HardwareHeaven.com

HardwareHeaven.com

Looking for the skin chooser?
 
 
  • Home

  • Hardware reviews

  • Articles

  • News

  • Tools

  • Gaming at HardwareHeaven

  • Forums

 

Go Back   HardwareHeaven.com > Forums > HardwareHeaven's Heaven > Feedback


Feedback Site or Forum problems? suggestions?

Reply
 
Thread Tools
Old Jul 19, 2010, 06:27 AM   #1
HardwareHeaven Newbie
 
Join Date: Aug 2007
Posts: 4
Rep Power: 0
DerAgo is on a distinguished road

Possible security / privacy problem with the sites email database

I used a customized email address only for this site ( "ago-drvhvn@bastart.eu.org" ), and today I started to receive spam for this address. Please check your servers security, guys. Here is a copy of the email:

Code:
Return-path: <mimihops1@hotmail.com>
Envelope-to: ago-drvhvn@bastart.eu.org
Received: from blu0-omc1-s37.blu0.hotmail.com ([65.55.116.48])
	by bastart.eu.org with esmtp (Exim 4.69)
	(envelope-from <mimihops1@hotmail.com>)
	id 1Oafmk-0004zQ-Ae
	for ago-drvhvn@bastart.eu.org; Mon, 19 Jul 2010 04:08:55 +0200
Received: from BLU0-SMTP39 ([65.55.116.7]) by blu0-omc1-s37.blu0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4675);
	 Sun, 18 Jul 2010 19:08:45 -0700
X-Originating-IP: [116.217.115.80]
X-Originating-Email: [mimihops1@hotmail.com]
Message-ID: <BLU0-SMTP398835D2A1EE79F38B4CE4FABF0@phx.gbl>
Received: from wrl ([116.217.115.80]) by BLU0-SMTP39.blu0.hotmail.com over TLS secured channel with Microsoft SMTPSVC(6.0.3790.4675);
	 Sun, 18 Jul 2010 19:08:45 -0700
From: "wowaccountadmin@blizzard.com" <donotrelpy@blizzard.com>
To: <ago-drvhvn@bastart.eu.org>
Subject: Account disable Notification
Date: Mon, 19 Jul 2010 10:14:56 +0800
MIME-Version: 1.0
Content-Type: text/html;
	charset="utf-8"
Content-Transfer-Encoding: base64
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.5512
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5512
X-OriginalArrivalTime: 19 Jul 2010 02:08:45.0385 (UTC) FILETIME=[51527390:01CB26E7]

PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9XM0MvL0RURCBIVE1MIDQuMCBUcmFuc2l0aW9uYWwv
L0VOIj4NCjxIVE1MPjxIRUFEPg0KPE1FVEEgaHR0cC1lcXVpdj1Db250ZW50LVR5cGUgY29udGVu
dD0idGV4dC9odG1sOyBjaGFyc2V0PXV0Zi04Ij4NCjxNRVRBIGNvbnRlbnQ9Ik1TSFRNTCA2LjAw
LjI5MDAuNTg5NyIgbmFtZT1HRU5FUkFUT1I+PC9IRUFEPg0KPEJPRFk+RGVhciBwbGF5ZXJzLCBB
cyBXb3JsZCBvZiBXYXJjcmFmdCdzIGRldmVsb3BtZW50IGFuZCBvcGVyYXRpb25zIHNlcnZpY2Ug
DQpwcm92aWRlcnMgLSBCbGl6emFyZCwgd2UgaGF2ZSBiZWVuIGhhcmQgd29yayBmb3IgZWZmb3J0
cyB0byBwcm92aWRlIGJldHRlciBhbmQgDQptb3JlIGp1c3QgZm9yIHRoZSBwbGF5ZXJzIG9mIHRo
ZSBnYW1lIG1vcmUgYmFsYW5jZWQgZW52aXJvbm1lbnQuPEJSPkp1c3QgDQpyZWNlbnRseSB3ZSBm
b3VuZCB0aGF0IHNvbWUgcGxheWVycyB0byB1dGlsaXplIGEgYnVnIGluIFdvcmxkIG9mIFdhcmNy
YWZ0IG1ha2UgDQppbXByb3BlciBidXNpbmVzcy48QlI+VGhpcyBpcyBvdXIgZmF1bHQsIHdlIGFy
ZSBhbHJlYWR5IGludmVzdGlnYXRpbmcgdGhlIA0KbWF0dGVyLjxCUj5BbmQgd2lsbCBBU0FQIHRv
IGFsbCBwbGF5ZXJzIGEgc2F0aXNmYWN0b3J5IGFuc3dlci48QlI+SW4gdGhpcyANCnByb2Nlc3Ms
IHdlIG5lZWQgeW91ciBjb29wZXJhdGlvbi4gWW91IG5lZWQgdG8gbG9nIDxBIA0KaHJlZj0iaHR0
cDovL3d3dy53b3ctaW0uY29tICIgdGFyZ2V0PV9ibGFuaz53d3cud29ybGRvZndhcmNhcmZ0LmNv
bSANCjwvQT4mbmJzcDtBbmQgdmVyaWZ5IHlvdXIgYWNjb3VudCBsb2dpbiwgYWNjb3VudCBpbmZv
cm1hdGlvbiBoYXMgYmVlbiB0byBlbnN1cmUgDQphdXRoZW50aWNpdHkuPEJSPlNpbmNlcmVseSwg
QmxpenphcmQgQ3VzdG9tZXIgU2VydmljZSA8L0JPRFk+PC9IVE1MPg0K
Here is the message text with Base64 decoding applied:

Code:
Dear players, As World of Warcraft's development and operations service providers - Blizzard, we have been hard work for efforts to provide better and more just for the players of the game more balanced environment.
Just recently we found that some players to utilize a bug in World of Warcraft make improper business.
This is our fault, we are already investigating the matter.
And will ASAP to all players a satisfactory answer.
In this process, we need your cooperation. You need to log www.[censored].com  And verify your account login, account information has been to ensure authenticity.
Sincerely, Blizzard Customer Service
If you need any more information, I will be happy to provide it.

- Axel Gembe, deve.loping.net
DerAgo is offline   Reply With Quote


Old Jul 19, 2010, 08:03 AM   #2
S.N.A.F.U.
 
Neshi's Avatar
 
Join Date: Dec 2005
Location: Wellington, NZ
Posts: 3,377
Rep Power: 177
Neshi is godlike in his statusNeshi is godlike in his statusNeshi is godlike in his statusNeshi is godlike in his statusNeshi is godlike in his statusNeshi is godlike in his statusNeshi is godlike in his statusNeshi is godlike in his statusNeshi is godlike in his statusNeshi is godlike in his statusNeshi is godlike in his status
System Specs

Re: Possible security / privacy problem with the sites email database

yea.. I'm getting alot of world of warcraft spam about my account being used in transactions etc.. my account was frozen ages ago.
I just delete them.. but if they are from here it would suck..
__________________
If one does not attach himself to people and desire, never shall his heart be broken. But then, does he ever truly live?

Life is just too damn short for if's and maybe's

Neshi is offline   Reply With Quote
Old Jul 19, 2010, 09:57 AM   #3
HH Administrator
 
craig5320's Avatar
 
Join Date: May 2002
Location: Manchester, UK
Posts: 8,565
Rep Power: 445
craig5320 is godlike in his statuscraig5320 is godlike in his statuscraig5320 is godlike in his statuscraig5320 is godlike in his statuscraig5320 is godlike in his statuscraig5320 is godlike in his statuscraig5320 is godlike in his statuscraig5320 is godlike in his statuscraig5320 is godlike in his statuscraig5320 is godlike in his statuscraig5320 is godlike in his status
System Specs

Re: Possible security / privacy problem with the sites email database

Thanks, I'm investigating now.
__________________

HardwareHeaven on Facebook
craig5320 is offline   Reply With Quote
Old Jul 19, 2010, 01:24 PM Threadstarter Thread Starter   #4
HardwareHeaven Newbie
 
Join Date: Aug 2007
Posts: 4
Rep Power: 0
DerAgo is on a distinguished road

Re: Possible security / privacy problem with the sites email database

BTW, the original email linked to "www.wow-im.com" with a link text of "www.worldofwarcarft.com" (sic), which is now down. The email header mentions 116.217.115.80 as the original IP. Both wow-im.com and 116.217.115.80 are registered in Beijing, China.
DerAgo is offline   Reply With Quote
Old Jul 19, 2010, 02:15 PM   #5
HH's curmudgeon
 
Tyrsonswood's Avatar
 
Join Date: Mar 2008
Location: Rustbelt, Ohio
Posts: 10,714
Rep Power: 389
Tyrsonswood is godlike in his statusTyrsonswood is godlike in his statusTyrsonswood is godlike in his statusTyrsonswood is godlike in his statusTyrsonswood is godlike in his statusTyrsonswood is godlike in his statusTyrsonswood is godlike in his statusTyrsonswood is godlike in his statusTyrsonswood is godlike in his statusTyrsonswood is godlike in his statusTyrsonswood is godlike in his status
System Specs

Gold Member
Re: Possible security / privacy problem with the sites email database

I'm not getting anything like this..... just sayin'
__________________
Quote:
Only after the last tree has been cut down. Only after the last fish has been caught. Only after the last river has been poisoned. Only then will you realize that money cannot be eaten.
Cree Nation Tribal Prophecy

No trees were harmed in the production of this message.
However, an extremely large number of electrons were rather annoyed.
Tyrsonswood is online now   Reply With Quote
Old Jul 19, 2010, 04:46 PM Threadstarter Thread Starter   #6
HardwareHeaven Newbie
 
Join Date: Aug 2007
Posts: 4
Rep Power: 0
DerAgo is on a distinguished road

Re: Possible security / privacy problem with the sites email database

Quote:
Originally Posted by Tyrsonswood View Post
I'm not getting anything like this..... just sayin'
Well, I think it is highly unlikely someone would have guessed the email, and I also don't think it was a breach on my side. I didn't even know about this email anymore until I received the spam today Also, I never even had a WoW account.
DerAgo is offline   Reply With Quote
Old Jul 20, 2010, 09:39 AM   #7
HH Administrator
 
craig5320's Avatar
 
Join Date: May 2002
Location: Manchester, UK
Posts: 8,565
Rep Power: 445
craig5320 is godlike in his statuscraig5320 is godlike in his statuscraig5320 is godlike in his statuscraig5320 is godlike in his statuscraig5320 is godlike in his statuscraig5320 is godlike in his statuscraig5320 is godlike in his statuscraig5320 is godlike in his statuscraig5320 is godlike in his statuscraig5320 is godlike in his statuscraig5320 is godlike in his status
System Specs

Re: Possible security / privacy problem with the sites email database

I've been through our firewall logs and various other logs we have and I can see no intrusions. There's also no other reports of this behaviour over at vBulletin.com. However I'm escalating our update schedule so we can rule out any security flaws in our current vB version and have changed mysql related passwords as a precaution.
__________________

HardwareHeaven on Facebook
craig5320 is offline   Reply With Quote
Reply

Thread Tools