SmugMug data compromised?

2»

Comments

  • AndyAndy Registered Users Posts: 50,016 Major grins
    edited December 18, 2007
    cabbey wrote:
    Actually, owning two ibm.com email addresses that are both blatantly obvious, one straight out of a dictionary, the other a first initial + last name combo that's ludicrously obvious, I can tell you it's AMAZING how little spam makes it through.

    I used to be ajwilli@ :) Do you still use Profs and Hone? ear.gif
  • AndyAndy Registered Users Posts: 50,016 Major grins
    edited December 18, 2007
    westpost wrote:
    I started getting spam to my SmugMug address on December 1. On December 4, I sent an email to help@smugmug dot com about it. Never got a response.

    Hi Adam, I scoured our entire email system for mail from your domain on or about Dec 4th... didn't find any. The only one I found was the mail that I replied to you on the 16th.... which was when we still didn't have much more info on the cause of the issue. Like Baldy said, it may have been caught in a filter, how ironic is that :(
  • westpostwestpost Registered Users Posts: 3 Beginner grinner
    edited December 18, 2007
    Andy wrote:
    Hi Adam, I scoured our entire email system for mail from your domain on or about Dec 4th... didn't find any. The only one I found was the mail that I replied to you on the 16th.... which was when we still didn't have much more info on the cause of the issue. Like Baldy said, it may have been caught in a filter, how ironic is that :(

    Kinda makes sense, because it contained an example of the spam I had been getting. So it was probably detected as spam itself. If you look at the second email I sent, the one you got, it contains the first email.
  • jfriendjfriend Registered Users Posts: 8,097 Major grins
    edited December 18, 2007
    Andy wrote:
    Hi Adam, I scoured our entire email system for mail from your domain on or about Dec 4th... didn't find any. The only one I found was the mail that I replied to you on the 16th.... which was when we still didn't have much more info on the cause of the issue. Like Baldy said, it may have been caught in a filter, how ironic is that :(

    Here's an idea for your anti-spam system. Since you have the email addresses of all your customers, how about you white-list all those email addresses in your anti-spam tool so they are never caught or blocked. Once you've done that, you could probably turn the anti-spam tool up even more aggresively because all emails from customer addresses would get right through.

    If the anti-spam tool can't handle hundreds of thousands of addresses in the whitelist file, then it would be possible to have a filter in front of the anti-spam tool that diverted customer address emails before they went into the anti-spam tool.

    I know that not every legitimate helpdesk email you receive comes from the same email address as customers have on their account, but I bet most do.
    --John
    HomepagePopular
    JFriend's javascript customizationsSecrets for getting fast answers on Dgrin
    Always include a link to your site when posting a question
  • AndyAndy Registered Users Posts: 50,016 Major grins
    edited December 18, 2007
    jfriend wrote:
    Here's an idea for your anti-spam system. Since you have the email addresses of all your customers, how about you white-list all those email addresses in your anti-spam tool so they are never caught or blocked. Once you've done that, you could probably turn the anti-spam tool up even more aggresively because all emails from customer addresses would get right through.

    If the anti-spam tool can't handle hundreds of thousands of addresses in the whitelist file, then it would be possible to have a filter in front of the anti-spam tool that diverted customer address emails before they went into the anti-spam tool.

    I know that not every legitimate helpdesk email you receive comes from the same email address as customers have on their account, but I bet most do.
    Thanks John bowdown.gif
  • bhambham Registered Users Posts: 1,303 Major grins
    edited December 23, 2007
    I have had one email address for I would say about 9 years now, and I know that I used it for too many things that I shouldn't have over the years.

    But about the only spam I get is about me winning million of dollars in foreign lotteries, or from higher ups in foreign banks (mostly in africa) asking me for the help in committing fraud to get millions of dollars.

    Spam, junk mail, taxes, death.
    "A photo is like a hamburger. You can get one from McDonalds for $1, one from Chili's for $5, or one from Ruth's Chris for $15. You usually get what you pay for, but don't expect a Ruth's Chris burger at a McDonalds price, if you want that, go cook it yourself." - me
  • jfriendjfriend Registered Users Posts: 8,097 Major grins
    edited January 9, 2008
    Baldy wrote:
    Update: Our spammer paid a visit to the URL that fires the script tonight... But this time he didn't get anything.

    How he got the URL is still a mystery, but there's no more doubt about how he got the email addresses.

    I just got four fake Bank of America login emails (phishing emails trying to trick you into logging into a fake site), two on each of my Smugmug addresses. Since I don't use these addresses anywhere, but at Smugmug (not even here at dgrin), they must have been part of this issue. It's too bad that the damage doesn't stop once the leak is plugged. Once the email address gets into the spam community, it's there potentially forever.
    --John
    HomepagePopular
    JFriend's javascript customizationsSecrets for getting fast answers on Dgrin
    Always include a link to your site when posting a question
  • OffTopicOffTopic Registered Users Posts: 521 Major grins
    edited January 9, 2008
    jfriend wrote:
    I just got four fake Bank of America login emails (phishing emails trying to trick you into logging into a fake site), two on each of my Smugmug addresses. Since I don't use these addresses anywhere, but at Smugmug (not even here at dgrin), they must have been part of this issue. It's too bad that the damage doesn't stop once the leak is plugged. Once the email address gets into the spam community, it's there potentially forever.

    That's funny (strange) because I got several today as well (Nigerian bank scams for me). Strange because there was nothing after that initial rash back in December.
Sign In or Register to comment.