Online Casinos - Casinomeister Logo Online Casinos - Casinomeister
Results 1 to 5 of 5

Thread: Privacy nightmare

  1. #1
    lifechooser is offline Full Member
    Join Date
    Oct 2006
    Location
    Southampton, UK
    Posts
    28
    Thanks
    13
    Thanked 11 Times in 5 Posts
    Rep Power
    22
    Reputation Points: 65

    Privacy nightmare

    I've just recieved a piece of spam which has left me speechless. I know that many casinos have let my details slip, something which has left me angry, but feeling powerless, but check this out;

    -------------

    from Richard Robbins <RichardtRobbinsyfdc118@********.com> hide details 4:40 pm (6 hours ago)
    to liuqinghai0625@********.com.cn
    cc littlewoods1@********.org,
    liujian_81_81@********.com,
    littlewoods@********.co.uk,
    liukep@********.it,
    livayka@********.com,
    liubeck@********.bg,
    liusumin@********.cn,
    liuxong@********.com
    date Jan 19, 2008 4:40 PM
    subject great bonus
    mailed-by srs.kundenserver.de

    Dear Player,

    Be the next big winner and let our casino change your life with the biggest bonus, the biggest games and the biggest payouts

    Download now! Copy Paste Url to your browser>> http://connicantua6.googlepages.com

    ------------

    You'll note that of all these addresses, it only covers addresses starting LI. Exactly how many addresses have been slipped by the casinos? I see at least one other littlewoods address, one of them is mine.

    ******'s added by myself.

    ------------
    Headers;
    Received-SPF: pass (google.com: domain of SRS0=Qebu=SJ=hotmail.com=*********@srs.kundenserve r.de designates 212.227.126.174 as permitted sender) client-ip=212.227.126.174;
    Authentication-Results: mx.google.com; spf=pass (google.com: domain of SRS0=Qebu=SJ=hotmail.com=************@srs.kundense rver.de designates 212.227.126.174 as permitted sender) smtp.mail=SRS0=Qebu=SJ=hotmail.com=************@sr s.kundenserver.de
    Received-SPF: pass (mxeu24: domain of hotmail.com designates 65.54.246.214 as permitted sender) client-ip=65.54.246.214; envelope-from=***********@hotmail.com; helo=bay0-omc3-s14.bay0.hotmail.com;
    Received: from bay0-omc3-s14.bay0.hotmail.com (bay0-omc3-s14.bay0.hotmail.com [65.54.246.214])
    by mx.kundenserver.de (node=mxeu24) with ESMTP (Nemesis)
    id 0MKtd6-1JGGkw082F-00057S for littlewoods@********.co.uk; Sat, 19 Jan 2008 17:41:18 +0100
    Received: from BAY113-W10 ([65.54.168.110]) by bay0-omc3-s14.bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.3959);
    Sat, 19 Jan 2008 08:40:26 -0800
    Message-ID: <BAY113-W100A43229783361F6ACA0F95430@phx.gbl>
    Return-Path: ************@hotmail.com
    Content-Type: multipart/alternative;
    boundary="_cac4c1b6-3a98-432f-85c3-8bfdd5da9242_"
    X-Originating-IP: [24.174.196.223]

  2. #2
    winbig's Avatar
    winbig is offline mmmm, Foxy.
    Achievements:
    VeteranCreated Album picturesCreated Blog entry50000 Experience PointsPeople Likes You
    Join Date
    Mar 2005
    Location
    Pennsylvania
    Posts
    8,228
    Blog Entries
    4
    Thanks
    1,371
    Thanked 3,608 Times in 2,120 Posts
    Rep Power
    165
    Reputation Points: 19093
    Don't be so paranoid

    From what it looks like to me, this list was generated by a brute force attack against multiple email servers...by trying multiple combinations of names, letters and numbers until they come across an address that works, then stored it for later use.


    Once they had a list of working addresses compiled, they simply alphabetized the list and mailed out their spam.

    It pretty much looks like amateurs that sent this out, as they forgot to BCC everyone that this mail went to.
    Operators: If you don't know what Transparency means, then here you go.....now how about practicing it?

    Transparency, as used in the humanities and in a social context more generally, implies openness, communication, and accountability. It is a metaphorical extension of the meaning a "transparent" object is one that can be seen through. ...

  3. #3
    lifechooser is offline Full Member
    Join Date
    Oct 2006
    Location
    Southampton, UK
    Posts
    28
    Thanks
    13
    Thanked 11 Times in 5 Posts
    Rep Power
    22
    Reputation Points: 65
    As stated previously, these addresses are not gained through brute force, they have been leaked. If they were brute force, I would recieve multiple spam to differentrandomletters@mydomain.co.uk, as it is, the spam goes to littlewoods@, ritzclub@, totesport@ etc, for most of the casinos I've ever registered with.

    I got another one today, cc'd to;
    plasticpaddy57@***********.com
    plato@***********.co.uk,
    playboy@***********.co.uk,
    player-a-status@***********.com,
    platins@***********.lv,
    player71@***********.pl,
    plasticoter@***********.com,
    platon.sandrine@***********.fr,
    player81@***********.ro

    Again, 9 addresses, just covering the first 2 letters.

  4. #4
    winbig's Avatar
    winbig is offline mmmm, Foxy.
    Achievements:
    VeteranCreated Album picturesCreated Blog entry50000 Experience PointsPeople Likes You
    Join Date
    Mar 2005
    Location
    Pennsylvania
    Posts
    8,228
    Blog Entries
    4
    Thanks
    1,371
    Thanked 3,608 Times in 2,120 Posts
    Rep Power
    165
    Reputation Points: 19093
    Quote Originally Posted by lifechooser View Post
    As stated previously, these addresses are not gained through brute force, they have been leaked. If they were brute force, I would recieve multiple spam to differentrandomletters@mydomain.co.uk, as it is, the spam goes to littlewoods@, ritzclub@, totesport@ etc, for most of the casinos I've ever registered with.

    I got another one today, cc'd to;
    plasticpaddy57@***********.com
    plato@***********.co.uk,
    playboy@***********.co.uk,
    player-a-status@***********.com,
    platins@***********.lv,
    player71@***********.pl,
    plasticoter@***********.com,
    platon.sandrine@***********.fr,
    player81@***********.ro

    Again, 9 addresses, just covering the first 2 letters.
    *shrug* I don't know what I'm talking about, I've only dealt with spammers for years.
    Operators: If you don't know what Transparency means, then here you go.....now how about practicing it?

    Transparency, as used in the humanities and in a social context more generally, implies openness, communication, and accountability. It is a metaphorical extension of the meaning a "transparent" object is one that can be seen through. ...

  5. #5
    vinylweatherman's Avatar
    vinylweatherman is offline Ueber Meister Achievements:
    Veteran50000 Experience PointsOverdrivePeople Likes YouFriends R Us
    Awards:
    Frequent PosterCommunity AwardMost Popular
    Join Date
    Oct 2004
    Location
    United Kingdom
    Posts
    10,224
    Thanks
    373
    Thanked 6,441 Times in 3,454 Posts
    Rep Power
    257
    Reputation Points: 35319
    I think I know what the point is.

    If it was a brute force attack, it would reveal ALL working addresses, such a brute force attack would have no way of determining whether the addresss were gambling related or not. It would follow that spam would fall equally on all the working addresses on the attacked mailserver.
    If the spam hits only a subset of working Email addresses, it means the addresses have a common bond that the unspammed ones don't share.
    In this case, the common bond is that the spammed addresses have all been registered at online casinos, and the unspammed ones have not.
    The obvious conclusion is that the list was not gained through brute force alone, but that the attack was seeded from a list of addresses that had leaked from online casino databases. A brute force attack just on these would confirm which of these were still working, and which were not. This would allow the list to be further refined, and then sold on.
    If this spammer is daft enough to forget to use BCC, surely they are too stupid to conduct a brute force attack themselves, and probably got hold of these addresses as a ready made list.
    Email addresses are the least secure pieces of information, as casinos have to pass these out to the agencies that handle their bulk mailings to regular players. It is these third parties, rather than the casinos, that present the greatest risk of leakage.
    Empty Fruities Astern Capt'n
    Back to port for unloading.
    Full Sails - before we get raided ourselves.

Similar Threads

  1. Privacy, Internet Billing Services / Grand Virtual and a bit of a rant!
    By Shocked in forum Casino Complaints - Non-Bonus Issues
    Replies: 3
    Last Post: 24th December 2007, 01:51 AM
  2. Poker Stars toughens up player privacy
    By jetset in forum Casinomeister's Poker Room
    Replies: 6
    Last Post: 7th October 2007, 07:51 AM
  3. Intercasino/ECash/Neteller Withdrawal Nightmare
    By mongol80 in forum Online Casinos
    Replies: 12
    Last Post: 19th February 2007, 11:13 AM
  4. Neteller - GoldenPalace nightmare
    By deedee23 in forum Online Casinos
    Replies: 22
    Last Post: 16th November 2006, 05:52 AM
  5. More Cirrus Nightmare
    By Garage3 in forum Casino Complaints - Non-Bonus Issues
    Replies: 15
    Last Post: 5th August 2006, 03:34 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Legal Statements and Privacy Policy
Casinomeister.com does not intend for any of the information contained on this website to be used for illegal purposes. You must ensure you meet all age and other regulatory requirements before entering a casino or placing a wager. Online gambling is illegal in many jurisdictions and users should consult legal counsel regarding the legal status of online gambling and gaming in their jurisdictions. The information in this site is for news and entertainment purposes only. Casinomeister.com is an independent directory and information service free of any gaming operator's control. Links to third party websites on Casinomeister.com are provided solely for informative/educational purposes. If you use these links, you leave this Website.