dvandom: (davedraw)
dvandom ([personal profile] dvandom) wrote2005-12-17 01:48 pm

Why, thank you, script kiddies.

Was checking my spamtraps and found the following email (return address no doubt false):


Return-Path: <nobody@falcon.dnsvs.net>
X-Original-To: dvandom@eyrie.org
Delivered-To: dvandom@eyrie.org
To: dvandom@eyrie.org
Subject: spaming. white-wolf.com hack. database.
Date: Fri, 16 Dec 2005 22:50:56 -0500
X-AntiAbuse: This header was added to track abuse, please include it with any ab
use report
X-AntiAbuse: Primary Hostname - falcon.dnsvs.net
X-AntiAbuse: Original Domain - eyrie.org
X-AntiAbuse: Originator/Caller UID/GID - [99 32756] / [47 12]
X-AntiAbuse: Sender Address Domain - falcon.dnsvs.net
X-Source: 
X-Source-Args: /usr/local/apache/bin/httpd -DSSL 
X-Source-Dir: /home2/gandalf4/public_html


After the server white-wolf.com has been hacked admins have refused \"to thank\" us.
We suggest you to buy database white-wolf.com all for 10 $.
In base of 65000 accounts with mails, icq, msn, personal data of users.
Mail for details whtwlfx@yahoo.com



Such a class act, eh? At least they don't claim to have cracked the passwords.

[identity profile] foomf.livejournal.com 2005-12-17 12:16 pm (UTC)(link)
Seems like a good idea to send a copy to either 'abuse' or 'spoof' at yahoo.
aberrantangels: (I'm going to fuck you to death)

[personal profile] aberrantangels 2005-12-17 01:27 pm (UTC)(link)
And possibly pass a copy along to White Wolf.

[identity profile] loki-liesmith.livejournal.com 2005-12-17 01:12 pm (UTC)(link)
I've known about this. I have a friend who works at White Wolf, and he assures me that it shouldn't end up being a big issue. They've reset all the passwords for their userbase, and they're working with the FBI and yahoo to catch the people responsible.


And if you want a fun card game and want to support myself and some other friends of mine, they've got Pimp: The Backhanding available :)

[identity profile] dvandom.livejournal.com 2005-12-17 02:45 pm (UTC)(link)
Well, the password issue is still relevant, since a lot of people use common passwords for boards (i.e. the same password at WW and LJ and so forth). Especially boards they don't intend to visit much, and don't want to have to reset every time because they've forgotten. :)

[identity profile] loki-liesmith.livejournal.com 2005-12-17 08:54 pm (UTC)(link)
There is that. I'm obsessive enough that even if I use the same root word as a password, I put a different random number/letter combo at the end of it just to be safe. Hopefully it won't end up being a major issue.

[identity profile] j-anderson123.livejournal.com 2005-12-17 09:41 pm (UTC)(link)
The database for sale for a whopping $10? A legit thief trying to sell that kind of info would be asking for thousands of dollars anyway.

[identity profile] dvandom.livejournal.com 2005-12-17 10:32 pm (UTC)(link)
No, see, this is spite. "You didn't pay our blackmail demands, so we'll sell your database really cheap to make sure it goes to as many people as possible!"

[identity profile] j-anderson123.livejournal.com 2005-12-17 10:45 pm (UTC)(link)
They have to know no one would be stupid enough to buy this now that it's public. The language structure also doesn't indicate it was typed by someone who speaks english as a first language... odds are, this is some kid who hopes to get free Paypal bucks by threatening people and making offers he can't back up.

[identity profile] ezrael.livejournal.com 2005-12-18 11:57 am (UTC)(link)
At least the Lawmeme hacker did it for the love of hacking.