Log in

View Full Version : Spam PM


EHaskins
17-07-2008, 19:35
I just got a spam PM from the user jnoor. That user doesn't appear to be a spam bot account, so somebody should look into it.

And since the latest activity on the account is continually being updated to be "creating private message" I assume I'm not the only person to get this.

BTW, is there an easier way to report spam PMs?

Jeff 801
17-07-2008, 19:40
I have also gotten a PM today that was spam from a Dave1236

EHaskins
17-07-2008, 19:43
I have also gotten a PM today that was spam from a Dave1236

That account appears to be doing the same thing.

Steve W
17-07-2008, 19:54
It seems that there is a problem. I just checked all of the logi users and most were creating PMs. I just got hold of Karthik who is at IRI and he will look for Brandon. I have also emailed Brandon. Everybody hold tight while it is being looked into.

Leav
17-07-2008, 19:57
just wanted to let you know that user "brasil" is also sending spam PM.

-Leav

P.S.
just FYI the user specifies he is from a certain location, and also specifies a team number which is really from that location...
At the very least this means that ChiefDelphi has been targeted directly:
the whole team number+location thing is not something just any vBulletin forum has.... (thus meaning that someone took the time to find at least one team from a specific location)

EHaskins
17-07-2008, 20:00
It seems that there is a problem. I just checked all of the logi users and most were creating PMs. I just got hold of Karthik who is at IRI and he will look for Brandon. I have also emailed Brandon. Everybody hold tight while it is being looked into.

I didn't think to look there good find, and thanks for the update.

GRaduns340
17-07-2008, 20:00
I have received same spam from user "sbf2009"

gburlison
17-07-2008, 20:02
Add 'RoboChick612' to the list.

ginosoprano09
17-07-2008, 20:02
i received spam from user "TimWoodin"

Steve W
17-07-2008, 20:02
Everybody hold tight. Almost all of the users online now are "creating a private message". There is not much we can do until Brandon takes a look at it. Please be patient!

It seems to me that something is using legit user ID's to send these messages. I do not think that those people even know what is happening. Adding names to the list at this time is not necessary and could in the future be harming if some says that they are spammers.

acdcfan259
17-07-2008, 20:02
I received one from wingnut1705.

Edit: We're just adding the names in case it helps. Or at least I am.

Akash Rastogi
17-07-2008, 20:12
add GroEng if its even needed.

Molten
17-07-2008, 20:30
I've got something useful. I found out from someone that one of these came from my account. I logged on and changed my password and now it doesn't happen. Not sure how this helps, but it doesn't show record that I sent a PM. I don't think they are using our real ids. Perhaps they are just pseudo-ids.

Also, add lebren to the list.

Joe G.
17-07-2008, 20:42
Wheeler is in on it too

EDIT: Once again, Wheeler has a history of 80 legit posts, Rep, etc.

KarenH
17-07-2008, 20:43
If you haven't already, DO NOT OPEN THE PM! Not the kind of thing anyone on CD needs to see; it's ugly. Wait till Brandon or other moderators get this problem solved. It sounds like someone's hacked the system.

basicxman
17-07-2008, 20:45
add user 'enoor' to the list

yea dont open it

Branden Ghena
17-07-2008, 20:52
I looked at currently active users, not only are most creating PMs, but most if indeed not all are legit reputable users (i.e. whytheheckme [Jacob Komar]). Maybe these are all users who check the stay logged in box?

EHaskins
17-07-2008, 20:54
I looked at currently active users, not only are most creating PMs, but most if indeed not all are legit reputable users (i.e. whytheheckme [Jacob Komar]). Maybe these are all users who check the stay logged in box?

I've got stay logged in selected on two machines, and as far as I can tell I'm not sending anything.

MrToast
17-07-2008, 20:57
I got one from whytheheckme, but after chatting with him on IM, I've confirmed it wasn't him.

Looks like Chief Delphi's been hacked.

ahecht
17-07-2008, 20:57
I got one from "gaga".

Branden Ghena
17-07-2008, 21:06
I've got stay logged in selected on two machines, and as far as I can tell I'm not sending anything.

Yeah probably not the remember me box, but I was just trying to find some common theme.

I got one from whytheheckme, but after chatting with him on IM, I've confirmed it wasn't him.

Looks like Chief Delphi's been hacked.

And on IRI weekend too. It probably wasn't on purpose, but it was the perfect (worst) time for an attack.

Allison K
17-07-2008, 21:08
Adding "Nantucket"

Joe G.
17-07-2008, 21:13
Until the problem is resolved, I would recommend not spending too much time on CD. About a year ago, another large (20,000+ member) forum I'm a member of had a similar attack, with various moderaters/high profile members having their accounts hacked. That attack was accompanied with a hidden banner ad that contained a Trojan. Especially any of the PMs come from members with administrative privileges, I'd be careful.

ahecht
17-07-2008, 21:17
^I'll add to that: If your chiefdelphi password is the same as your IM or email password, I'd change them all now, especially if your email address and screen names are listed in your profile.

Kranerian
17-07-2008, 21:18
Adding zerorsd to the list- no team listed, only one post (deleted by a mod). message showed up In my gmail inbox that I had a pm. I had forgotten I even had a login here. Image in the pm is most definitely against ToS.

Joe G.
17-07-2008, 21:27
A list of members who, as of 9:15, have the status of "creating private message" (I apologize if anyone is legitimatly PMing) I reccomend that these users particularly change their passwords.

303Dad
AJRobotics
akachan
AKIBSAYYED
alanelf
Asheron
auroraponce
bahmutov
Barnes
boiler
brasil
c0bra540
carmen
chadbarbe
champ2010
chelznkim
cobra33
coconut
collins
competition
Dave1236
davildo
diviney
dvfleet
erfanfar868
esau
etdeshon
frc1959
gaga
general
GroEng
harriton
ilikecheese
jamd
jnoor
John C
kaye
kutty18
lalala
lax4life
lcmessage
lebren
MAHSTeam
nantucket
nelsonabo
nick1230
peetarII
pizza
pookie
prateesh
Primela
qwqw
ravonics
razzoc
rdkbob
rhdz12
riddle
ritcheyz
robert
RoboChick612
robouser72
romeo 2005
Rosyaxaya
sbf2009
Screamin Eagles
sdvfd5
snickers
snowbird6620
spsteam1512
supriyav
surper
SVEC
team1573
the dude
thopkins
TimWoodin
USRSF
vtheiss
wannabchicken
wheeler
whytheheckme
wingnut1705
zerorsd

Weightmn
17-07-2008, 21:48
Wish I would have seen this thread BEFORE I opened this PM!
Hope you get all of this figured out. People REALLY need to get a life.
The user that sent mine was: chelznkim

EricH
17-07-2008, 21:51
Add lcmessage to the list of users sending spam.

I changed my password, so hopefully no spam from me.

JoeXIII'007
17-07-2008, 21:58
durr... just waken up to the realization that CD has been hacked.

And in the very case that my account has been overtaken, I personally have not sent any out.

*sigh*

Branden Ghena
17-07-2008, 22:17
Odd... checking active users, it doesn't appear that anyone is creating PMs anymore. Wonder what happened? Hacker's bedtime? :D

whytheheckme
17-07-2008, 22:20
I got some IMs that I sent some out....

And of course it wasn't me actually sending these out. So my apologizes in advance.

Hope this is the end of it!

Jacob

EHaskins
17-07-2008, 22:22
Odd... checking active users, it doesn't appear that anyone is creating PMs anymore. Wonder what happened? Hacker's bedtime? :D

Hopefully someone shut them down. I'd like to hear what level of information they were able to access.

ttldomination
17-07-2008, 22:29
I got one from "champ2010".

And might I add it was EXTREMELY inappriopriate.

ChrisH
17-07-2008, 22:39
I got one from "champ2010".

And might I add it was EXTREMELY inappriopriate.


Thanks to the warning from others, the PM I got from "general" was deleted before being opened.

Mike Betts
17-07-2008, 22:43
I just got one from nick1230 titled "Illegal Youtube Portal". As with the other cases, extremely inappropriate...

Mike

Scott L.
17-07-2008, 22:47
Thanks to the warning from others, the PM I got from "general" was deleted before being opened.

Same here.

ahecht
17-07-2008, 22:51
I just got one from nick1230 titled "Illegal Youtube Portal". As with the other cases, extremely inappropriate...
Mike

The one I got was titled "Tube Trick", which sounded legitimate enough since I had recently posted a picture of last year's game pieces being sold as "Pool Tubes". As others have said, the content was inappropriate.

ComradeNikolai
17-07-2008, 22:53
"Better version of Youtube," or something... deleted it as I would just from the title, but I also had this thread for warning.

vtheiss was the alleged sender to add to the list.

smurfgirl
17-07-2008, 23:16
I just got one of the spam PMs from the user qwqw, it sounds like it was the same message everyone else got but under a different title ("Have you ever seen this website?"). I'm glad to see this problem is being taken care of. (:

Kyle
17-07-2008, 23:18
I got a message from nelsonabo with the title of Uncenzored Youtube (http://www.chiefdelphi.com/forums/private.php?do=showpm&pmid=317990)
and it was really not something that should be on CD.

gallo26
17-07-2008, 23:29
I cant remember what the name was because i deleted it so fast but it was from team #2010 if that helps. thats all i remember. and i dont mean to blame that team, im just saying thats what it was...

RyanN
18-07-2008, 00:01
Yea, many of the people on the list are well respected people. I got a PM from AKIBSAYYED. Just curious to see what crud it sent me to, I opened the link. It brought me to a website that was inappropriate, but also tried to install something on my Mac, so a warning to others, don't open the link, it may be a virus, I quickly stopped it.

For the admin though, please please look through this carefully. whytheheckme is someone that I quickly recognized on the list, and a person who I know would not do anything like this. This is definitely a hacker's job.

MrForbes
18-07-2008, 00:36
thanks for letting us know there was a problem, I deleted the spam pm I got without opening it.

BHS_STopping
18-07-2008, 01:05
Ah, thanks for the warning! I'm glad that my PM's subject line was obvious of its contents, I deleted it immediately. It was received from "brasil", but I'm sure that it wasn't him.

I did check a list of my sent PMs, and it appears that nobody has accessed my account to spread messages like this. Perhaps other users should check, just to be safe?

Madison
18-07-2008, 01:30
This information is accurate to the best of my knowledge.

The PMs are sent by a bot; a computer program designed to use the vBulletin system's private messaging functions to send spam. They index the member list and automagically generate PMs to each user.

The site was not hacked. What happened, while annoying and inappropriate, used a simple, straightforward method for sending spam.

Do not open PMs that are at all suspicious and, particularly, do not follow any links contained within them. I'm sure word's reached Brandon by now. If trouble starts up again, we can handle things on a user by user basis and temporarily suspend accounts as necessary.

Thanks for generating a list of the accounts that were involved.

Steve W
18-07-2008, 06:15
I got a response from Brandon. He believes that somehow they used a members list and used the members names as password. If your user name and password are the same PLEASE change it ASAP.