Security Alert for All (???)

Discussion in 'Chit-Chat' started by chrisnchips, Jul 29, 2010.

  1. chrisnchips

    chrisnchips Regular Member

    Joined:
    Apr 17, 2008
    Messages:
    153
    Likes Received:
    0
    Occupation:
    Student
    Location:
    SF/BayArea, California, USA
    Hi everyone,

    Wondering if anyone else has received emails from people they do not know which claim to have found your email through BadmintonCentral.com... sounds fishy to me because I have never posted my email on here. I'm wondering how they could have related my username to my email. I'll post the email here because of how ridiculous it sounds:
    Hello sweetie

    My name is judy, i am 25yrs old, i'm a free minded, open hearted girl, i like to take life as easy as i could, i'm one of the few that still belives in friendship,love, trust and signs, am very much single and ready to mingle. was browsing through the internet and came across your contact at (www.badmintoncentral.com) belive me i like what i see,it will be my sincere pleasure to be your friend if you don't mind, i hope you will not take my request for granted, feel free to email me, i will appreciate it if you can send me some pics, i look forward to hear from you soon.
    Take care.

    Judy
    Yeah, and she(he/she/it) attached a photo too. Afraid to download it so I took a 'print screen' to attach to here for you guys.

    leme kno what u think... and i hope im not just being a little bit overly paranoid.:p
     
  2. drifit

    drifit newbie

    Joined:
    Mar 14, 2007
    Messages:
    2,609
    Likes Received:
    6
    Occupation:
    PM
    Location:
    Selangor, Malaysia
    i did mention before.
    do not post your personal details in the forum/thread;
    1. email
    2. phone number
    3. address
    this is like inviting spam. "please email me, anything will do"

    *if need to, exchange them via Private Messaging*

    dear chrisnchips,
    refer this, http://www.badmintoncentral.com/forums/showthread.php?78419
    what you mean by never post??
     
  3. chrisnchips

    chrisnchips Regular Member

    Joined:
    Apr 17, 2008
    Messages:
    153
    Likes Received:
    0
    Occupation:
    Student
    Location:
    SF/BayArea, California, USA
    lol, guess im wiser now than back then... Thanks for the heads up!
     
  4. kwun

    kwun Administrator

    Joined:
    Apr 24, 2002
    Messages:
    41,048
    Likes Received:
    2,073
    Occupation:
    BC Janitor
    Location:
    Santa Clara, CA, USA
    anyone else getting this? i have a couple other reports.

    i am not exactly sure how this has happened and how the spammer managed to get hold of the emails. there must be a security hole in the software. i will start investigating this.

    my apologies to whoever received it. please delete it.
     
  5. ctjcad

    ctjcad Regular Member

    Joined:
    Sep 27, 2004
    Messages:
    19,083
    Likes Received:
    6
    Location:
    u.s.a.
    never encountered this. well, at least when i saw such emails/spams in my reg. email, i'd delete them right away without checking the contents.
    it's interesting from whom/which email address did chrisnchips get the email from and the title of the email..??..
     
  6. Thom_bad

    Thom_bad Regular Member

    Joined:
    Jun 20, 2009
    Messages:
    2,490
    Likes Received:
    1
    Occupation:
    Student
    Location:
    Saskatoon, Canada
    Hey Ctjcad what's the matter ?
    That person sounds kinda friendly and lovely ! Gimme her mail if don't plan to answer yourself :D:D:p:rolleyes::eek:
     
  7. mel1234

    mel1234 Regular Member

    Joined:
    Aug 20, 2007
    Messages:
    72
    Likes Received:
    0
    Occupation:
    Engineer
    Location:
    Ang Mo Kio
    Hi chrisnchip,

    I have just received the same email as you did. I have downloaded the photo and I can say please do not download the photo. You'll be regretting if you saw her.. haha :D:D
     
  8. ctjcad

    ctjcad Regular Member

    Joined:
    Sep 27, 2004
    Messages:
    19,083
    Likes Received:
    6
    Location:
    u.s.a.
    ..i was thinking, is it perhaps related to badmintoncentral.com's facebook's page??..i don't know if chrisnchips is a member of BC's facebook page or not??..
    ..you sure the person is a "she"???..
     
  9. kwun

    kwun Administrator

    Joined:
    Apr 24, 2002
    Messages:
    41,048
    Likes Received:
    2,073
    Occupation:
    BC Janitor
    Location:
    Santa Clara, CA, USA
    ok. so out of the incidents that has been reported to me. there are cases where the email address used was not the email address the person used to registered in BC. and in all cases, those people have their email address posted publicly. from this we can conclude that the spammer simply farmed email addresses from BC posts and use them for spam.

    which is good as that means the user registration database is ok and not compromised.

    but also means that to protect our users' privacy, we should:

    - discourage posting email publicly
    - have some way to prevent unregistered user to see email address posted in the forum.
     
  10. RSLvictorSOTX

    RSLvictorSOTX Regular Member

    Joined:
    May 10, 2010
    Messages:
    642
    Likes Received:
    0
    Location:
    court
    …in Data Mining/Farming…we were each assigned to data mine a given (authorised for internship marks amongst one of many projects) website for the purpose of program testing how efficient and effective a company’s Query systems are. …thereby, saving valuable programming hours for their in-house programming personnel.

    What we found out is amazing (at the time). Trends, frequencies, sites, duration, purpose, purchasing, limits, access times (at work, home, airports, hotels, gyms, coffee shops, etc) and so on and so forth.

    It can be sequential or random.

    Culling and harvesting email addresses is key and this is also where amazing is discovered (with the help of IT security officers).

    Many accounts are created to sleep, for ease of access only. Many multi-accounts are created to be target-specific with topics of discussions only…these are of course nothing!

    What we found out the most alarming/unusual is/are those who are able to orientate themselves anywhere and everywhere from all access points (around the world). These user(s) is/are found to be able to straddle on a single node (same node; same machine address code) but is actually nowhere AND elsewhere! The ‘’how’’ (as we discovered later on) on how they are able to straddle a single node in any access points anywhere shouldn’t be left for open elaboration here.

    To complicate matters of this kind (on a low level though), we also found out that college fraternities tend to use single computer (single node and single MAC) for every frat member to surf the net that serves their purpose (of course, they have their own laptops!).

    [FONT=&quot]…the point is…the data mining project was done a few years back. Certainly, advances by leaps and bounds have been made to dig and delve even deeper. BCDF should be vigilant. Unfortunately, only a periodically upgraded security system can make it less vulnerable because it is impossible to be vigilant at all times![/FONT]
     
    #10 RSLvictorSOTX, Jul 30, 2010
    Last edited: Jul 30, 2010

Share This Page