INTERACT FORUM

Please login or register.

Login with username, password and session length
Advanced search  
Pages: [1] 2 3   Go Down

Author Topic: Fake PayPal Spam Problem  (Read 43387 times)

kragorn

  • Regular Member
  • Recent member
  • *
  • Posts: 17
  • I'm a llama!
Fake PayPal Spam Problem
« on: January 09, 2004, 02:16:57 am »

This morning I received one of the standard "Paypal Verification" scams in my e-mail.  Nothing strange with that, delete and move on, but ...

I have my own domain and whenever I register somewhere I use a unique address, eg. when I registered for this forum I used 'fromjriver@'.  This is the ONLY place I've used that address.

The Paypal scam was sent to 'fromjriver@'.  How did the scammer get this unique address?
Logged

RhinoBanga

  • Citizen of the Universe
  • *****
  • Posts: 1703
  • Developer
Re:Do JRiver Sell E-Mail Addresses?
« Reply #1 on: January 09, 2004, 02:49:08 am »

Funnily enough I got one yesterday too.

I generally use my hotmail account when registering with forums but this is one of the few places where I used my real address and that is where I received the email.



P.S.  That's a good trick with the email addys.   I am going to change to that system.
Logged

ChicoSelfs

  • Regular Member
  • Citizen of the Universe
  • *****
  • Posts: 1079
Re:Do JRiver Sell E-Mail Addresses?
« Reply #2 on: January 09, 2004, 02:57:29 am »

I received one E-Mail from Pay-pal too  ?
Logged
Made in Portugal

gpvillamil

  • Citizen of the Universe
  • *****
  • Posts: 829
  • Listen to the music...
Re:Do JRiver Sell E-Mail Addresses?
« Reply #3 on: January 09, 2004, 03:08:37 am »

Weird. I got one too. It went to my personal e-mail address, which is long and complicated, so I don't think they were just randomly generating addresses.

For those of you new to the subject, if you received an e-mail purporting to be from Paypal asking you to verify your identity, IGNORE IT. It is a scam to get your payment info. Paypal will only ever interact with you through their own website. Read their security guidelines.

If you received such an e-mail, please post to this thread.
Logged

georgem29

  • Regular Member
  • Recent member
  • *
  • Posts: 48
Re:Do JRiver Sell E-Mail Addresses?
« Reply #4 on: January 09, 2004, 03:11:15 am »

I also have my own domain and create unique addresses for individual companies I deal with.  I got the PayPal scam email to the address I used to register Media Center and register for this forum.  I've never used it for anything else.

I'd like to hear JRiver's explanation.
Logged

sirshambling

  • Regular Member
  • Galactic Citizen
  • ****
  • Posts: 379
  • real soul lives on....
Re:Do JRiver Sell E-Mail Addresses?
« Reply #5 on: January 09, 2004, 03:22:05 am »

Add me to the list of recipients.
Logged

JaWe

  • Regular Member
  • World Citizen
  • ***
  • Posts: 100
Re:Do JRiver Sell E-Mail Addresses?
« Reply #6 on: January 09, 2004, 03:25:13 am »

I got one too  ?
Logged

DJMUK

  • Regular Member
  • Junior Woodchuck
  • **
  • Posts: 76
Re:Do JRiver Sell E-Mail Addresses?
« Reply #7 on: January 09, 2004, 04:13:10 am »

I got 2 some hours apart - How Lucky I am!!! ;D

They were both to my main address which I use for all software/forum registrations.

EDIT: Should have said that I did not purchase MC with PayPal - Just in case it helps JRiver get to the bottom of this.
Logged

Marko

  • Guest
Re:Do JRiver Sell E-Mail Addresses?
« Reply #8 on: January 09, 2004, 04:14:10 am »

I got one too.
Well actaully, I got a couple. different mail addresses for different versions.

Now, please, please, please tell me.....

I'm almost certain jriver don't sell e-mail lists. (If I'm wrong, It'll end my association with MC)
If jriver don't sell e-mail lists, then it looks quite likely they have been compromised in some way, if that's the case, is it only e-mails they got? or should I cancel my credit card?
Logged

Jaguu

  • MC Beta Team
  • Citizen of the Universe
  • *****
  • Posts: 1336
Re:Do JRiver Sell E-Mail Addresses?
« Reply #9 on: January 09, 2004, 04:18:10 am »

Received 4 emails from Paypal, my jaguu email address is hardly known, just 2 or 3 very definite places such as this forum.
Logged

zevele10

  • Guest
Re:Do JRiver Sell E-Mail Addresses?
« Reply #10 on: January 09, 2004, 04:24:46 am »

They are still sleeping....hard time when starting the day job.

I cannot beleive that they sell email adress-I really mean it-
I did not get any ,but i did not buy MC10

So ,did all of you updated to MC10?
How is the mail?
A real PayPal ?
Or a prank?
Logged

Stilton

  • Regular Member
  • Junior Woodchuck
  • **
  • Posts: 56
Re:Do JRiver Sell E-Mail Addresses?
« Reply #11 on: January 09, 2004, 04:27:47 am »

In a vain attempt to combat spam, I use special different email addresses for everything I sign up for on the 'net (my ISP allows anything@username.ips.com, so I set anything to be what I'm signing up for).

I used one email, prefixed 'jriver@', to purchase the jriver software. I use one prefixed mc@ to sign up for this forum.

I received a spam to both of these accounts this morning. This is rather worrying on both accounts.  I've got 'hide email addresses from public' ticked in my profile, so my forum email address shouldn't be available to spam bots. My jriver@ one should only be stored securely with jriver.

I'm not suggesting you're selling our email addresses, but this is rather worrying. You may want to check over your security on where you store our emails. I'm sure I haven't used these emails anywhere else - definately not outside jriver.

The spams were paypal phishing. If anyone else got the same, please post here.
--------------------------------------------------

Good to see I'm not the only one who's looking for an explanation on this one.

I have not purchased v10, so that's not it.
Logged

RhinoBanga

  • Citizen of the Universe
  • *****
  • Posts: 1703
  • Developer
Re:Do JRiver Sell E-Mail Addresses?
« Reply #12 on: January 09, 2004, 04:28:41 am »

I haven't updated to v10 and I got the email.

Maybe the board was hacked?
Logged

retrospek

  • Regular Member
  • Junior Woodchuck
  • **
  • Posts: 93
  • Hello !
Re:Do JRiver Sell E-Mail Addresses?
« Reply #13 on: January 09, 2004, 04:37:11 am »

I've also received a Paypal scam message this morning using the same address as I used for JRiver  :o

Mark.
Logged

zevele10

  • Guest
Re:Do JRiver Sell E-Mail Addresses?
« Reply #14 on: January 09, 2004, 04:43:54 am »

look like good news that not only mc10 buyers got it
Logged

kragorn

  • Regular Member
  • Recent member
  • *
  • Posts: 17
  • I'm a llama!
Re:Do JRiver Sell E-Mail Addresses?
« Reply #15 on: January 09, 2004, 04:56:04 am »

So ,did all of you updated to MC10?
How is the mail?
A real PayPal ?
Or a prank?
The e-mail address I received it on was only ever used to register on this forum .. I am not a registered MC user, only on this forum am I 'known' to JRiver, so this forum's member record for me is the only place I know of that 'fromjriver@xxx' is recorded.

RhinoBanga has a good point.

It's a scam .. using the by-now conventional means of obscuring the real destination of the link by appending lots of 0x01s to the URL which Outlook Express and Internet Explorer don't show .. I use Poco and Firebird so saw them ;).


PS, I'm STILL not a llama.  :D
Logged

zevele10

  • Guest
Re:Do JRiver Sell E-Mail Addresses?
« Reply #16 on: January 09, 2004, 04:59:15 am »

ok
so calm down
all of us
Logged

Stilton

  • Regular Member
  • Junior Woodchuck
  • **
  • Posts: 56
Re:Do JRiver Sell E-Mail Addresses?
« Reply #17 on: January 09, 2004, 05:21:20 am »

ok
so calm down
all of us

It's actually quite serious. Not only has my forum address been grabbed, but also the confidential one used to register to jriver.

If it was only the the forum one's it's not as serious - likely a bug in the forum software. But for the registration emails to somehow get in the hands of spammers could have compromised other data, such as CC details.

Can anyone else say for sure that it is specifically jriver registration email address that was spammed (NOT their forum one)?

The spams are called 'phishing' - pretending to be an official email and sending the user off to collect their information (such as passwords, or CC details) (see http://www.urbandictionary.com/define.php?term=phishing). The URL in the email uses the classic 'username' method - the URL looks like it's going to paypal.com, but actually it's going to another domain, logging in with the username 'www.paypal.com'. The actual domain you'll see at the end of the long URL, not usually in sight because of all the 0s obscuring it out of view.
Logged

TimB

  • Citizen of the Universe
  • *****
  • Posts: 1062
Re:Do JRiver Sell E-Mail Addresses?
« Reply #18 on: January 09, 2004, 06:08:43 am »

I have my own domain and whenever I register somewhere I use a unique address, eg. when I registered for this forum I used 'fromjriver@'.  This is the ONLY place I've used that address.

VERY cool idea!

No spam of this type received here.

-=Tim=-
Logged
Boy do I LOVE Media Center!!!

JimH

  • Administrator
  • Citizen of the Universe
  • *****
  • Posts: 71548
  • Where did I put my teeth?
Re:Do JRiver Sell E-Mail Addresses?
« Reply #19 on: January 09, 2004, 06:57:46 am »

We don't sell or otherwise provide your e-mail address to anyone.  

Many of these schemes are based on worms that can read an e-mail address book and then use the addresses to send more and also use the addresses as the sender name.  So if the address was in an e-mail address book anywhere, it's possible for the worm to find it.

A second possibility is that someone's e-mail server is being used to capture addresses.

Another possibility is that the addresses are publicly visible here on Interact.  Can you see each other's addresses?  If so, a robot can collect them.

Still another is that addresses are being randomly generated.  fromjriver would be a logical one.

There are other possibilities, but WE DO NOT PROVIDE YOUR ADDRESS TO ANYONE ELSE.
Logged

kragorn

  • Regular Member
  • Recent member
  • *
  • Posts: 17
  • I'm a llama!
Re:Do JRiver Sell E-Mail Addresses?
« Reply #20 on: January 09, 2004, 07:12:57 am »

Many of these schemes are based on worms that can read an e-mail address book and then use the addresses to send more and also use the addresses as the sender name.  So if the address was in an e-mail address book anywhere, it's possible for the worm to find it.

A second possibility is that someone's e-mail server is being used to capture addresses.

Another possibility is that the addresses are publicly visible here on Interact.  Can you see each other's addresses?  If so, a robot can collect them.

Still another is that addresses are being randomly generated.  fromjriver would be a logical one.

There are other possibilities, but WE DO NOT PROVIDE YOUR ADDRESS TO ANYONE ELSE.


1. My e-mail address would not be in ANY address book, I have never had e-mail contact with anyone else here, only your board's database knows it AFAICS.

2. Unlikely since I've never sent an e-mail from that address and only 1 has ever been delivered to me when I registered some time ago.

3. My e-mail address is marked "Hidden" in my member record.

4. 'fromjriver' is extremely UNLIKELY IMO.

MANY MEMBERS ARE REPORTING THIS.  If you say you don't pass on e-mail addresses given to you then I'll accept that, however it seems highly suspicious that the recipt of this scam by so many members means the source of the e-mail addresses IS YOUR BOARD.  

If you refuse to accept that as a possibility, as you are doing by invoking that list of possibilities which I have easily demolished, then clearly customers and potential users of this board need to be wary, because your systems could have been compromised and you appear to be doing nothing to look into it.
Logged

JimH

  • Administrator
  • Citizen of the Universe
  • *****
  • Posts: 71548
  • Where did I put my teeth?
Re:Do JRiver Sell E-Mail Addresses?
« Reply #21 on: January 09, 2004, 07:19:23 am »

Did I say that we would not investigate it?  Sorry for the omission.  It's 7:00AM here.

fromjriver is extremely likely, IMO.  from + domain name.

It would be nice if you would not make sinister assumptions about what has happened.
Logged

JimH

  • Administrator
  • Citizen of the Universe
  • *****
  • Posts: 71548
  • Where did I put my teeth?
Re:Do JRiver Sell E-Mail Addresses?
« Reply #22 on: January 09, 2004, 07:23:04 am »

Can everyone add a reply here that tells us the domain name of your mail server?  hotmail.com or aol.com, for example.
Logged

jleerigby

  • Guest
Re:Do JRiver Sell E-Mail Addresses?
« Reply #23 on: January 09, 2004, 07:24:45 am »

Just to add to the list of recipients I got one too.  I was amazed as this is the first spam I've seen since I changed the e-mail address about 3 months ago.  I too only use this address for MC so I was immediately worried about how on earth someone got hold of this address.  

I can't imagine that any worm invaded my PC as I am very careful as to which sites I visit (mostly it's just interact) and NAV 2003 is constantly up to date.  My wife uses the PC regularly and she has had no such e-mail - neither has anyone else I've spoken to at work or freinds or family.
Logged

zevele10

  • Guest
Re:Do JRiver Sell E-Mail Addresses?
« Reply #24 on: January 09, 2004, 07:29:05 am »

OK

Please.let try to have the most indications  ready for when they start to look at.

ME: email adress visible on interact==NO email sent to me-
adress yahooFR [ not COM]
NEXT!
Logged

jleerigby

  • Guest
Re:Do JRiver Sell E-Mail Addresses?
« Reply #25 on: January 09, 2004, 07:35:56 am »

I'm going to keep a creaful eye on my CC statement.  I hope Jim confirms they'll look into this.
Logged

RhinoBanga

  • Citizen of the Universe
  • *****
  • Posts: 1703
  • Developer
Re:Do JRiver Sell E-Mail Addresses?
« Reply #26 on: January 09, 2004, 07:38:36 am »

I have my own domain jdnet.co.uk.

They got my personal name too, jamie.

I can't see how both of these could have been randomly generated.   Also my mail server did not pick up any non-deliverable messages.

Now my email address is only registered on 2 boards (this and another one).   No-one on the other board has reported this situation whereas others have reported it here.   The facts are pointing this way.



P.S.  My email is hidden from public view on both boards.
Logged

JollyJim

  • Regular Member
  • World Citizen
  • ***
  • Posts: 217
Re:Do JRiver Sell E-Mail Addresses?
« Reply #27 on: January 09, 2004, 07:47:44 am »

I got two this morning from paypal to xxxx.freeserve.co.uk
Logged

bob

  • Administrator
  • Citizen of the Universe
  • *****
  • Posts: 13561
Re:Do JRiver Sell E-Mail Addresses?
« Reply #28 on: January 09, 2004, 07:56:23 am »

It sounds to me like someone found a way to pull the database but doing a quick check, I haven't found any notifications of holes in this version of the software. I also tried a few tricks that would lead me to be able to pull the database but they didn't work.

I'll keep looking...
Logged

kragorn

  • Regular Member
  • Recent member
  • *
  • Posts: 17
  • I'm a llama!
Re:Do JRiver Sell E-Mail Addresses?
« Reply #29 on: January 09, 2004, 08:01:26 am »

It's clearly not a dictionary attack, I've received no others.
Logged

gpvillamil

  • Citizen of the Universe
  • *****
  • Posts: 829
  • Listen to the music...
Re:Do JRiver Sell E-Mail Addresses?
« Reply #30 on: January 09, 2004, 08:03:14 am »

Better post a sticky and an urgent announcement on the board, warning users about the fake mail. Most of us are pretty aware and won't fall for it, but others might not be so careful. Might also want to e-mail all users of the board and warn them of the compromise.
Logged

kragorn

  • Regular Member
  • Recent member
  • *
  • Posts: 17
  • I'm a llama!
Re:Do JRiver Sell E-Mail Addresses?
« Reply #31 on: January 09, 2004, 08:06:33 am »

It just occurred to me there may have been one other place I entered my e-mail address .. when you download a trial version there's an optional registration page, I now can't recall if I entered it there or not, I usually don't offer my details unless I'm forced to but it is possible I may have done.

Clearly many of your members and customers would also have entered details on that page.
Logged

KingSparta

  • MC Beta Team
  • Citizen of the Universe
  • *****
  • Posts: 20049
Re:Do JRiver Sell E-Mail Addresses?
« Reply #32 on: January 09, 2004, 08:17:38 am »

Funnily enough I got one yesterday too.

I generally use my hotmail account when registering with forums but this is one of the few places where I used my real address and that is where I received the email.



P.S.  That's a good trick with the email addys.   I am going to change to that system.

I already talked to paypal yesterday, and submitted the info from the orginal message.

it seems this is going around, per their message back to me

they are working on shutting down the spammer

the one i got also had a Virus attached to it that was stripped out by Road Runner (My Provider)
Logged
Retired Military, Airborne, Air Assault, And Flight Wings.
Model Trains, Internet, Ham Radio
https://MyAAGrapevines.com
https://centercitybbs.com
Fayetteville, NC, USA

kragorn

  • Regular Member
  • Recent member
  • *
  • Posts: 17
  • I'm a llama!
Re:Do JRiver Sell E-Mail Addresses?
« Reply #33 on: January 09, 2004, 08:22:38 am »

It could be just the time difference, but I notice that there are a lot of UK users here.  Mail server hack in the UK?

I don't see where the e-mail address used to target me would ever have been present on any mail server other than yours.  My domain is virtually hosted by mail is received using normal MX record resolution AFAIK and is not forwarded, hence anything sent from you to me would not be staged elsewhere.

Also it's hosted on a small local web hoster, the chances of 2 of their customers also being present here is very, very small IMHO.
Logged

JimH

  • Administrator
  • Citizen of the Universe
  • *****
  • Posts: 71548
  • Where did I put my teeth?
Re:Do JRiver Sell E-Mail Addresses?
« Reply #34 on: January 09, 2004, 08:27:23 am »

Correct me if I'm wrong, but I believe that the e-mail address is visible in the packets forwarded from machine to machine across the Internet, so if any machine in between is compromised, they could be collected there.
Logged

ChicoSelfs

  • Regular Member
  • Citizen of the Universe
  • *****
  • Posts: 1079
Re:Do JRiver Sell E-Mail Addresses?
« Reply #35 on: January 09, 2004, 08:27:36 am »

my email is from my provider netvisao.pt
Logged
Made in Portugal

JimH

  • Administrator
  • Citizen of the Universe
  • *****
  • Posts: 71548
  • Where did I put my teeth?
Re:Do JRiver Sell E-Mail Addresses?
« Reply #36 on: January 09, 2004, 08:38:35 am »

Logged

LisaRCT

  • Guest
Re:Do JRiver Sell E-Mail Addresses?
« Reply #37 on: January 09, 2004, 08:43:06 am »

I got it too . . .
Yahoo.com
Logged

DJMUK

  • Regular Member
  • Junior Woodchuck
  • **
  • Posts: 76
Re:Do JRiver Sell E-Mail Addresses?
« Reply #38 on: January 09, 2004, 08:44:39 am »

Can everyone add a reply here that tells us the domain name of your mail server?  hotmail.com or aol.com, for example.


JimH, In case it helps mine is: dial.pipex.com

My email address is not used exclusively for this forum and/or registration of MC.  I only opened a PayPal account on 20/09/2003 to purchase a shareware program that had no other payment options.  I bought MC by CC.

If my memory serves me I also got one of these PayPal spoofs about 6-8 weeks ago.

Hope this helps.

David
Logged

RhinoBanga

  • Citizen of the Universe
  • *****
  • Posts: 1703
  • Developer
Re:Do JRiver Sell E-Mail Addresses?
« Reply #39 on: January 09, 2004, 08:45:12 am »

Correct me if I'm wrong, but I believe that the e-mail address is visible in the packets forwarded from machine to machine across the Internet, so if any machine in between is compromised, they could be collected there.

But the suspicious fact here is that it's a high number of interact users that have been spammed.

I don't know of anyone else who has got it who isn't an interact user.
Logged

John Gateley

  • Citizen of the Universe
  • *****
  • Posts: 4957
  • Nice haircut
Re:Do JRiver Sell E-Mail Addresses?
« Reply #40 on: January 09, 2004, 08:45:17 am »

Hi Y'all,

A couple of things:

JLee, cc info is never on the machine that supports interact, though keeping a close eye on your statement is always a good thing.

Those of you who are SURE that you got the spam because of this board, did you use the chat room? Is that a possible source of the spam?

j

RhinoBanga

  • Citizen of the Universe
  • *****
  • Posts: 1703
  • Developer
Re:Do JRiver Sell E-Mail Addresses?
« Reply #41 on: January 09, 2004, 08:46:14 am »

Hi Y'all,

Those of you who are SURE that you got the spam because of this board, did you use the chat room? Is that a possible source of the spam?

j


No as I have a fake email addy on irc, usually me@you.com.
Logged

JimH

  • Administrator
  • Citizen of the Universe
  • *****
  • Posts: 71548
  • Where did I put my teeth?
Re:Do JRiver Sell E-Mail Addresses?
« Reply #42 on: January 09, 2004, 08:51:01 am »

But the question was "did you use the chat room?"

Sounds like you did.
Logged

ChicoSelfs

  • Regular Member
  • Citizen of the Universe
  • *****
  • Posts: 1079
Re:Do JRiver Sell E-Mail Addresses?
« Reply #43 on: January 09, 2004, 08:51:51 am »

By the way i don't have an paypal account
Logged
Made in Portugal

RhinoBanga

  • Citizen of the Universe
  • *****
  • Posts: 1703
  • Developer
Re:Do JRiver Sell E-Mail Addresses?
« Reply #44 on: January 09, 2004, 08:53:03 am »

Quote
But the question was "did you use the chat room?"

Sounds like you did.

Correct but I am pointing out that my IRC email address is fake so a whois on me would have resulted in a fake address.
Logged

retrospek

  • Regular Member
  • Junior Woodchuck
  • **
  • Posts: 93
  • Hello !
Re:Do JRiver Sell E-Mail Addresses?
« Reply #45 on: January 09, 2004, 08:56:35 am »

I don't believe I've ever used the Chat Room - In fact I didn't even know we had one available...

I'm wondering if maybe a 'plugin' has required us to provide our email address somewhere along the line - and maybe that person has been hacked somehow...

I can't remember though if I've had to provide my email details for any plug-ins.

My email address is hosted by plus.net in the UK

Cheers,

Mark

P.S. Good job I was running Mailwasher - which highlighted that this was a dodgy email from Paypal..
Logged

crowfan

  • Regular Member
  • Galactic Citizen
  • ****
  • Posts: 302
  • For every sprinkle I find, I shall kill you.
Re:Do JRiver Sell E-Mail Addresses?
« Reply #46 on: January 09, 2004, 08:56:46 am »

I have two email addresses: optonline.net and yahoo.com. Both emails received the PayPal spoof.

I use my Yahoo account for anything that I think will generate spam.

I use my optonline account here at Interact, and I *never* get spam in that account.

I am located in NY.

Hope this helps,

crow
Logged
"It's going to be a trilogy."   Robert Jordan, circa 1989

John Gateley

  • Citizen of the Universe
  • *****
  • Posts: 4957
  • Nice haircut
Re:Do JRiver Sell E-Mail Addresses?
« Reply #47 on: January 09, 2004, 08:57:32 am »

If you got the spam, could you please post the header info (minus personal details) here please? I need to know if they all came from the same mailer.

Rhino - did you use a real e-mail address when registering, and was it the same one as here? I know the public one wasn't, but it is possible the chat room was hacked.

j

Deivit

  • Citizen of the Universe
  • *****
  • Posts: 1215
  • I find your interest interesting...
Re:Do JRiver Sell E-Mail Addresses?
« Reply #48 on: January 09, 2004, 08:59:07 am »

Got two emails... one yesterday the other one today. Reported the first one to paypal.

The address is the one I use with this forum and to register Media Center, but I use it for other purposes too, so I cannot be sure of the origin.

The address is xxxx @ yahoo (not .com but .es)

Edit: Never used the chat room. My email is hidden here on my Interact profile.
Logged

markp99

  • Regular Member
  • World Citizen
  • ***
  • Posts: 191
Re:Do JRiver Sell E-Mail Addresses?
« Reply #49 on: January 09, 2004, 09:00:18 am »

got one on my xxx@comcast.net account...


Actually...looking at header, it was my attbi.com account, forwarded to comcast.
Logged
Pages: [1] 2 3   Go Up