Forum Moderators: phranque

Message Too Old, No Replies

Trying to track down a name or an origin of site

illegal email account theif leads to site with no name

         

spamkiller

11:33 pm on Sep 5, 2002 (gmt 0)


I keep getting a bunch of ridiculous emails supposedly from an AOL member, but I am willing to bet anything that it's not from the supposed sender. AOL has a terrible occurence rate of identity theft for the use of spamming.

Once I follow the link in the message, I get some stupid mortgage quote site. I can't view the source because it's disabled the right click function. I can't seem to gain any luck in finding out who these idiots are. There is no name or contact information on the site.

I've tried ARIN, RIPE, and APNIC, and frankly, can't understand the results to do anything with it. Oddly, RIPE's results contain RIPE info...

The original IP contained in the email is: http://64.251.23.142/921345/mort2/

Now, I could simply block the sender, but each time, it's a new sender. I'm averaging 2-4 emails per day. None of them ever contain any indication that I'm going to be lead to a mortgage quote site. You'd think it was porn the way they're soliciting. The last message said, "Subj:Sorry to tell you the bad news but.." and inside it says: "Do not be mean to me anymore!
<A Href= "http://64.251.23.142/921345/mort2/">CLICK HERE"

 I don't want to limit my account to only accepting email from specified senders because I want anyone to be able to contact me, with the exception of spammers.

I found this site through Google searching one of the key terms I found from RIPE. So, I don't know if I'm at the right board, or forum for that matter.

If not, could you possibly redirect me? And if so, could you help me find out who this idiot(s) is?

Thanks!

bird

12:18 am on Sep 6, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



[ws.arin.net...]

CustName: OptIn Services LLC 
Address: 632 NW 53 St Boca Raton, FL 33487
NetRange: 64.251.20.0 - 64.251.25.255
CIDR: 64.251.20.0/22, 64.251.24.0/23
NetName: INMM-64-251-20-0
NetHandle: NET-64-251-20-0-1
Parent: NET-64-251-0-0-1
NetType: Reassigned
RegDate: 2002-08-28
Updated: 2002-08-28

Some people block their ISP/hoster as well:

OrgName: Infolink Communication Services, Inc. 
OrgID: INMM
NetRange: 64.251.0.0 - 64.251.31.255
CIDR: 64.251.0.0/19
NetName: INFOLINK-BLK-100
NetHandle: NET-64-251-0-0-1
Parent: NET-64-0-0-0-0
NetType: Direct Allocation
NameServer: THING1.INFOLINK.COM
NameServer: THING2.INFOLINK.COM
Comment: ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
RegDate: 2001-02-05
Updated: 2002-03-06

mivox

12:21 am on Sep 6, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I can't view the source because it's disabled the right click function.

Use the "View Source" command in the top drop-down menus (it's under the "View" menu in IE/Mac), or use the File menu to save the page to your hard drive, and open the resulting html file with a text editor.

There's more than one way to view a page's source code... :)

Woz

12:31 am on Sep 6, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



>I can't view the source because it's disabled the right click function.

Another trick (PC) is to

1. click and hold right button. (Dialog box pops up)
2. whilst holding right button, click and hold left button.
3. whilst holding left button release right button
4. whilst holding left button cancel dialog box
5. right hand menu should have appeared, now use left button to activate choice from menu.

Sounds complicated, but you get used to it and once you do it is quite quick. Works 99.9% of the time.

Onya
Woz

spamkiller

7:37 am on Sep 6, 2002 (gmt 0)



Bird, thank you. What do I do with that information? Hahahah! I've got the motivation, just not the know how to carry it through.

Mivox and Woz, thank you! I knew this was a good place to go!

Woz, I tried it and it worked. I did it here. I'll go there and try it.

Turns out this little scam runs deeper than I realized. They've connected themselves to another site and are making it look like this site is the one behind it. I've teamed up with her to try and bust 'em.

I usually just delete spam, but I'm getting this every day, and it's annoyed me enough to want to do something about it. That, and I don't have a life outside the Internet until school starts.

Thanks again, guys!