eMail Spam fm a MG user

Discussion in 'The Lounge' started by RexB, May 3, 2008.

Thread Status:
Not open for further replies.
  1. RexB

    RexB Private E-2

    ??

    Someone spammed me through my MG email contact page, if this isn't a counterfeit. It asks me to go visit their website, not well written. Anybody else getting these?

    Source:
    --------------------------------------------------------------------------------------
    Return-path: <webmaster@forums.majorgeeks.com>
    Envelope-to: rex@&&&&&.&&&
    Delivery-date: Sat, 03 May 2008 04:25:34 -0700
    Received: from [74.86.200.43] (helo=beta.majorgeeks.com)
    by smtp1.&&&&&&.&& with esmtp (Exim 4.67)
    (envelope-from <webmaster@forums.majorgeeks.com>)
    id 1JsFrt-0002Mx-Aq
    for rex@&&&&&&&&&; Sat, 03 May 2008 04:25:34 -0700
    Received: from localhost (beta.majorgeeks.com.local [127.0.0.1])
    by beta.majorgeeks.com (Postfix) with ESMTP id A8D0ED5419D
    Received: from beta.majorgeeks.com ([127.0.0.1])
    by localhost (beta.majorgeeks.com [127.0.0.1]) (amavisd-maia, port 10024)
    with ESMTP id 18377-02 for <rex@&&&&&&&>;
    Sat, 3 May 2008 06:25:29 -0500 (CDT)
    Received: by beta.majorgeeks.com (Postfix, from userid 2003)
    id 74CC7D541A5; Sat, 3 May 2008 06:22:09 -0500 (CDT)
    To: rex@&&&&&&&&
    Subject: h4ck-y0u.org
    From: "you@majorg33k.com" <you@majorg33k.com>
    Message-ID: <200805031109.7d3a71798023@forums.majorgeeks.com>
    MIME-Version: 1.0
    Content-Type: text/plain; charset="ISO-8859-1"
    X-Priority: 3
    X-Mailer: vBulletin Mail via PHP
    Date: Sat, 3 May 2008 06:22:09 -0500 (CDT)
    Content-Transfer-Encoding: quoted-printable
    X-WNSpam-Score: 0.1
    X-WNSpam-Int: 1
    X-Antivirus: avast! (VPS 080503-0, 05/03/2008), Inbound message
    X-Antivirus-Status: Clean

    Hello,
    please visit a this great security site:

    xxxxxxxxxxxxxxx {DON'T CLICK UNLESS YOU WANT TO GO TO THEIR SITE}

    -------------------------------------------------------------------------------------------------
     
    Last edited by a moderator: May 4, 2008
  2. Clark_Kent

    Clark_Kent MajorGeek

    Yes i just receive the same e-mail today.....

    I will like to have more information about that...

    Is this realy you guys ??? me it say you@majorg33k

    Is you database been hack ???
     
  3. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    While I did get this email to my actual @majorgeeks.com email address I deleted it as it was in spambox, so didnt take much notice of this. I can tell you this email is NOT send from us here at Majorgeeks, likely someone spoofing the MG email addy, so I have forwarded this post onto the owners and rest of admin team for investigation.

    Many thanks for highlighting this and as usual do not goto unknown sites, delete unsolicited spam from your inbox.
     
  4. Gensuknives

    Gensuknives Grand pooty-meister

    I got it too in junk mail box. Deleted without even looking at it.
     
  5. RexB

    RexB Private E-2

  6. augiedoggie

    augiedoggie The Canadian Loon - LocoAugie (R.I.P. 2012)

    Ya, same here, got that POS. :crap I might have to change my account as I'm sure there is a list being sold ATM.
     
  7. Grumbles

    Grumbles Bamboozled Geek

    I hope you guys get to the bottom of this :)
    Kind of worrying though :(

    If there is anything that I can do to help, more than happy to oblige.

    G
     
  8. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    No problems, someone exploited a hole and the problem has been solved, basically the arcade has been removed. It is the repeated cause of many exploits, apparently the author can't keep up, so it is removed. Your account info is secure and not realted.
     
  9. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member

    I was wondering what was going on with the arcade.

    Is it permanently gone?
     
  10. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Yes, we have had security issues on this forum 3 times I can remember. All 3 were arcade exploits. It is the reason we moved the forums to their own servers (to not compromise the main servers) and the reason we must now completely remove it. Sorry.
     
  11. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member

    s'ok (withdrawal may set in though ;))

    Better to be safer.

    Thanks for the reply MA.
     
  12. Sgt. Tibbs

    Sgt. Tibbs Ultra Geek

    Huh, so that came from here? I just deleted it without looking at anything other than the subject line, didn't even think to look where it came from.
     
  13. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Casino is still fun, poker has chat, though I know some have moral objections to gambling, so.....
     
  14. ItsWendy

    ItsWendy MajorGeek

    This makes me sad. I liked the arcade, but I understand. Some folks are going to go into withdrawal I'm sure, but there are lots of other sites we can announce on the interesting websites forum.

    I'm going to miss them though. Moon Base, Lunar Lander, Space Invaders, Asteriods....

    Come to think of it, I'm going to be one of those people, even though I didn't spend much time there.

    MA, you might add an announcement to the Arcade Sticky to let people know what's going on.
     
  15. Clark_Kent

    Clark_Kent MajorGeek

    If you have arcade flash game withdraw go to kongregate they have like over 3000 games,i am there everyday and you can chat at the same time......

    Just hope my e-mail account do not become a spamfest...........
     
  16. Calltaker

    Calltaker MajorGeek

    I guess it's that whole all good things must come to an end business.

    Even though i didn;t get in there that often, I'll miss it.

    Now I guess I have to go play Luau Bingo over on pogo again

    LOL...

    Sorry to hear about this....


    ~C
     
  17. Sakari

    Sakari Private E-2

    I haven't been on for a while,what has happened? is MG finishing completly or just the arcade and why? Sakari
     
  18. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member

    Just the Arcade.

    MA explained the reasons in an above post. Apparently it had some vulnerabilities that had been exploited.
     
  19. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Read back up please, its all in here.
     
  20. Jason A

    Jason A Private E-2

    I have reported this to MrZeroPage. Are you sure this is from the arcade, and not an exploit anywhere else on your site? The reason I ask, is because no exploits have been reported, and it does indeed have regular updates.
     
  21. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Yes and we can prove it, he is welcome to contact tim or jim@ this website for the details. Since he has not updated it in 5 months, he might not be aware. We actually bought a new server and moved the forums because of exploits from the arcade last time, so this is the last straw. Of course, it was fairly specific to a certain game this time around, but regardless not worth the hassle.
     
  22. RexB

    RexB Private E-2

    Major Attitude, thanks for zapping the problem. Haven't rec'd any more spammails from whoever it was and they don't seem to have spread our addresses around knockonwood. Good deal! :thumbup:
     
  23. Jason A

    Jason A Private E-2

    Sorry Major, but this is definitely on your side. Even contacted MrZeropage:

    I presume you have other hacks installed that need dealing with.
     
  24. Sgt. Tibbs

    Sgt. Tibbs Ultra Geek

    I completely missed where you said it was from the arcade...don't know if it makes any difference or not, but I have never, not even once, gone to the arcade here and I still got the spam mail.
     
  25. Adrynalyne

    Adrynalyne Guest

    It was an exploit of the arcade, not an exploit of user accounts.

    Nobody was harvesting email addresses, as I understand it. They used the forum's email verification system to send the spam.

    Jason, I'll forward your concern to MA, but I think they know their stuff enough to figure out where the exploit was, as this is not the first time the Arcade has caused problems. As MA said, they have proof. Maybe you should direct this person to talk to MA instead of going through you as a proxy, and not checking out the details. That would be the responsible thing for him to do.
     
  26. Philipp

    Philipp Administrator Staff Member

    The exploit is in ibProArcade itself and was not in one of the games. I analyzed in the meantime the attack and forward a fix to MrZeropage.
     
  27. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    His denying it does not make it not so. IBproarcade WAS the cause, we have the proof, "MrZeroPage" needs to get his head out of his butt. His ignoring this and talking through you shows he does not care. IBproarcade was used to acces 2 admin accounts here and then send mail through them, I feel sorry for any popular websites using this add on if this is how he responds to MASSIVE security holes.


     
  28. Jason A

    Jason A Private E-2

    Hello MA,

    It now seems you are correct. Phillip managed to find the exploit and a fix has been forwarded to MrZeropage.

    Will keep you updated.

    @ Adrynalyne: Unfortunately, I don't speak to MrZeropage -- I'm just a coder over at vbulletin.org and other various places. Once again, sorry for the confusion.
     
  29. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    We always were. In all honesty, when you see me acting like a prick, I usually am right and being a prick because I am being told I am wrong. Philipp is nothing short of a brilliant coder so if it comes from his mouth, I knew it was so. He has experience coding with Vbulletin and wrote the backend to Majorgeeks, the Esselbach Storyteller; http://www.esselbach.com/ .

    Another note, the last 6 or so updates to IbproArcade read "security fix" meaning we were right about other exploits as well and that this is nothing new. Sadly, this MrzeroPage never bothered to credit Philipp who found an enourmous hole that could have cost anyone running it access to their own forum. He owes Philipp a debt of gratitude for the hours wasted finding his MISTAKE.

     
    Last edited: May 8, 2008
  30. Jason A

    Jason A Private E-2

    I'm aware of who Phillip is ;)

    I also develop add-ons for vBulletin, I have done for a while. Unfortunately, I didn't have the time to check the coding in the arcade, nor should I. I totally agree with you, MrZeropage does owe Phillip a lot of credit - and I on behalf of the vb.org community thank him. :)
     
  31. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    I would warn people using this addon with large forums to be careful and I hope this posts remains high on search engines where people can look into this mod. This addon has potential to be problematic to large site owners. I doubt anyone with a few-ten thousands users would be affected. It is too bad, our users liked it and so did I, but the risk and cost (seperate server to spare our main website from hacks for example) have outweighed its useability. Rock on Jason, appreciate your understanding and involvement.
     
  32. Jason A

    Jason A Private E-2

    I also thank you MA for brining this into the open. :)

    I passed it on to all arcade owners. :)
     
  33. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    In case you missed it, it isnt coming back. Constant security problems with it resulting in possible taking over all of the server or at least the forums. Its never coming back, and I feel sorry for any large websites running it. You can always start your own forum, put it up and hope you don't get hacked ;)
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds