to this email.

The message they sent you was:

If you have some time check out this COOL pic:
[URL DELETED fb] Also, check out the following website I came across:
[URL DELETED fb]
It will knock your socks off!
Next, the below website is thrilling!!!
[URL DELETED fb]
Finally, the following website is the absolute BOMB!!!
[URL DELETED fb]
ENJOY!!!

MY PIC: [URL DELETED fb]
Reply to this Personal Message here: http://www.beersmith.com/forum/index.php?action=pm;sa=send;f=inbox;pmsg=97;quote;u=923

**** End of email ****

I don't appreciate that, and if the message somehow originated from your site or your forums, I hope you will do something about it.

Thanks.

Bill Velek -- HomeBrewer not interested in pornography
www.2plus2is4.com
« Last Edit: November 04, 2006, 06:38:27 PM by bonjour »

mortong

  • Guest
Re: I'm receiving pornography from your website
« Reply #1 on: November 04, 2006, 02:37:18 PM »
This probably isn't actually from Beersmith.com.  The way most spam programs work is they take control of a machine through a trojan horse type program.  They then access your email records and randomly choose an email address that you've had contact with and spam people using that email address as a faked "sent from" email.

This indicates that someone on this forum or who has bought Beersmith has an infected machine.  Update your antivirus and run a spyware check; make sure it's not you.

Offline bonjour

  • Global Moderator
  • BeerSmith Grandmaster Brewer
  • *****
  • Posts: 566
    • Beer du Jour
Re: I'm receiving Spam from your website
« Reply #2 on: November 04, 2006, 06:34:30 PM »
Bill,  this board was spammed and every forum had the post you describe published.  At the same time a number of users were, as you were here, PM'd, Private messaged This was removed the morning this occured but the PM's are not accessible by the moderators because the are considered private.   You may read our initial responses in the news section.  I knew of 10 members that were PM'd, myself included, you are the 11th.

I appreciate your sending the entire post as that is helpful in understanding what happened.  Because the posts containg the URL's of the pornography I am going to edit the URL's out.

We do not tolerate this at all and are working to do what we can to prevent this from happening.

Fred Bonjour
Moderator

Offline BeerSmith

  • Brewer, Author, Patriot
  • BeerSmith Administrator
  • BeerSmith Grandmaster Brewer
  • *****
  • Posts: 5568
  • BeerSmith - take the guesswork out of brewing!
    • BeerSmith
Re: I'm receiving SPAM(fb) photos from your website
« Reply #3 on: November 05, 2006, 01:08:02 AM »
Bill,
  I'm just as unhappy as you that someone exploited the forum to distribute this kind of filth.

  Basically, an overseas user created a valid account, posted a bunch of junk on the forum and then started sending Private Messages to people with the same offensive spam.  As soon as we found out (perhaps an hour later), we deleted the offending forum messages, and shut down the private messaging system.  Unfortunately we could not recall the private messages that were sent out to those who have email notification set for these types of messages.

  We also found the offending user, deleted his account, banned his IP address from the forum, and took at least 6 other steps to increase the security of the forum and try to prevent this kind of junk from being posted again.  Unfortunately it is very difficult to lock out malicious users from a public site without also locking out legitimate users.  That's why we have moderators assigned to look for offensive messages and take appropriate action when it does occur.

  I apologize to anyone who received an offensive message.  We will continue to work to improve the security of the forum.  Hopefully legitimate users will not allow the actions of one malicious person deter them from using the forum for legitimate brewing discussion.

Cheers!
Brad Smith
beersmith.com
Get a free trial of BeerSmith 3 here

 

modification