Online Casinos - Casinomeister Logo Online Casinos - Casinomeister

Go Back   Casinomeister's Online Casino and Poker Forum > Online Casino and Poker Complaints > Casino Spam Complaints

Notices

Casino Spam Complaints Spam complaints and information about evil spammers is located here.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 19th January 2008, 11:55 PM
Fully Registered
 
Join Date: Oct 2006
Location: Southampton, UK
Posts: 28
WTGs: 0
WTGd at 0 Times in 0 Posts
Thanks: 13
Thanked 11 Times in 5 Posts
Reputation Points: 65
Rep Power: 7
lifechooser is on a distinguished road
Privacy nightmare

I've just recieved a piece of spam which has left me speechless. I know that many casinos have let my details slip, something which has left me angry, but feeling powerless, but check this out;

-------------

from Richard Robbins <RichardtRobbinsyfdc118@********.com> hide details 4:40 pm (6 hours ago)
to liuqinghai0625@********.com.cn
cc littlewoods1@********.org,
liujian_81_81@********.com,
littlewoods@********.co.uk,
liukep@********.it,
livayka@********.com,
liubeck@********.bg,
liusumin@********.cn,
liuxong@********.com
date Jan 19, 2008 4:40 PM
subject great bonus
mailed-by srs.kundenserver.de

Dear Player,

Be the next big winner and let our casino change your life with the biggest bonus, the biggest games and the biggest payouts

Download now! Copy Paste Url to your browser>> http://connicantua6.googlepages.com

------------

You'll note that of all these addresses, it only covers addresses starting LI. Exactly how many addresses have been slipped by the casinos? I see at least one other littlewoods address, one of them is mine.

******'s added by myself.

------------
Headers;
Received-SPF: pass (google.com: domain of SRS0=Qebu=SJ=hotmail.com=*********@srs.kundenserve r.de designates 212.227.126.174 as permitted sender) client-ip=212.227.126.174;
Authentication-Results: mx.google.com; spf=pass (google.com: domain of SRS0=Qebu=SJ=hotmail.com=************@srs.kundense rver.de designates 212.227.126.174 as permitted sender) smtp.mail=SRS0=Qebu=SJ=hotmail.com=************@sr s.kundenserver.de
Received-SPF: pass (mxeu24: domain of hotmail.com designates 65.54.246.214 as permitted sender) client-ip=65.54.246.214; envelope-from=***********@hotmail.com; helo=bay0-omc3-s14.bay0.hotmail.com;
Received: from bay0-omc3-s14.bay0.hotmail.com (bay0-omc3-s14.bay0.hotmail.com [65.54.246.214])
by mx.kundenserver.de (node=mxeu24) with ESMTP (Nemesis)
id 0MKtd6-1JGGkw082F-00057S for littlewoods@********.co.uk; Sat, 19 Jan 2008 17:41:18 +0100
Received: from BAY113-W10 ([65.54.168.110]) by bay0-omc3-s14.bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.3959);
Sat, 19 Jan 2008 08:40:26 -0800
Message-ID: <BAY113-W100A43229783361F6ACA0F95430@phx.gbl>
Return-Path: ************@hotmail.com
Content-Type: multipart/alternative;
boundary="_cac4c1b6-3a98-432f-85c3-8bfdd5da9242_"
X-Originating-IP: [24.174.196.223]
Reply With Quote
  #2 (permalink)  
Old 20th January 2008, 12:01 AM
winbig's Avatar
Redrum, Redrum...
 
Join Date: Mar 2005
Location: Pennsylvania
Posts: 5,060
WTGs: 0
WTGd at 0 Times in 0 Posts
Thanks: 779
Thanked 2,038 Times in 1,208 Posts
Reputation Points: 10532
Rep Power: 91
winbig has a reputation beyond reputewinbig has a reputation beyond reputewinbig has a reputation beyond reputewinbig has a reputation beyond reputewinbig has a reputation beyond reputewinbig has a reputation beyond reputewinbig has a reputation beyond reputewinbig has a reputation beyond reputewinbig has a reputation beyond reputewinbig has a reputation beyond reputewinbig has a reputation beyond repute
Don't be so paranoid

From what it looks like to me, this list was generated by a brute force attack against multiple email servers...by trying multiple combinations of names, letters and numbers until they come across an address that works, then stored it for later use.


Once they had a list of working addresses compiled, they simply alphabetized the list and mailed out their spam.

It pretty much looks like amateurs that sent this out, as they forgot to BCC everyone that this mail went to.
__________________
'Cause I'm stranded all alone in the Gas Station of Love
And I have to use the self-service pumps - Weird Al
Reply With Quote
  #3 (permalink)  
Old 20th January 2008, 10:00 AM
Fully Registered
 
Join Date: Oct 2006
Location: Southampton, UK
Posts: 28
WTGs: 0
WTGd at 0 Times in 0 Posts
Thanks: 13
Thanked 11 Times in 5 Posts
Reputation Points: 65
Rep Power: 7
lifechooser is on a distinguished road
As stated previously, these addresses are not gained through brute force, they have been leaked. If they were brute force, I would recieve multiple spam to differentrandomletters@mydomain.co.uk, as it is, the spam goes to littlewoods@, ritzclub@, totesport@ etc, for most of the casinos I've ever registered with.

I got another one today, cc'd to;
plasticpaddy57@***********.com
plato@***********.co.uk,
playboy@***********.co.uk,
player-a-status@***********.com,
platins@***********.lv,
player71@***********.pl,
plasticoter@***********.com,
platon.sandrine@***********.fr,
player81@***********.ro

Again, 9 addresses, just covering the first 2 letters.
Reply With Quote
  #4 (permalink)  
Old 20th January 2008, 10:12 AM
winbig's Avatar
Redrum, Redrum...
 
Join Date: Mar 2005
Location: Pennsylvania
Posts: 5,060
WTGs: 0
WTGd at 0 Times in 0 Posts
Thanks: 779
Thanked 2,038 Times in 1,208 Posts
Reputation Points: 10532
Rep Power: 91
winbig has a reputation beyond reputewinbig has a reputation beyond reputewinbig has a reputation beyond reputewinbig has a reputation beyond reputewinbig has a reputation beyond reputewinbig has a reputation beyond reputewinbig has a reputation beyond reputewinbig has a reputation beyond reputewinbig has a reputation beyond reputewinbig has a reputation beyond reputewinbig has a reputation beyond repute
Quote:
Originally Posted by lifechooser View Post
As stated previously, these addresses are not gained through brute force, they have been leaked. If they were brute force, I would recieve multiple spam to differentrandomletters@mydomain.co.uk, as it is, the spam goes to littlewoods@, ritzclub@, totesport@ etc, for most of the casinos I've ever registered with.

I got another one today, cc'd to;
plasticpaddy57@***********.com
plato@***********.co.uk,
playboy@***********.co.uk,
player-a-status@***********.com,
platins@***********.lv,
player71@***********.pl,
plasticoter@***********.com,
platon.sandrine@***********.fr,
player81@***********.ro

Again, 9 addresses, just covering the first 2 letters.
*shrug* I don't know what I'm talking about, I've only dealt with spammers for years.
__________________
'Cause I'm stranded all alone in the Gas Station of Love
And I have to use the self-service pumps - Weird Al
Reply With Quote
  #5 (permalink)  
Old 20th January 2008, 02:54 PM
vinylweatherman's Avatar
MunchkinMeister
 
Join Date: Oct 2004
Location: Bracknell, United Kingdom
Posts: 4,050
WTGs: 0
WTGd at 21 Times in 4 Posts
Thanks: 170
Thanked 2,419 Times in 1,244 Posts
Reputation Points: 12740
Rep Power: 99
vinylweatherman has a reputation beyond reputevinylweatherman has a reputation beyond reputevinylweatherman has a reputation beyond reputevinylweatherman has a reputation beyond reputevinylweatherman has a reputation beyond reputevinylweatherman has a reputation beyond reputevinylweatherman has a reputation beyond reputevinylweatherman has a reputation beyond reputevinylweatherman has a reputation beyond reputevinylweatherman has a reputation beyond reputevinylweatherman has a reputation beyond repute
I think I know what the point is.

If it was a brute force attack, it would reveal ALL working addresses, such a brute force attack would have no way of determining whether the addresss were gambling related or not. It would follow that spam would fall equally on all the working addresses on the attacked mailserver.
If the spam hits only a subset of working Email addresses, it means the addresses have a common bond that the unspammed ones don't share.
In this case, the common bond is that the spammed addresses have all been registered at online casinos, and the unspammed ones have not.
The obvious conclusion is that the list was not gained through brute force alone, but that the attack was seeded from a list of addresses that had leaked from online casino databases. A brute force attack just on these would confirm which of these were still working, and which were not. This would allow the list to be further refined, and then sold on.
If this spammer is daft enough to forget to use BCC, surely they are too stupid to conduct a brute force attack themselves, and probably got hold of these addresses as a ready made list.
Email addresses are the least secure pieces of information, as casinos have to pass these out to the agencies that handle their bulk mailings to regular players. It is these third parties, rather than the casinos, that present the greatest risk of leakage.
__________________
http://www.vinylweatherman.net

The woefully out of date guide to Fruit Machines on the UK Motorway network.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Privacy, Internet Billing Services / Grand Virtual and a bit of a rant! Shocked Casino Complaints - Non-Bonus Issues 3 24th December 2007 12:51 AM
Poker Stars toughens up player privacy jetset Casinomeister's Poker Room 6 7th October 2007 07:51 AM
Intercasino/ECash/Neteller Withdrawal Nightmare mongol80 Online Casinos 12 19th February 2007 10:13 AM
Neteller - GoldenPalace nightmare deedee23 Online Casinos 22 16th November 2006 04:52 AM
More Cirrus Nightmare Garage3 Casino Complaints - Non-Bonus Issues 15 5th August 2006 03:34 AM


All times are GMT +2. The time now is 10:44 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0
© All Rights Reserved, 1998-2008


  Casinomeister is proud to present the following quality portals
Online Casinos | GoneGambling | Online Casino Reviews | Wizard of Odds | Games and Casino | Online Poker Rooms | BetOnCharity | Winneronline | Online Casinos| Online Slots | Online Casino Reviews

Legal Statements and Privacy Policy
Casinomeister.com does not intend for any of the information contained on this website to be used for illegal purposes. You must ensure you meet all age and other regulatory requirements before entering a casino or placing a wager. Online gambling is illegal in many jurisdictions and users should consult legal counsel regarding the legal status of online gambling and gaming in their jurisdictions. The information in this site is for news and entertainment purposes only. Casinomeister.com is an independent directory and information service not affiliated with any casino. Links to third party websites on Casinomeister.com are provided solely for informative/educational purposes. If you use these links, you leave this Website.

Inactive Reminders By Mished.co.uk