Some spammer is mass spewing emails with subjects like "<name>, Fuck their Faces then spurt chunks all over them!!!!" joe-jobbed against all sorts of domains that appear to have nothing in common. Friends have alerted me to their situation, and all I could say is "me too".
I'll post more details about the spammer in question as a response to this journal entry when I find out more details. Meanwhile, if you've been joe-jobbed by this spammer, post a response to this journal (I know there are at least two other journal entries here on use perl about this) containing the headers of the original email (assuming the bounce contained them) and I'll find out more details.
Here's an example of the mails I'm getting:
Return-path: <utashiro@dave.org.uk>
Received: from crane-hp.pocket ([10.4.120.44] helo=crane)
by volcano.mail.pas.earthlink.net with smtp (Exim 3.33 #1)
id 1953dH-0003V9-00
for elnmall@corp.earthlink.net; Mon, 14 Apr 2003 06:04:23 -0700
X-MindSpring-Loop: elnmall@earthlink.net
Received: from compuserve.com ([210.8.112.211])
by crane (EarthLink SMTP Server) with SMTP id 1953Dc2Bc3NZFjC0
for <fryan02@themall.net>; Mon, 14 Apr 2003 06:04:13 -0700 (PDT)
Date: Mon, 14 Apr 2003 13:04:10 +0000
From: utashiro@dave.org.uk
Subject: Fryan02, WoW!!
To: Fryan02 <fryan02@themall.net>
References: <@themall.net>
In-Reply-To: <@themall.net>
Message-ID: <06A8FF13HF3G03H6F@dave.org.uk>
Sender: Phi <phi@winning.com>
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=_NextPart_H74I4J.2CC527L4ELIF1_..J_"
Of course, now "utashiro@dave.org.uk" will be picked up by the spam robots and I'll start getting spam there
Return-Path:
Received: (from mailnull@localhost) by drjimmy.it.northwestern.edu (8.12.9/8.12.9) id h3E4kqxG008069 for ; Sun, 13 Apr 2003 23:46:52 -0500 (CDT)
Received: from compuserve.com (unknown [211.147.1.109]) by drjimmy.it.northwestern.edu via smap (V2.0) id xma007813; Sun, 13 Apr 03 23:46:45 -0500
Date: Mon, 14 Apr 2003 04:00:19 +0000
X-Phforward: V2.5@drjimmy (nwu.edu)
From: kenn@drewtaylor.com
Subject: Hbnguyen, Fuck their Faces then spurt chunks all over them!!!!
To: Hbnguyen <hbnguyen@nwu.edu>
References: <2EBF32J9.23D890JD@nwu.edu>
In-Reply-To: <2EBF32J9.23D890JD@nwu.edu>
Message-ID: <H3KJLL..43B52L8A4@drewtaylor.com>
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=_NextPart_A.2_EK92211G_6EH7_4DA8_0."
Re:Here's another one
ajtaylor on 2003-04-14T14:28:22
Oops, the return path should have been:Return-Path: <kenn@drewtaylor.com>
Unfortunately I've killed all my AOL and Compuserve ones this morning.Return-Path: <hilliard@missbarbell.co.uk>
Received: (qmail 16840 invoked by uid 840); 14 Apr 2003 12:50:25 -0000
Received: from hilliard@missbarbell.co.uk by mail.seacove.net with qmail-scanner-1.01 (fsecure: 4.14/4062/2003-04-10/2002-12-17. 2003-04-09/. Clean. Processed in 1.475296 secs); 14 Apr 2003 12:50:25 -0000
Received: from unknown (HELO Microsoft.com) (61.4.77.74)
by mail.seacove.net with SMTP; 14 Apr 2003 12:50:24 -0000
Date: Mon, 14 Apr 2003 12:04:00 +0000
From: hilliard@missbarbell.co.uk
Subject: Strobel, I Got So Hard With This Product...
To: Strobel <strobel@seacove.net>
References: <49D84BB3.1HE8HBA5@seacove.net>
In-Reply-To: <49D84BB3.1HE8HBA5@seacove.net>
Message-ID: <AFKCH1H995CCCHHF7@missbarbell.co.uk>
Return-path: <GST_BAILEY@missbarbell.co.uk>
Received: from adsl-66-138-124-39.dsl.wchtks.swbell.net ([66.138.124.39] helo=compuserve.com)
by granger.mail.mindspring.net with smtp (Exim 3.33 #1)
id 194yX0-00058M-00
for jsutphen@mindspring.com; Mon, 14 Apr 2003 03:37:38 -0400
Date: Mon, 14 Apr 2003 06:51:10 +0000
From: GST_BAILEY@missbarbell.co.uk
Subject: Jsutphen, Fuck their Faces then spurt chunks all over them!!!!
To: Jsutphen <jsutphen@mindspring.com>
References: <H0FI85294909JJHG6@mindspring.com>
In-Reply-To: <H0FI85294909JJHG6@mindspring.com>
Message-ID: <37GE15ECF4A75H2.9@missbarbell.co.uk>
Note: (changed @ to --AT-- for jbisbee.com)Received: from rcpt-impgw.biglobe.ne.jp by biglobe.ne.jp (RCPT_GW)
id AAA27215; Tue, 15 Apr 2003 00:42:17 +0900 (JST)
Received: from microsoft.com ([211.115.209.218])
by rcpt-impgw.biglobe.ne.jp (nkrw/3410050802) with SMTP id h3EFgE727185
for <gons@mte.biglobe.ne.jp>; Tue, 15 Apr 2003 00:42:15 +0900 (JST)
Date: Mon, 14 Apr 2003 14:55:51 +0000
From: btr --AT-- jbisbee.com
Subject: Gondou Youichi, Christina Aguilera's infamous topless video!
+i1g5UUczUBbx4WDIlhWU5HNoE1qfKNb4
To: Gondou Youichi <gons@mte.biglobe.ne.jp>
References: <3CBJAG1E9LF0B8L5A@mte.biglobe.ne.jp>
In-Reply-To: <3CBJAG1E9LF0B8L5A@mte.biglobe.ne.jp>
Message-ID: <FE8DE8BDH90IG4H5G --AT-- jbisbee.com>
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=_NextPart_G9DJAI0LDD_5_JE_8__A_F.61"
They just keep coming.
ct on 2003-04-14T17:38:29
Received: from bryson.student.princeton.edu ([140.180.144.5]
+helo=compuserve.com)
by dragon.relcom.ru with smtp
id 1957GI-000JSL-00 for dmk@ru.net; Mon, 14 Apr 2003 20:56:55 +0400
Date: Mon, 14 Apr 2003 16:56:46 +0000
From: jbnivoit@cthompson.com
Subject: \325\356\360\356\370\345\345
\361\340\354\356\367\363\342\361\362\342\350\345
To: Dmk <dmk@ru.net>
References: <HEFG.3H92BDH7EAJ.@ru.net>
In-Reply-To: <HEFG.3H92BDH7EAJ.@ru.net>
Message-ID: <DLG79C9DI.DLIGA38@cthompson.com>
MIME-Version: 1.0
Content-Type: multipart/mixed;
+boundary="----=_NextPart_D_._LH.4._7.1KI_8J_I_IA0B"
And a good thing I just check my spam file. There was a rather important false positive.
False positives
vsergu on 2003-04-14T21:22:57
Yes, you really should remind your family, friends, and clients not to use the word "p3n1z" in e-mail to you.
The battle has been joined!
Re:Conspiracy theory
jbisbee on 2003-04-14T19:57:21
Yes it would appear that they screen scraped use.perl.org's member list somehow and used it to seed the 'From:' email header. I've been relatively spam free up until this point to. I guess I'm not getting spam at this point, just bounces, but it still sucks.:(
Return-Path:
Received: from compuserve.com ([142.59.85.193])
by southgate.starhub.net.sg (8.12.5/8.12.5) with SMTP id h3F0wQXC013985
for ; Tue, 15 Apr 2003 08:58:27 +0800 (SST)
Date: Tue, 15 Apr 2003 00:12:05 +0000
From: markn@rubberband.org
Subject: FW: Rajen, Check this out, :)
To: Rajen
References:
In-Reply-To:
Message-ID:
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=_NextPart_617_6D.H2H_DL9J__8_C6K.D3"
I've been getting these since at least April 5th. The From: header seems to be my domain name (wickline dot org) with some semi-random username on the front of it. Some of the usernames lead me to suspect that perhaps user names are being harvested from some perl source. For example, here are a few user names from today: Koenig, guntermann, iandstanley, tbekel, xpix, artis, tzoompy, giegerich, leonvs, fila, Boubaker, jkeen, tori, palmieri.On or before March 28th, someone harvested some addresses
They pulled from several technical mailing lists
(or possibly from NNTP interfaces to those lists)
Those included perl lists, but were not exclusively perl.
Around March 28th, that list was used
(to send the 'Swiss Group' spam)
By around April 5th that list saw wider distribution
(probably sold to some other spammers)
Around April 5th, someone used the list in their spamming
software to generate bogus From headers and presumably
genuine To headers. I've been the victim of having an
address of mine used in the From: header of a spam
message, and on that occasion I received hundreds of
bounces and complaints. From what I'm seeing, I'd say
that their software is generating a new bogus From:
header for each recipient.
and the email addresses were those I'd used to post to various geeky lists (not the user@example.com above). They were usernames (at my domain) like the following:Re: user@example.com, Swiss Group Switzerland ! Earn up to 2 daily in the Swish Stock Exchange !
Note that the last username was never used in a perl-specific list. The first four were perl-specific, and the penultimate username was used in many contexts some years ago. At about the same time (March 28th), I also saw this same form of spam at several work email addresses. Some of those had been used to post to mailing lists, and others were not.m_module_authors
m_perltrainers_digest
m_libwww_digest
m_pause
m_listbox
m_ to-validatorlist-re_tagclosing
-mattReceived: from compuserve.com (c-24-125-58-3.va.client2.attbi.com [24.125.58.3])
by vmk.prodigy.net (8.12.9/8.12.3) with SMTP id h3EN2Uiu176762
for <mariuszwojciuk@prodigy.net>; Mon, 14 Apr 2003 19:02:30 -0400
Date: Mon, 14 Apr 2003 22:16:08 +0000
=============
Received: from w151.z064000245.lax-ca.dsl.cnc.net
(64.0.245.151)
by mail01h.rapidsite.net (RS ver 1.0.80vs) with SMTP id 4-310779139
for <efdr@ageless.com>; Mon, 14 Apr 2003 15:55:49 -0400 (EDT)
Date: Mon, 14 Apr 2003 19:55:47 +0000
=============
Received: from [61.4.77.74] ([61.4.77.74]:17490 "HELO tccity.com" ident:
"NO-IDENT-SERVICE[2]" whoson: "-unregistered-" smtp-auth: <none>
TLS-CIPHER: <none> TLS-PEER-CN1: <none>) by gnome06.net.rol.ru
with SMTP id <S9942136AbTDNSdG>; Mon, 14 Apr 2003 22:33:06 +0400
Date: Mon, 14 Apr 2003 18:32:56 +0000
=============
Received: from compuserve.com (6532116hfc40.tampabay.rr.com [65.32.116.40])
by relay.wplus.net (8.11.7/8.11.6/Wplus-RELAY) with SMTP id h3EESEH20570
for <cleoltd@mail.wplus.net>; Mon, 14 Apr 2003 18:28:16 +0400 (MSD)
Date: Mon, 14 Apr 2003 14:28:10 +0000
=============
Received: from aar.alcatel-alsthom.fr ([203.177.63.185]) by mailin01.sul.t-online.com
with smtp id 193KVD-11VTKGC; Wed, 9 Apr 2003 20:40:55 +0200
Date: Wed, 09 Apr 2003 17:54:04 +0000
Re:I don't think it's use.perl.org they've scraped
sneex on 2004-02-14T09:06:25
This is why I change addresses frequently.
=/
-Sx-
Can somebody explain to me why this file even exists?