Computer Chess Club Archives


Search

Terms

Messages

Subject: Re: Changing Email ? WARNING : HackerZ around

Author: Nadejda Zaitzeva

Date: 17:56:03 08/01/02

Go up one level in this thread


Hello,

You guys are being had by a liar, hacker and a thief. First of all, Jerry Jones
and this Sergey Smith who replied to him are the same guy. That should be clear
to all of you.

In addition to hacking into our site many times, committing credit card fraud
and threatening us repeatedly, he also repeatedly mailbombed our server, which
mostly likely resulted in the cancellation of his accounts. I'm including some
examples of this below, but as the logs, emails and other proof we have is
enormous, I can only post a small sample of it here. As any programmer knows,
there isn't a way to collect anyone's email, passwords or credit card
information using Java or any other kind of scripts placed on a web page, that's
ridiculous. We didn't do anything to this guy except gently scold him for
hacking and then after he continued, we reported him to his account providers.

This guy began hacking into our site on July 29th. We have programming in place
to limit free members to 3 email message sent to ladies. This guy, who's real
name is erik vanlint, by the way - he's from Belgium, began creating many false
profiles, using many different email addresses, user names and using many proxy
servers to try and circumvent our programming. This is bad enough, but something
we don't get too excited about. But at the same time - before one word was
exchanged between us, this guy committed credit card fraud against us. He joined
our site as a paying member using fraudulent credit card information - this time
using the name Phillip Crew. A lot of names this guys has......

Just after doing this, this thief sent to our anti-scam site a report about two
girls he was writing (and lying) to, claiming that they must be scammers. We
answered him very politely and quickly, and he returned our message, and this
time wrote something slanderous about our dating site - and this AFTER he had
continually hacked into our site and committed credit card fraud!

We were not aware of the credit card fraud at this point, but we had become
aware of his hacking attempts. We wrote him a very polite letter (please see
below), only gently scolding him for his hacking, nothing rude or vulgar or
threatening, as you will see is his own method.

We have logs to backup all of this - tons of it. We have every line from every
log, and every email he sent (including the thousands of mailbombs). We can
prove everything we say here. His lies are all ridiculous and unsubstantiated.
Since he is slandering us on bulletin boards, we are also pursuing this by
reporting his illegal activities to the proper authorities, and making them
public wherever he posts lies about us.

Please take a look at only a tiny sample of proof:

This is what we received in reply from him (I'm adding YYYTTT to help protect
from spam):

Return-Path: <YYYTTTchessbase@yahoo.com>
Received: from web14507.mail.yahoo.com (web14507.mail.yahoo.com
[216.136.224.70])
	by trueloves.com (8.9.3/8.9.3) with SMTP id PAA03752
	for <YYYTTT@YYYTTTtrueloves.com>; Mon, 29 Jul 2002 15:41:02 -0400
Message-ID: <20020729214236.5171.qmail@web14507.mail.yahoo.com>
Received: from [134.58.253.194] by web14507.mail.yahoo.com via HTTP; Mon, 29 Jul
2002 14:42:36 PDT
Date: Mon, 29 Jul 2002 14:42:36 -0700 (PDT)
From: Chess Base <YYYTTTchessbase@yahoo.com>
Subject: Scam report
To: Matt Parker <YYYTTT@YYYTTTtrueloves.com>
In-Reply-To: <004e01c2373f$cba2b2e0$aabbefd8@q2u3l3>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
X-UIDL: lpm"!ZIG"!mNa!!N6B!!

Actually, I'm a scam hunter, sometimes hack sites to
get info about potential scammers, and play their game
to gather info about them.

Jerry

__________________________________________________
Do You Yahoo!?
Yahoo! Health - Feel better, live better
http://health.yahoo.com




Then he continues his hacking the next day, by creating more free profiles on
our site and sendig more letters:

Login: JerryJ 2002-07-30

IP: 134.58.253.194

E-mail: YYYTTTchessbase@yahoo.com

Name: DO_U_WANT_2_B_HACKED_?

Gender: Men-seeking-Women

Country: Russia

City: DO_U_WANT_2_B_HACKED_?

Age: x

Height: 185cm, 6 ft 1 in

Weight: 83kg, 185 lbs.

Sign: Aries

Hair: White curly

Eye color: Brown

Social: Separated

Children: No children

Family: Undecided about having children

Religion: Not Specified

Race: Not Specified

Language:

Occupation:

Type: Not Specified

Education: Not Specified

Study:

Smoking: Never smoke

Drinking: Never drink alcohol

Music:

Appearance:

Adjectives: x

Hobbies: x

Comments:

Seeking: x

Relationship: Love and marriage

Full Name:

Address:


Phone:

Photo:

Here is the receipt from his credit card fraudelent registration:

========= ORDER INFORMATION =========
Invoice : 62985219970
Description : Trueloves.com Membership
Amount : 19.95 (USD)
Payment Method : MasterCard
Type : Authorization w/ Auto Capture

============== RESULTS ==============
Response : This transaction has been approved.
Authorization Code : 040869
Transaction ID : 311078350
Address Verification : Street Address: No Match -- First 5 Digits of Zip: No
Match

==== CUSTOMER BILLING INFORMATION ===
Customer ID : phrocrew
First Name : Philip
Last Name : Crew
Company :
Address : FUCK OFF
City : FUCK OFF
State/Province : Wa
Zip Code : 452366
Country : USA
Phone : 452123456
Fax :
E-Mail : phrocrew@yahoo.com

=== CUSTOMER SHIPPING INFORMATION ===
First Name :
Last Name :
Company :
Address :
City :
State/Province :
Zip Code :
Country

Data from our logs 07/29/02, when he used a credit card to register as a
paying member (credit card info excluded here):

Fuckoff **passwrd** 2035 30 members You@are.com Fuckoff russian Fuck off
russian bastard xxxx xx 4125 xx 45236

phrocrew **passwrd** 2035 30 members phrocrew@yahoo.com Philip Crew private
FUCK OFF Wa 452366 USA 452123456

Here he is trying to login after using the credit card. Notice that his
proxie failed and gave him away:

134.58.253.194 - - [29/Jul/2002:09:02:49 -0400] "POST
/cgi-bin/pass/pass_reminder.cgi HTTP/1.1" 200 239
"http://www.the-cloak.com/Cloaked/+cfg=136/http%3A//www.trueloves.com/cgi-bi
n/members/index.shtml" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98) Opera
6.02  [en]"
216.127.72.7 - phrocrew [29/Jul/2002:09:02:30 -0400] "GET
/cgi-bin/members/index.shtml HTTP/1.0" 401 1228
"http://www.trueloves.com/members.shtml" "Mozilla/4.0 (compatible; MSIE 5.0;
Windows 98) Opera 6.02  [en]"
216.127.72.7 - phrocrew [29/Jul/2002:09:02:28 -0400] "GET
/cgi-bin/members/index.shtml HTTP/1.0" 401 1228
"http://www.trueloves.com/members.shtml" "Mozilla/4.0 (compatible; MSIE 5.0;
Windows 98) Opera 6.02  [en]"

Here's the second letter we wrote to him, after we first discovered his hacking:

From: "Trueloves.com" <YYYTTT@trueloves.com>
To: "Chess Base" <YYYTTTchessbase@yahoo.com>
References: <20020729200026.52586.qmail@web14510.mail.yahoo.com>
Subject: Re: Scam report
Date: Mon, 29 Jul 2002 13:35:24 -0700
MIME-Version: 1.0
Content-Type: text/plain;
 charset="iso-8859-1"
Content-Transfer-Encoding: 8bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4522.1200
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4522.1200

Jerry

Thanks for sending this info about the girls, it will be reviewed and we'll
let you know when they're published on Antiscam.org.

As for Trueloves.com, your allegations are totally unfair. My husband and I
own both Trueloves and Antiscam. Do you think that "crooked agency" would
have own antiscam site? In fact we were concerned with all this scam
situation and it was the reason for opening Antiscam.org. I personally
devote lots of my time screening and weeding out scammers from our site, by
the way doing that for free and only because I am honest person and don't
want my customers to be cheated. We don't promise that our site is 100% free
of scammers because nobody can make such a claim but we promise zero scam
tolerance and we keep our promise. If you saw some scammers on our site,
please report. We have a link "report scam or abuse" on each and every our
page. We delete profiles of scammers, block them from further postings and
expose them on Antiscam.org Our goal is to have clean database, not big
database. That is why those 6 or 7 profiles that you created and filled with
garbage were deleted.

Your idea of us being connected to spam is simply ridiculous. Nobody can see
your email, that's why members send first letter through the form. And we
earn our living by selling membership in this agency, not sending spam. I
guess you don't quite understand how all this works. Women create their
profiles themselves via the web, they can modify and delete them any time
they wish. They are absolutely real. By the way, if you were so much in
"doubt that a single of our candidates
is real", why you wrote more than three allowed free letters? We don't
respect such approach at all. This site is a full time job for us and we,
like everybody else, expect to be paid for work we do, not to be ripped off.

I don't think that you'll be able to find in whole Internet people more
concerned about their customers and about purity of their database than my
husband and me. And it's very disappointing to see that this quite rare
attitude is not appreciated at all.


Here's just one of the nasty letters we received from him:


Slushai, vonyuchaya suka : Ya soglasen isparitjsya raz na vsegda.
Da ya soglasen. Pri tom uslovii,
chto parolj E mail : erikvanlint@yahoo.com
budet kak ranshe : evlhevlh
Nikakix drugix pretenzii ne imeyu.
Mne ni ot tebya, ni ot tvoix telok ni xuya ne nado.
Vy prosto xaknuli E mail, i eto vam darom ne proidet.
Tam vsyakie pisma, kotorye mne nuzhny.
Mogu ix, konechno, vse zanovo sostavit, no mne prosto lenj.
Mozhesh vse skopirovat i zasunut sebe v pizdu.
Ty izmeni parolj , i u tebya so mnoi bolshe nikogda nikakix problem ne
budet. Ot menya bolshe
nikogda ni slova ne uslishesh, k gadalke ne xodi.
A ne to, mozhesh zavyazat svoi biznes.

And a translation, for thos who don't understand Russian:

Listen, you stinky bitch: I agree to disappear once and for good. Yeah, I agree.
But on my terms: password to email account erikvanlint@yahoo.com must be changed
as it was before evlhevlh There'll be no more claims. I don't need a fuck nor
from you neither from your cows. You simply hacked my email and it will cost
you. There're the letters I need. I of course can write them again, but I am
simply lazy. You may copy them all and stuff them in your cunt. Change the
password and you won't have any troubles with me ever. You won't ever hear from
me. But otherwise you're done with your business.

---------------------------------

Nice guy, huh? Please understand what kind of liar and psychopath you're dealing
with here. We run a completely honest business and value our reputation. This
guy attacked us for no reason, absolutely unprovoked.


On July 31, 2002 at 12:52:53, Sergei Smith wrote:

>I do believe you, but I had another, yet comparable problem.
>Actually I reported the authorities today a serious internet
>abuse by the online agency True Loves http://www.trueloves.com
>The Java scripts on this site are meant to retrieve information
>about their visitors for the purpose of spam mail,
>to retrieve their visitors' Credit Card information and their
>E mail address for which people often use the same password as
>they use to sign up for that site.
>Being unaware about this, I yesterday signed up twice
>at that site and noticed that the Java scripts on that site
>indeed retrieved browser info and maybe also CCard data.
>On that site I signed up with the same password
>as for my Hotmail account, my E mail was also hacked last
>night and this morning I immediately blocked my Credit Card
>account and wrote an e mail to the I.P. of that
>site's domain. The same webmaster also runs the
>(fake) site : www.antiscam.com
>He (or she) has a Yahoo ID : nadzaitz@yahoo.com
>2 hours ago I received a threatening E mail
>message from that address saying that they know
>all about me and that I must leave their I.P.
>alone because they have "muscular friends" all
>over the world and that they will sue me.
>That site is a scam and a dangerous one.
>My first reaction was to scream "bomb and nuke
>that skunk!" but maybe it's better to proceed
>with caution. NEVER use the same password twice.



This page took 0 seconds to execute

Last modified: Thu, 15 Apr 21 08:11:13 -0700

Current Computer Chess Club Forums at Talkchess. This site by Sean Mintz.