Page 1 of 2

To0d Showgun, has the board been compromised by ninjas?

Posted: Tue Aug 14, 2007 17:42 -0700
by Dustykat
I got this in my email box:

Hello

My name Prisca. I am good looking, humble, respectful, caring , sexy and loving .I saw your profile in www.usagiyojimbo.com and it got me interested and i decided to know more about you. kindly get in touch with me through this email: prisca_san@yahoo.com ,So that i can tell you more about myself and as well send my picture to you.

Hope to hear from you soon.

Regards, Prisca.

It originaly came from a hotmail account. I dont know if this person is an actual member or if this is a scam.

Just letting you know so you can check it out.

Ever vigilent

Dusty

Posted: Tue Aug 14, 2007 18:45 -0700
by Samurai of the Stars
Man... that's creepy... sorta funny, though...

Posted: Tue Aug 14, 2007 22:29 -0700
by Steve Hubbell
I recieved one as well.

Funny thing is that the message is sent from a hotmail account but the reply address given is a yahoo account.

Posted: Wed Aug 15, 2007 2:21 -0700
by Fanfan
I sent an email to Todd in order he remove my email address from here :
http://usagiyojimbo.com/membership/retainers.html

With bot and so on, this page is an invitation to spam...

Posted: Wed Aug 15, 2007 12:13 -0700
by Todd Shogun
I took out all of the email addresses on that page. The bots can also get email addresses from forums like this one I believe...not certain.

Posted: Thu Aug 16, 2007 1:24 -0700
by Fanfan
In the forum you can only send a PM message. I don't think there is any problem with that.

I have looked how to add the email without problem

the best way is to add a formulary contact (cgi or php)
I did it on UY.fr : http://usagiyojimbo.fr/tinc?key=HdjNA42 ... me=Contact
time to time i receive spam, but the address is not finishing in a listing

this looks very good too (it is a protection again bots, not human...):
http://www.dynamicdrive.com/emailriddler

Posted: Thu Aug 16, 2007 8:01 -0700
by Treadwell
Bots can farm email addresses from wherever they're posted publicly. If your email address is given in a post or your signature (even if it's really an email LINK and not textual), they can get it.

That's why people type them as myemail (at) whatever (dot) com

Posted: Thu Aug 16, 2007 8:07 -0700
by Todd Shogun
Fanfan wrote:In the forum you can only send a PM message. I don't think there is any problem with that.
Actually, you can send email from the forum. Most everyone here has to enter a valid email address to sign up...it's stored and when you click on the email button at the bottom of someone's post, you can send email to them. The work around would be to simply go in and change your email address to a bogus address or insert the "[removethis]" tag to disguise it. I myself use a bogus email address todd@usagiyojimbo.com which is currently not in use. No spam in my Yahoo or my real UsagiYojimbo.com account!

Posted: Thu Aug 16, 2007 10:35 -0700
by Treadwell
Or you can just turn off the email feature in your control panel, so no need to register under a bogus address. Note that there is no email link at the bottom of my posts.

Posted: Thu Aug 16, 2007 11:33 -0700
by Todd Shogun
Treadwell wrote:Or you can just turn off the email feature in your control panel, so no need to register under a bogus address. Note that there is no email link at the bottom of my posts.
Yes there is:

Image

And when I hover over it, it displays what the address is. It may not appear for standard-level users, but it's there...and the bots WILL find it!

Posted: Thu Aug 16, 2007 14:12 -0700
by Treadwell
Oh, the board software is smart enough to know that I wouldn't need to email myself so it doesn't display it. :oops:

Posted: Thu Aug 16, 2007 16:00 -0700
by sschroeder
Treadwell wrote:Oh, the board software is smart enough to know that I wouldn't need to email myself so it doesn't display it. :oops:
No, I think Todd Shogun can see it because he has Admin/Mod level access. I can't see it on your posts as a regular user, for example (and you should not be able to see mine).

I wonder if Todd is being a little too pessimistic (or exaggerating for humorous effect). What he is saying implies all the user emails are unprotected for a bot to find. That's possible but feels unlikely.

I've also heard most bots only farm off regular pages so the most likely source of those spams is email listed in profile pages or posts.

Posted: Thu Aug 16, 2007 16:17 -0700
by estee
I feel so rejected...none of these internet loonies ever stalk me. :cry:

Posted: Thu Aug 16, 2007 20:43 -0700
by Steve Hubbell
Sounds like something from a Bruce Willis movie.......
"I see email addresses!" :D
estee wrote:I feel so rejected...none of these internet loonies ever stalk me. :cry:
Hey estee, would you like us to send you some spam?

Speaking of spam, I have a relatively new and all but unused Yahoo email address. I set it up strictly to allow me to registered a seperate image shack account, and the only email sent from it was the image shack registration message forwarded to my hotmail address. The address is not listed anywhere, except imageshack. I checked the mail at that address recently after two months and it had close to five pages of spam accumulated. :D

Posted: Fri Aug 17, 2007 21:09 -0700
by Todd Shogun
I'm not so certain the bots are getting it from the site itself anymore. I just got PM'd by a relatively newer member who says the same email was sent to his work email address, which exists only in the DojoList Mailing List! He used his GMail account on the DojoBoard. It could be that the bots are piggybacking on to the UYD mailing list. God only knows how they're able to do that. I'm still investigating.