Spam Email from 'Mark Sibly'
Miscellaneous Forums/General Discussion/Spam Email from 'Mark Sibly'
Today I received a an email with this content:
BlitzBasic - Account expires
Dear klepto2,
Due to the exceeding mass of users the free disc space of our server is in danger to run out. To cope with this thread we came to the conclusion to delete all the inactive users.
If you want your account to be not deleted please login under
http://biltzbasic.tk/.Yours,
Mark Sibly
Obvious this is a fake just to get my account details as the provided link leads to a faked blizbasic.com page with a login form.
the sender has the folowing email : BlitzResearch@...
klepto2
Bastard.
EDIT: The spammer cleverly made all the other links on the page go to blitzbasic.com, but he messed up one thing (so far, that I can see): the site icon.
EDIT2: Counter-spam? Let's run a Max program to spam POST's to the login script!
Wow... Just wow.
Whew, thanks for posting that. I don't want my account deleted!
Domain name:
BLITZBASIC.TK
Organisation:
Malo Ni Advertising Limited
16 Peel Road
Douglas IM1 4LR
Isle of Man
Phone: +44 (0)1624 623543
Fax: +44 (0)1624 623548
E-mail: abuse: abuse@..., copyright infringement: copyright@...
@xlsior: I was just about to WHOIS search the domain..
Wow.. realllly sneaky, this guy has a list of the users, or some of them atleast. If you attempt to login with bogus information it says "Error: Username not found."
EDIT: That may actually be him forwarding on to blitzbasic and holding on to the user & pass before passing it on.
EDIT2: Media site:
http://marksibly.ma.ohost.de/
..im wondering why people actually trying to mess with Blitzbasic and mark Sibly..guy is quite silent, and im sure not messing around....and what is use for someone to so such stupid things like this guy did??
the fake log in has: 1- the Home section hilighted on the login, and 2- A submenu of home when it should not, and 3- The icon, and funnilly, if you press the login link, you get to the real login link. weird...
Domain name:
BLITZBASIC.TK
The domain name being used here seems to be Biltzbasic.tk. (Biltz instead of Blitz.)
This is one lousy individual. I hate low life like this.
I've sent an email to abuse@..., hopefully it gets removed speedily.
site seems dead to me.
and what is use for someone to so such stupid things like this guy did??
Because when you try to 'log in' on that site, all it does is store your username and password, which they can then use on this site to download as many updates/products as are available from your account.
If anybody's been fooled by this site, you should change your password straight away.
There's now a news item on the front page warning people about this, so thanks for bringing it up, but they do seem to have pulled the site since this morning (probably because of this thread).
I've also found out who the actual web host is/was, so hope to have them suspend the person's account as well.
Good Find Klepto.
It's not the first attempt some disgruntled people have made to grab peoples login details for the forum.
also Mark signs off with 'bye!' - I think - lol
Yep, he does.
Can you name and shame that person James?
Where's Puki the internet detective when you need him?
Sorting out a new domain name I guess! >:) Just kidding ;)
Here's the response email I got:
Dear Sir/Madam,
Dot TK is the exclusive registry for the
Country Code Top Level Domain for the island
of Tokelau (also known as "ccTLD").
Dot TK (.TK) registers domain names globally,
through our services Free Domain and Paid Domain.
As your email alerts us to
unacceptable content by a holder of a Dot TK domain, I
have researched the case. The user is in
fact a Free Domain registrant, therefore
because of the violation, the domain has
been cancelled and the registrant has been
removed from our database.
Thank you for your assistance & I apologise for any
offense or inconvenience caused.
With Kind Regards,
Dot TK Support
http://www.dot.tkRenaming The Internet
The majority of support questions and answers
are available on Dot TK's Wiki at
http://www.wiki.tk
>There's now a news item on the front page warning people about this
Nice, but you should move it up further. As it is, it is placed so far down many people will either have to scroll down or just don't see it. I use 1024x768 res and I had to scroll.
Sucks that it was removed with no further investigating done. I'm sure the host can be traced (where the DNS is pointing to), with the host traced, the account could be traced.
OR
At least you can look at the file structure, determine what might be administration access and get an ip from the last used administration point (or last uploaded file). The IP could narrow down the country and usually the city to which that block is registered to (meaning what ISP they use). Not sure any more info could be attained, and most of that would be a wild goose chase... but it's fun none the less.
Whoever it is would have a blitzbasic account here in order to get the login redirect correctly nailed down I would think.
@Dark Half: It's unlikely the domain user had an 'administrator' page/login. The setup was simple enough for manual managing.
I never got one of these e-mails.
Who actually got this e-mail other than "klepto2"?
Interesting - "Terry B" got an e-mail too and he was born and raised in Germany.
Any none-German Blitzers get an e-mail too?
and what is use for someone to so such stupid things like this guy did??
because some people (-lots in fact) are dumb enough to use the same password for everything.
now when I click the link i come to a password cracking page... odd... it has links on the right that say excell password cracker... windows password cracker and other odd links... hardly legal I would think
@Nate the Great: Very legal. The site was taken down, but is still under management of the domain provider. Providers typically turn the site into an ad page until it is bought by another user.
Yeah it's probably an automatic system that creates links about password stealing because the now-removed website was also about that. It may take them some time though to find a new "buyer" for biltzbasic.tk. :D
Wow, you would really think this guy would be a bit more proffesional
about his scam. Sounds like shoddy workman ship to me!
Thanks for the heads up on this though Klepto2!
And as to D4NM4Ns most recent post
'because some people (-lots in fact) are dumb enough to use the same password for everything.'
I'm afraid hes right, LOL. I use the same password for everything!
It makes it easy to remember, although if someone managed to figure
it out, they would have total access to nearly every site I'm a member
with.
So bit of advice. Use a different password for EVERY SINGLE SITE YOU
HAVE AN ACCOUNT WITH.
The Mighty WERDNA(Lord Of Darkness)
It may take them some time though to find a new "buyer" for biltzbasic.tk. :D
In this case (with .TK) it would just be an acquirer, as these domains are free (public-domain).
I had a .tk site way back when but they canceled it because it didn't get enough hits. Good thing too, because now I have better hosting and a real domain.
.tk domains are about as impressive as geocities/angelfire/that other one.
It is sad that some persons are trying to denier the merits of the BlitzBasic company. The worst part is that the domain and name BlitzBasic.com is also considered *SPAM* into the Yahoo! mail.
In fact, last week I was trying to make a come back into the programming scene. This is not a difficult task because the BlitzPlus is such a nice development environment.
So bit of advice. Use a different password for EVERY SINGLE SITE YOU
HAVE AN ACCOUNT WITH.
Sage advice.
I use
KeePass, that way I can use one easy to remember password to access my passwords, and then very strong, random passwords everywhere else.
Means that he either illegally has Blitz3D and want to use one of our accounts to access the forums...
Simple really..