Some spammer is mass spewing emails with subjects like "<name>, Fuck their Faces then spurt chunks all over them!!!!" joe-jobbed against all sorts of domains that appear to have nothing in common. Friends have alerted me to their situation, and all I could say is "me too".
I'll post more details about the spammer in question as a response to this journal entry when I find out more details. Meanwhile, if you've been joe-jobbed by this spammer, post a response to this journal (I know there are at least two other journal entries here on use perl about this) containing the headers of the original email (assuming the bounce contained them) and I'll find out more details.
Re: Mass Joe Job (Score:2)
Here's an example of the mails I'm getting:
Here's another one (Score:1)
"Perl users are the Greatful Dead fans of computer science." --slashdot comment
Re:Here's another one (Score:1)
"Perl users are the Greatful Dead fans of computer science." --slashdot comment
Murderers, Rapists and Spammers (Score:1)
Received: from compuserve.com (pcp036474pcs.unl.edu [129.93.204.37])
by msgdirector3.onetel.net.uk (Mirapoint Messaging Server MOS 3.2.2-GA)
with SMTP id AQC48679;
Sun, 13 Apr 2003 22:36:39 +0100 (BST)
From: <dwmalone@cthompson.com>
Date: Sun, 13 Apr 2003 20:50:11 +0000
Subject: Hi, Tmunt, Nasty Girls Getting Down And Dirty!! Username:
+downonthefarm, Password: horsespunk!!
To: Tmunt
another example: (Score:1)
Date: Mon, 14 Apr 2003 00:56:25 +0000
From: Thomas_Bolioli@carline.org
Subject: Dcboy4bm, Fuck their Faces then spurt chunks all over them!!!!
To: Dcboy4bm
References:
In-Reply-To:
Message-ID:
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=_NextPart_BD087I.FA9K.CHK_.J2HIJ0F7"
Super Matt, The Spam Avenger to the rescue (Score:1)
me too (Score:1)
-biz-
Yet More. (Score:1)
Received: from mx11.airmail.net from [209.196.77.108] by mail.airmail.net
(/\##/\ Smail3.1.30.16 #30.56) with esmtp sender: <edv@cthompson.com>
id <mO/1956Sn-001gFRO@mail.airmail.net>; Mon, 14 Apr 2003 11:05:45 -0500
+(CDT)
Received: from danapris.kw.ua ([195.177.71.30] helo=microsoft.com)
by mx11.airmail.net with smtp (Exim 4.10)
id 1956Se-000JYG-00
for sh3010@airm
They just keep coming. (Score:1)
+helo=compuserve.com)
by dragon.relcom.ru with smtp
id 1957GI-000JSL-00 for dmk@ru.net; Mon, 14 Apr 2003 20:56:55 +0400
Date: Mon, 14 Apr 2003 16:56:46 +0000
From: jbnivoit@cthompson.com
Subject: \325\356\360\356\370\345\345
\361\340\354\356\367\363\342\361\362\342\350\345
To: Dmk <dmk@ru.net>
References: <HEFG.3H92BDH7EAJ.@ru.net>
In-Reply-To: <HEFG.3H92BDH7EAJ.@ru.net>
Message-ID:
$name! Gr0w a larger p3n1z (Score:1)
And a good thing I just check my spam file. There was a rather important false positive.
False positives (Score:3, Funny)
Conspiracy theory (Score:1)
The battle has been joined!
Re:Conspiracy theory (Score:2, Insightful)
-biz-
Another (Score:1)
Return-Path: :)Received: from compuserve.com ([142.59.85.193])
by southgate.starhub.net.sg (8.12.5/8.12.5) with SMTP id h3F0wQXC013985
for ; Tue, 15 Apr 2003 08:58:27 +0800 (SST)
Date: Tue, 15 Apr 2003 00:12:05 +0000
From: markn@rubberband.org
Subject: FW: Rajen, Check this out,
To: Rajen
References:
In-Reply-To:
Message-ID:
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=_NextPart_617
I don't think it's use.perl.org they've scraped (Score:4, Interesting)
I've been getting these since at least April 5th. The From: header seems to be my domain name (wickline dot org) with some semi-random username on the front of it. Some of the usernames lead me to suspect that perhaps user names are being harvested from some perl source. For example, here are a few user names from today: Koenig, guntermann, iandstanley, tbekel, xpix, artis, tzoompy, giegerich, leonvs, fila, Boubaker, jkeen, tori, palmieri.
Yes. Those are all from today. Each of those users at my domain was used in the From: header of a bounced spam message. Also, a Google search for each of those usernames and perl (ie "Koenig perl") will turn up hits. So, it seems likely that some perlish source was harvested. However, I'm not sure it's use.perl.org. Some other spam I've seen has left me thinking that someone recently harvested a variety of geeky mailing lists.
Shortly before all this started, I saw spam on previously unspammed addresses used to post to various mailing lists. The spam was sent March 28th, and always had a subject which read
and the email addresses were those I'd used to post to various geeky lists (not the user@example.com above). They were usernames (at my domain) like the following:
Note that the last username was never used in a perl-specific list. The first four were perl-specific, and the penultimate username was used in many contexts some years ago. At about the same time (March 28th), I also saw this same form of spam at several work email addresses. Some of those had been used to post to mailing lists, and others were not.
Most of my mailing list addresses have been safe. Those are all older email addresses. All of my more recent subscriptions have been with usernames (at my domain) in the form m-list-subscribe-list_name_here. The 'list' and 'subscribe' in the address seem to scare off the address harvesting spiders.
So, I've been getting joe-jobbed bounce messages since about April 5th. I also got a small batch of joe-jobbed spam on April 7th. The following usernames (which I've never used from my domain, so I'm assuming must be joe jobbed) appeared in the To: headers of spam messages: gerald_bahorich, losing, gregory_adams, jeff_richmond. The joe jobbed To: headers may or may not be related to the From: header situation. My hunch is that they're two separate things.
On April 12, the St. Louis perl hackers mailing list got a couple bits of spam, but those may not be related. That list hadn't seen spam previously (for around a year that I'm aware of). My cpan address gets a few bits of spam each day, but that's nothing new.
Matt, if you want full headers o
Reply to This
Re:I don't think it's use.perl.org they've scraped (Score:1)
This is why I change addresses frequently.
=/
-Sx-
__Sx_______________________________________
More (Score:1)
compuserve.com" ident: "NO-IDENT-SERVICE[2]" smtp-auth:
TLS-CIPHER: TLS-PEER-CN1: ) by gnome07.net.rol.ru
with SMTP id ; Tue, 15 Apr 2003 20:15:57 +0400
Date: Tue, 15 Apr 2003 16:18:09 +0000
From: eragigr@clueball.com
Subject: ??????????? ????????????? ????????? ??
Addresses on CPAN (Score:1)