spam on email address used only for this forums account - About xda-developers.com

Can any of the Admins look into this: I received spam on my email account that is only used to register for this forum. There must be a leak.

maicod said:
Can any of the Admins look into this: I received spam on my email account that is only used to register for this forum. There must be a leak.
Click to expand...
Click to collapse
The admins have been monitoring on this thread: Forum Database Email Spam Compromise?
If you could please take a look there and see if your details match anything reported or if you might have some new clues to offer we would appreciate it. Thanks!

Related

Had problems submitting my first post.

Hello,
I had some problems submitting my first post to this forum. I always got this error message:
1.To prevent spam to the forums, new users are not permitted to post outside links in their messages. All new user accounts will be verified by moderators before this restriction is removed.
... and wondered what went wrong. I had no outside links in my posting and decided to wait for some time, maybe it was a temporary problem with the forum. After then I tried to post my message again. Same error.
After some brain work I noticed my mistake:
in my nickname I have a (at). Maybe the rule set for the e-mail-filter is a bit restrictive, so it wrongly validates every (at) in the posting.
Should be only taken as an advice to maybe adjust the filtering or at least the error message a bit.
best regards
gu(at)no
[email protected] said:
Hello,
I had some problems submitting my first post to this forum. I always got this error message:
1.To prevent spam to the forums, new users are not permitted to post outside links in their messages. All new user accounts will be verified by moderators before this restriction is removed.
... and wondered what went wrong. I had no outside links in my posting and decided to wait for some time, maybe it was a temporary problem with the forum. After then I tried to post my message again. Same error.
After some brain work I noticed my mistake:
in my nickname I have a (at). Maybe the rule set for the e-mail-filter is a bit restrictive, so it wrongly validates every (at) in the posting.
Should be only taken as an advice to maybe adjust the filtering or at least the error message a bit.
best regards
gu(at)no
Click to expand...
Click to collapse
Maybe trying to find clever ways to put sh*t as your user name, wasn't as clever as you thought ?
Hello, I have a problem in my first Thread. I would send a new ROM for the raphael, but it gives me this error "To prevent spam to the forums, new users are not permitted to post outside links in their messages. All new user accounts will be verified by moderators before this restriction is removed."
how can I do?
thanks for all answers.
blaste said:
Hello, I have a problem in my first Thread. I would send a new ROM for the raphael, but it gives me this error "To prevent spam to the forums, new users are not permitted to post outside links in their messages. All new user accounts will be verified by moderators before this restriction is removed."
how can I do?
thanks for all answers.
Click to expand...
Click to collapse
Check your PMs
Mike
ok, thaks!
i have the some problem like friends up
Bartezz612 said:
i have the some problem like friends up
Click to expand...
Click to collapse
I would do what the warning/restriction says and contact a moderator.
JAguirre1231 said:
I would do what the warning/restriction says and contact a moderator.
Click to expand...
Click to collapse
I wouldn't
There's nothing we can do. The restriction is on posting links and images. It automatically lifts after the member posts enough times.
It was added to prevent spam bots and it has worked wonders.
Dave
DaveShaw said:
I wouldn't
There's nothing we can do. The restriction is on posting links and images. It automatically lifts after the member posts enough times.
It was added to prevent spam bots and it has worked wonders.
Dave
Click to expand...
Click to collapse
So...... it was a lie? False advertising I say, even if the product is the ability to post links.
JAguirre1231 said:
So...... it was a lie? False advertising I say, even if the product is the ability to post links.
Click to expand...
Click to collapse
Contact us by all means, but we will tell you we can't help .
I have asked if this can be re-worded at some point in the future.
Dave
work in progress said:
If you can't help new users post questions, then this forum isn't worth a**** !!!!! I will go to another site where the people aren't as useless and ***** as you are!!!!!
Click to expand...
Click to collapse
You will be dearly missed. New members are allowed to post questions...just not links without mod approval. Have fun at your new site.
I'm having the same issue. I get the following message, which is different from the one above:
"To prevent spam to the forums, ALL new users are not permitted to post outside links in their messages. After approximately eight posts, you will be able to post outside links. Thanks for understanding!"
But I do not have any links in my message.
What are the characters the forum SW parses as links?
bozothedeathmachine said:
I'm having the same issue. I get the following message, which is different from the one above:
"To prevent spam to the forums, ALL new users are not permitted to post outside links in their messages. After approximately eight posts, you will be able to post outside links. Thanks for understanding!"
But I do not have any links in my message.
What are the characters the forum SW parses as links?
Click to expand...
Click to collapse
Images also count as part of the check, or anything starting http:// (IIRC).
If you are still having problems, try uploading the BB Code to pastebin (or similar).
Dave
bozothedeathmachine said:
I'm having the same issue. I get the following message, which is different from the one above:
"To prevent spam to the forums, ALL new users are not permitted to post outside links in their messages. After approximately eight posts, you will be able to post outside links. Thanks for understanding!"
But I do not have any links in my message.
What are the characters the forum SW parses as links?
Click to expand...
Click to collapse
I believe it can also detect links as being strings separated by at least one dot, with a slash "/" present...
But I think Dave might be right about the http part. Try a basic post, removing anything other than plain text, then add the suspected parts in via edit, and see what it is rejecting.
I think I found the issue. I didn't have any "http", slashes, or images.
I was trying to post the handset info from my HTC Hero, which contains all manner of random characters, including the hash sign. I'm thinking it was that which was marked as spam.
Three posts down, 5 to go before I can start making sense.
Thanks for the assist.

spam mail

I got spam mail to a unique address I registered with xda-developers.
The address is not readable publicly and isn't findable in Google.
If anybody with the site is interested I can provide details.
lklotz said:
I got spam mail to a unique address I registered with xda-developers.
The address is not readable publicly and isn't findable in Google.
If anybody with the site is interested I can provide details.
Click to expand...
Click to collapse
Not sure we can help, but yes, send me a PM with the details.
We do not sell or otherwise distribute email addresses. email addresses can "leak" out from many places, from your PC and from contact lists on your phone. This is happening to an increasing extent on mobile devices: http://www.xda-developers.com/android/logging-test-by-treve-sassibob-review/
OK I sent you a PM but it doesn't show up in my PM Sent folder so if you didn't get it let me know here. I'm certain the compromise didn't come from my phone as the address I use is only for this forum registration and not any other purpose.
lklotz said:
OK I sent you a PM but it doesn't show up in my PM Sent folder so if you didn't get it let me know here. I'm certain the compromise didn't come from my phone as the address I use is only for this forum registration and not any other purpose.
Click to expand...
Click to collapse
Received your PM and will have it looked into.
Also activated the option for you to have sent PMs saved in your sent mail folder.
lklotz said:
OK I sent you a PM but it doesn't show up in my PM Sent folder so if you didn't get it let me know here. I'm certain the compromise didn't come from my phone as the address I use is only for this forum registration and not any other purpose.
Click to expand...
Click to collapse
To satisfy my curiosity, do you use the XDA App / Tapa Talk / Forum Runner / etc?

Phishing attempt (Guild Wars 2)

I received a phishing e-mail today to an address that I set up specifically for the xda-developers forum. I'm pretty sure I haven't given it to anyone else. Could there be a database leak?
Greetings!
Due to an unusual change in your access pattern, the Guild Wars 2 account under this email address has been locked. This can be caused by logging in from a new location, but it may also signal an attempt to compromise your account. If you feel that your account's security is at risk, please follow the steps below.
Step 1: Verify Your Account Ownership​
​ Click on the link below to verify your e-mail address of the Guild Wars 2 account:​ hxxps://account.guildwars2.com/account/login-support.html
Click to expand...
Click to collapse
The link actually goes to hxxp://guildwars2.com.us-support.pw/?loginservice=wam&ref=0&app=bam (WARNING! COULD BE DANGEROUS)
IHaveADiamond said:
I received a phishing e-mail today to an address that I set up specifically for the xda-developers forum. I'm pretty sure I haven't given it to anyone else. Could there be a database leak?
​
The link actually goes to hxxp://guildwars2.com.us-support.pw/?loginservice=wam&ref=0&app=bam (WARNING! COULD BE DANGEROUS)
Click to expand...
Click to collapse
There is a thread from a few months back that describes a similar situation. If I can find it I'll post a link.
Edit:
http://forum.xda-developers.com/showthread.php?t=1835116
Flagging the admin to check it out @bitpushr
Thank you,
mikef
XDA Senior Moderator

[Request for Moderator/Admin Assistance] Request to verify new user account.

I recently received this error message while attempting to update a post with a logcat attachment that I had meant to attach to the post originally but forgot to.
To prevent spam to the forums, new users must wait five minutes between posts. All new user accounts will be verified by moderators before this restriction is removed.
Click to expand...
Click to collapse
Now I know I'm not a terribly active poster, but I would hardly qualify myself as new, since I joined back in Aug. 2010. How can I go about verifying my account to avoid this in the future? Also, is this the appropriate forum, or should it go under Q&A instead.
Thank you for your assistance.
There is a lot of replies that covered your question. You need to have 30 posts to have these restriction lifted. We can't do anything about that.
Thread closed.

Password Reset Spoofing

Hey,
Ive just used the pw reset feature today,
and heck,
I was shocked when I entered my email adress into the input form and it prompted a message that my password reset was send to my email.
A password reset request has been emailed to you. Please follow the instructions in that email.
Click to expand...
Click to collapse
The prompted message should NOT give any detail if the entered email is used in the db, or not!
That needs to be adressed imho asap!
Simply by:
If true:
If this email is associated with an account, the password reset request has been emailed to it. Please follow the instructions in that email.
If not true:
If this email is associated with an account, the password reset request has been emailed to it. Please follow the instructions in that email.
Ty
@MikeChannon @the_scotsman
Gentlemen, for your attention please.
GuestNoOne said:
Hey,
Ive just used the pw reset feature today,
and heck,
I was shocked when I entered my email adress into the input form and it prompted a message that my password reset was send to my email.
The prompted message should NOT give any detail if the entered email is used in the db, or not!
That needs to be adressed imho asap!
Simply by:
If true:
If this email is associated with an account, the password reset request has been emailed to it. Please follow the instructions in that email.
If not true:
If this email is associated with an account, the password reset request has been emailed to it. Please follow the instructions in that email.
Ty
Click to expand...
Click to collapse
Contact Us | XDA Developers
Founded in 2002, XDA is the world’s largest smartphone and electronics community. Looking for the latest tech news and reviews? Want to do more with your Android phone, Windows PC, iPhone, iPad, or MacBook? Look no further than XDA.
www.xda-developers.com
Requests to Moderators and Recommendations for XDA improvements
[All XDA Members] Requests to Moderators and Admins [All XDA Members] Feedback/Recommendations for XDA
forum.xda-developers.com
sd_shadow said:
Contact Us | XDA Developers
Founded in 2002, XDA is the world’s largest smartphone and electronics community. Looking for the latest tech news and reviews? Want to do more with your Android phone, Windows PC, iPhone, iPad, or MacBook? Look no further than XDA.
www.xda-developers.com
Requests to Moderators and Recommendations for XDA improvements
[All XDA Members] Requests to Moderators and Admins [All XDA Members] Feedback/Recommendations for XDA
forum.xda-developers.com
Click to expand...
Click to collapse
What a mess in here... Instead of deleting this thread the mod decided to delete the post I made, after checking your reply, in:
https://forum.xda-developers.com/t/...recommendations-for-xda-improvements.4300729/
... but hey, its actually not a recommendation, its a security flaw and therefor bug report. So maybe the mod was right to leave this thread. Still confused
GuestNoOne said:
Hey,
Ive just used the pw reset feature today,
and heck,
I was shocked when I entered my email adress into the input form and it prompted a message that my password reset was send to my email.
The prompted message should NOT give any detail if the entered email is used in the db, or not!
That needs to be adressed imho asap!
Simply by:
If true:
If this email is associated with an account, the password reset request has been emailed to it. Please follow the instructions in that email.
If not true:
If this email is associated with an account, the password reset request has been emailed to it. Please follow the instructions in that email.
Ty
Click to expand...
Click to collapse
This matter has been referred to those who can officially review and potentially change the way the process works.
Mike
I just fixed this by standardizing verbiage across both situations. Thank you for bringing it to our attention @GuestNoOne !
Lol. Mods thanking each other to gain more likes - while the one who brought it up doesnt get any.
That phenomen got a name and aint healthy...
GuestNoOne said:
Lol. Mods thanking each other to gain more likes - while the one who brought it up doesnt get any.
That phenomen got a name and aint healthy...
Click to expand...
Click to collapse
Do you really expect an answer? Certainly not from me.
GuestNoOne said:
Lol. Mods thanking each other to gain more likes
Click to expand...
Click to collapse
We don't care about likes anymore, this is no longer significant at this point, for moderators at least. We are not chasing them.
GuestNoOne said:
while the one who brought it up doesnt get any.
Click to expand...
Click to collapse
Fixed! You got likes now, thanks!
Yeah that happens, I've seen moderators (myself included) affected by this situation as well, don't worry, e.g. a moderator posts a smart question or an interesting issue and only the other mod who answered got likes! This is not specific to non-moderators, trust me.
GuestNoOne said:
That phenomen got a name and aint healthy...
Click to expand...
Click to collapse
I know for sure there is nothing malicious here. Trust me here too

Categories

Resources