Kitz ADSL Broadband Information
adsl spacer  
Support this site
Home Broadband ISPs Tech Routers Wiki Forum
 
     
   Compare ISP   Rate your ISP
   Glossary   Glossary
 
Please login or register.

Login with username, password and session length
Advanced search  

News:

Author Topic: Spam? to email used on these forums  (Read 4856 times)

jelv

  • Helpful
  • Kitizen
  • *
  • Posts: 2054
Spam? to email used on these forums
« on: January 17, 2022, 12:36:50 PM »

I've received a few emails recently with links to a survey on bmetrack (which itself seems legit). The latest is "BONUS: $50 SAINSBURY Gift Card Opportunity".

The email receiving it is kitz@<mydomain> - obviously not used for anyone else.

The reward in dollars not pounds is a bit of a giveaway!

Anyone else getting these?
Logged
Broadband and Line rental: Zen Unlimited Fibre 2, Mobile: Vodaphone
Router: Fritz!Box 7530

parkdale

  • Reg Member
  • ***
  • Posts: 597
Re: Spam? to email used on these forums
« Reply #1 on: January 17, 2022, 01:52:18 PM »

Yes I've had a few, as you pointed out $$  ;) bit of a give away!! all forwarded to report@phishing.gov.uk.
Sent from address changes each time!
Logged
Vodafone FTTC ECI cab 40/10Mb connection / Fritz!box7590

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33884
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: Spam? to email used on these forums
« Reply #2 on: January 18, 2022, 10:50:40 AM »

Hi jelv.

Thanks for reporting this.

I've been doing some checks and there is no sign of any compromise.  The only person who has logged into the server is from my IP address2 weeks ago.    Although I do get quite a lot of spam the vast majority is to web@.   I have not had anything to the email address I use for this forum in my name nor to the admin account.   I've also run a check on the site security which is clean.

All I can think is that it may be related to matters which were discussed in this thread regarding the mysterious pyrotechnics and or the discussion of bots harvesting emails based on forum names.   I myself get a fair amount of dictionary spam but its also surprising the no of distinct names that I get spam to.   
Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

smiggy

  • Just arrived
  • *
  • Posts: 3
Re: Spam? to email used on these forums
« Reply #3 on: March 10, 2023, 02:18:45 PM »

Received spam today sent to my unique forum email address: "Did you receive your package?"

Has a hack/breach been acknowledged previously?
Logged

j0hn

  • Kitizen
  • ****
  • Posts: 4099
Re: Spam? to email used on these forums
« Reply #4 on: March 10, 2023, 04:19:08 PM »

Has a hack/breach been acknowledged previously?

Nope.

I tend to use an already well spammed Gmail address for registering on forums and that's the email I have registered here so can't comment specifically on the kitz site.

I've had spam sent to an email address that has NEVER been registered anywhere. Never sent or received an email from the address but it has received 2 spam emails in the 7 years it's been registered.
It's a pretty unique domain too.

I also use Gmail and often set individual addresses for different sites.
I have mygmail+bank@gmail.com registered with my bank only and that has received spam very recently after many years of nothing at all. I don't believe the bank has been breached.
Logged
Talktalk FTTP 550/75 - Speedtest - BQM

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33884
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: Spam? to email used on these forums
« Reply #5 on: March 12, 2023, 03:31:28 PM »

There is a reported incidence from several years ago where a couple of members using unique email addresses reported they'd received spam.  At that time I had an excellent line of communication with my web hosts (who unfortunately have since sold out) and they too got involved checking to see if the forum database could have been breached and their conclusion was that it had not.    I spent a considerable amount of time and can confidently say that it does not appear that the forum database has been breached.

I use a unique email address for my kitz forum login which is clean and never rec'd any spam.  Most members reported they had no spam.  However I took the report seriously and spent an awful amount of time looking into the report and drew a blank.  I don't believe many forum owners would have spent as much time investigating as I did for an unconfirmed spam attack.   There are lots of forum regs whose accounts had been open for many years who joined in the conversation saying they hadn't received any spam. 

What I did find out during that time is that using a unique forum username and password is no longer a way of completely protecting against spam.   There is one particular bot that specifically targets unique email addresses.  All it takes is for you to have been involved in one of the many known larger breaches such as say myspace. 

Firstly the bot checks the list of the breached myspace accounts specifically looking for email addresses that have used the format 'myspace@mydomain'.  It assumes that any accounts using the alias 'myspace' (or some variation of 'myspace
#eg MySpc) in the email address has their own domain name and are using unique references for email.   The bot then sets off trawling  the Internet looking for accounts elsewhere in use using the same forum username and assumes a match. Even better if you are using the same av or some other public info.  If you use your domain name to create email addresses for forum mail, this is no longer a way to keep all your mail spam free. 

iirc a couple of users said they suddenly received spam mail, yet 100's of others didnt.  Both users were using their domain names with the site as an alias. My web hosts confirmed there was absolutely no sign of a forum breach of data and all logins to the forum database were from my IP.  There was no sign of any other database activity.  Because there is only me who has access to the database then it was easy for them to check that there were no other accesses to the server except from either me or one of their IPs. 

I do however suspect we may have been trawled by bots looking for matches. Unfortunately there is absolutely nothing I can do about this and its a risk we all take when we partake in activity on the Internet.  I get spam to an email address linked to ISP usergroup forum from which there has been no breach.  I am guilty of using my domain name with unique sites as the alias and there are no several that routinely get spam, just a couple of weeks ago I was surprised to see a spam mail come in on an address I use for shopping.  I doubt theve been hacked or I'd be seeing something about it. Over the past few years I've had spam to unique addresses that have been compromised.  These addresses have nothing to do with the site and use a different mail name. I also get plenty of spam to email address names that have never been used

---
TLDR; 
1) There is no evidence of this site data having been breached.
2) Link to discussion July 2017 here
3) Using unique email addresses are no longer protection against spam - especially if one of your aliases has been compromised in one of the big name hacks. Unique addresses are now being targetted without there ever having been a compromise on that server.  There's several in-depth articles for more info.
Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

craigski

  • Reg Member
  • ***
  • Posts: 294
Re: Spam? to email used on these forums
« Reply #6 on: March 13, 2023, 09:01:15 AM »

Agree with Kitz on point 3.

As a forum user, if you are concerned about spam, and you have your own vanity domain setup and a unique email address for forum(s), could you setup your receiving mail server to only accept emails from specific email addresses from those specific forums, and reject all other emails?

If using a unique email address, it wont only be on the kitz hosting server(s), it will be on servers where that email address was created, servers the email has passed through in and out, backup servers, and possibly engineer/support servers that have downloaded log files in the past.



Logged

meritez

  • Content Team
  • Kitizen
  • *
  • Posts: 1626
Re: Spam? to email used on these forums
« Reply #7 on: March 13, 2023, 11:02:30 AM »

No spam here,
Logged
 

anything