Thursday, August 16, 2001

Yahoo! Personals Spam Update


Got another e-mail from that brittany girl at hotmail wanting me to call her at the chat line... note the additional social engineering at work ("I have to pay too").

------------------------------------------------
Date: Thu, 16 Aug 2001 10:47:27 -0400
From: Brittany323@hotmail.com
Subject: Your personal ad

Hey,
I have not heard from you yet, I have to pay to talk on the line as
well.
I know it is weird but I use this as a safety precaution for myself.
As I told you in my earlier mail, I have had some problems with giving
out
my phone number in the past.
Well I would really like to get to know you better,so when you get
this,drop
me a line.
Talk to you later...
-Brittany

http://www.one-on-onechat.com/3822.html
------------------------------------------------

So I did some more digging trying to find other profiles on the site. Finally I stumbled across the fact that their /graphics folder will return a list of all of the files in that directory. Since I already knew that the profiles were a 4 digit number, the fact that there were a bunch of .gif files that were just numbers gave me the final clue in order to check the other profiles on the web site (there are no links to the profiles off of the root page). Here's a short list of what I found:

10503 - Bethany

10506 - Bethany (again)

10509 - (yet another) Bethany

10512 - Bethany (and again)

10518 - Bethany (another one?)

12312 - Kimberly (gee, a new name)

Here's the full list of ID numbers: 10503 10506 10509 10512 10515 10518 11403 11406 11409 11412 11415 12303 12306 12309 12312 12315 13203 13206 13209 13212 13215 3186 3822 96 (you can take stabs at the rest of the URLs)

This has SCAM written all over it now and I'm debating whether it's worth getting Verio or the BBB involved (since I think I could track the web owner down since it looks like he lives in Baltimore). I reckon that the images are stolen from another personals site.

If you have the time (and a high bandwidth line), you could download the access logs for the site (the one log is over 200Mb and the error log is around 20Mb).

Labels:



posted by Wuphon's at 9:32 PM

Powered by Blogger Who's linked to me?