Author Topic: Spam on my email address soley used here.  (Read 32346 times)

0 Members and 1 Guest are viewing this topic.

exocet

  • Guest
Spam on my email address soley used here.
« on: March 30, 2012, 05:45:42 AM »
I have just received Spam on the email address used in here only, the email address doesn’t exist as its a forward address to a collection address, it has never, and cannot be used to send mail. Therefore the weak link is this forum. So perhaps Avast exec or website manager would care to explain this.

I say again, this is an email address that is a forwarder only, has never cannot be used to send mail. This is done for the specific purpose of knowing where a weak link is when Spam is received on a given email address. I do not allow other users to contact me in this forums.

I attach the Spam email in raw form for your perusal. I am not impressed!


Offline Muad'Dib

  • Jr. Member
  • **
  • Posts: 74
    • The underwater sound of the Antarctic Ocean
Re: Spam on my email address soley used here.
« Reply #1 on: March 30, 2012, 06:00:13 AM »
exocet,

I got the same spam email (also sent to a forum unique address), I already posted about this in another thread.

I'd suggest you change your forum email address (and disable your current one), especially since your attachment includes your forum address for anyone to download and see.


exocet

  • Guest
Re: Spam on my email address soley used here.
« Reply #2 on: March 30, 2012, 06:17:17 AM »
exocet,

I got the same spam email (also sent to a forum unique address), I already posted about this in another thread.

I'd suggest you change your forum email address (and disable your current one), especially since your attachment includes your forum address for anyone to download and see.

Thank you, I did that already before I even posted, I run a forums using the same core software this forum uses.

You can check out this post on my forums by clicking here.

Now we will see how long it takes before my new email forwarder unique to this forum gets breached.

AdrianH

  • Guest
Re: Spam on my email address soley used here.
« Reply #3 on: March 30, 2012, 06:43:52 AM »
This has nothing to do with avast. I have the same spam on a reserved email address that has never been used anywhere at avast.

The same complaint has been seen of late on several forums I use and people automatically think it MUST be the sites fault.  Fact is spam can be sent to domains where no email account has ever been set up, I have 3 domains where the mail system has never been used, BOTS however are programmed to locate domains and find a usable name to forward their junk and crap is received.

exocet

  • Guest
Re: Spam on my email address soley used here.
« Reply #4 on: March 30, 2012, 06:54:01 AM »
That may well be true but my domain has had no bots probe email addresses, I cannot say too much but I will know instantly if an email address received a probe, again it is not an email address its a trap for a forward.

That’s all I’m saying, only one other forums leaked my email and others but that was down to and idiot admin who decided to reveal email addresses. But this is not probed as it doesn’t exist and cannot respond to a mail request.


Offline Muad'Dib

  • Jr. Member
  • **
  • Posts: 74
    • The underwater sound of the Antarctic Ocean
Re: Spam on my email address soley used here.
« Reply #5 on: March 30, 2012, 07:17:44 AM »
Both exocet and I received identical emails to our avast! forum only email addresses on the same night. And the same night, the user Stalka (who started a similar thread) also received spam to his avast forum only address (I don't know the content's of Stalka's email, so I can't confirm if it's identical or not). The only place my email could have been detected is from the avast! forum. The domain is used solely for email, and the email addresses used are not stored there (they are primarily unique addresses for various uses - forums, merchant sites, etc.). And I have also not received the same spam to any other email address - only to my avast! forum one. To me this clearly points to someone/thing having access to the forum's email list.

Now given the topic of the spam, I'm sure a lot of people may have this automatically blocked by their ISPs, so they may never know if they received one. But I predict that more forum users will be soon be posting messages similar to the ones exocet and I have posted.

tbessie

  • Guest
Re: Spam on my email address soley used here.
« Reply #6 on: March 30, 2012, 09:13:23 AM »
I also have received spam emails (not related to antivirus products, either) from the email address I use ONLY for this forum.  I believe I may also have received spam emails to the email address I use for my Avast account itself.

Not very encouraging for a security company, huh?

- Tim

tbessie

  • Guest
Re: Spam on my email address soley used here.
« Reply #7 on: March 30, 2012, 09:20:16 AM »
This has nothing to do with avast. I have the same spam on a reserved email address that has never been used anywhere at avast.

The same complaint has been seen of late on several forums I use and people automatically think it MUST be the sites fault.  Fact is spam can be sent to domains where no email account has ever been set up, I have 3 domains where the mail system has never been used, BOTS however are programmed to locate domains and find a usable name to forward their junk and crap is received.

I have my own domain, and specifically tag each email address I supply with the name of the party to whom I am supplying it.  A "dictionary attack" spam (where they try many addresses at a given domain) wouldn't be likely to generate these specific strings that are ONLY provided to certain parties (forums or other accounts).

This has happened with even big-name companies - for example, I provided the Wall Street Journal and United Airlines with special tagged emails that only they had, and I received spam on them.

Happily, I have received spam on these tagged emails rarely, so they are likely instances of employees of the companies stealing the mailing lists, the companies themselves having an internal policy of selling them, or third party hackers getting hold of the user databases.

Man-in-the-middle attacks can happen (capturing packets, capturing routed emails, etc.), but I would be seeing a LOT more spam on these tagged emails if that were happening frequently, so I tend to hold the people I gave the email address to (eg. this forum, etc.) accountable for its lack of security.

- Tim

DPAvaster

  • Guest
Re: Spam on my email address soley used here.
« Reply #8 on: March 30, 2012, 09:32:04 AM »
I have also received today 2 spam messages to my email account that was used for registration to this forum in 2009.
The email address is not used anywhere else and so it identifies Avast forums as the source.
I would like to know if Avast sells email address lists to 3rd parties.   As has been said before, this is not impressive !!!!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Spam on my email address soley used here.
« Reply #9 on: March 30, 2012, 10:07:00 AM »
1. I have also received today 2 spam messages to my email account that was used for registration to this forum in 2009. The email address is not used anywhere else and so it identifies Avast forums as the source.
2. I would like to know if Avast sells email address lists to 3rd parties.

1. I can't confirm the reports posted here...!!!
I had a look at my mails, on my local spam folder and even on my ISP's spam folder. Nothing related there.
2. Certainly not..!!!
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

davegm

  • Guest
Re: Spam on my email address soley used here.
« Reply #10 on: March 30, 2012, 11:15:30 AM »
I too have received 3 spam emails within the past day or so to an email address used to register with Avast in 2007 and later used to register with this forum, but not used for any other purpose.

bioxx750

  • Guest
Re: Spam on my email address soley used here.
« Reply #11 on: March 30, 2012, 11:31:04 AM »
1. I can't confirm the reports posted here...!!!

Means absolutely nothing

2. Certainly not..!!!

How would you know?

BTW,  2 emails this morning to the address I only use here, both marked as spam but the sender must be known to the AV I use coz they both got flagged as phishing attempt as well.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 88897
  • No support PMs thanks
Re: Spam on my email address soley used here.
« Reply #12 on: March 30, 2012, 11:49:14 AM »
@ exocet
I have received spam on address that haven't even been used anywhere before (just created).

But what doesn't help is the attachment you have posted has your email address in it, so I would suggest you remove the attachment.

These are publicly available forums that no doubt email harvester bots would scan, so another area is your email address showing in public (forum profile settings, Allow users to email me), if it was even for a limited time that too could be a source. But your settings currently don't allow that so there is no email icon displayed (only you and moderators can see the email icon).

That said the new forum software doesn't directly display your email address, but it could potentially be harvested, if you have the Allow users to email me, it could be manually harvested.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.2.6105 (build 24.2.8918.824) UI 1.0.799/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Spam on my email address soley used here.
« Reply #13 on: March 30, 2012, 11:52:13 AM »
1. I can't confirm the reports posted here...!!!

Means absolutely nothing

Well, that's my personal experience. :P
If I should get such mails in the future, I'll let you know.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

IWRConsultancy

  • Guest
Re: Spam on my email address soley used here.
« Reply #14 on: March 30, 2012, 01:16:40 PM »
Me too, today.

I imagine the problem is nothing to do with Avast itself but with the forum software. Many forum coders (and CMS website coders) are ostriches with their heads firmly stuck in buckets of sand when it comes to the issue of address harvesting.

http://spamwise.org has some tools which can help locate such vulns.