Tuesday, June 19, 2007

E-mail address leaked from RubyCorner to spammers?

A few minutes ago I received a spam message at my Inbox. A snippet follows:

Subject: Information
From: INFINITY LOTTERY <infinitylottery@yahoo.de>
To: Administrator <"#{'q'.succ}ubycorner@romulo.e#{2+2}ward.com">

INFINITY LOTTERY PROMOTIONS THE NETHERLANDS
FROM:THE DESK OF THE PRESIDENT
INFINITY LOTTERY PRIMOTION/PRIZE AWARD DEPT
Ref. Number:WRH/12726/PZP
Batch Number:29/064701/904HM

ATTENTION.

Sir/ Ma/ Miss,

We are pleased to inform you of the result of the winners of the Infinity
Lottery Promotions
programs held on 14th June,2007.Your e-mail address attached to ticket
number 085---2356789--789
with serial number 8567--46 drew lucky numbers 9- -01-23455-34 which
consequently won in the
category A.You have therefore been approved for a lump sum pay of US
$1.200,000.00(one million two hundred
thousand United States Dollars)in cash credited to file Ref.
Number:WRH/12726/PZP.This is from a total
cash prize of US $16.800,000.00usd international winners in this category.
CONGRATULATIONS!!!

(...)

Most interesting is the address to which the message was sent (mangled here by me), a unique one I generated on June 3, 2007 using E4ward to sign up for RubyCorner. I didn't give it to anyone else. That leaves only two possibilities:

  1. It somehow leaked from RubyCorner. I don't see anyway to get the e-mail of other users or set a specific option on my profile regarding visibility. Thus, if not intentionally leaked, it was stolen.
  2. The spammer used a dictionary attack against the sub-domain romulo.e4ward.com. That seems unlikely. What kind of idiot would perform such an onerous attack to find addresses among no more than a few dozens which are known to be from an e-mail forwarding service?

To be really sure I need to generate a random address and sign up again for RubyCorner. Meanwhile, if you also suspect the address you have registered at RubyCorner was abused, please, let me know.

2 comments:

Jon Gretar said...

Actually I would think opeion 2 to be more likely. Spammers are computer programs and they spam onto any server they find with smtp ports open.

Ryan Bates said...

I received the same email a couples days ago and I'm registered on rubycorner. Seems they are leaking it. I'm sure not on purpose, but either way...