Thứ Sáu, 27 tháng 1, 2012

It's now been over a week since Formspring last replied (e-mails have been sent since, but no response).As such, I thought I'd list the current tally here again* - same criminals responsible as last time. You'd have thought that would make it easy to filter, especially given the keywords they're using are also exactly the same but alas - it seems they've resigned themselves to doing whatever it

Thứ Hai, 23 tháng 1, 2012

Oh dear, this isn't going to end well. To clarify folks - as securityerrata.org makes clear, there isn't a vulnerability here - it's a simple case of typo-squatting and attempted extortion.Introducing Arthur 'Wesley' Kenzie, aka SecurikaiLate in December of 2011, HD Moore received a curious email from "Arthur (Wesley) Kenzie" notifying him that Kenzie had "important information to discuss with

Chủ Nhật, 22 tháng 1, 2012

Well, I was hopeful after their last response, that there was finally going to be a reduction, but sadly it appears this isn't the case.As of 2 seconds ago, the abuse is still prolific, and it's STILL the same parties responsible;1. download2d.com2. mSpyI've had no response from Formspring, to the e-mail I sent a few days ago, so god only knows what's going on over there, but until they get a

Thứ Sáu, 20 tháng 1, 2012

Well, seems they're not keeping on top of it that well, still a few from this morning still active;http://www.formspring.me/kifihiclihttp://www.formspring.me/rytelnucomhttp://www.formspring.me/abarlaforhttp://www.formspring.me/engatreperhttp://www.formspring.me/erlasticenhttp://www.formspring.me/pharigeschlinghttp://www.formspring.me/unelsenlahttp://www.formspring.me/inphabalrahttp://

Thứ Năm, 19 tháng 1, 2012

I am pleased to report, I've been monitoring the Formspring.me abuse and they're now keeping on top of it, so all abusive pages created, are now being taken down relatively quickly.Still seems to be the same IP responsible for at least part of the abuse (188.143.232.113 - IP is well known for comment spam). Whether or not this is the same IP actually creating them in the first place, is something
Due to a power failure yesterday, the fSpamlist.com server was down from approx 21:20 (GMT London) until I woke up (around 40 minutes later) and fixed the issue. Sadly it turned out the power failure had corrupted not only the file system, but the MFT and MBR. This was fixed and the server brought back online.However, further corruption has been found in the PHP installation, preventing the sites

Thứ Tư, 18 tháng 1, 2012

The formspring.me abuse is continuing, but in the meantime, it looks like they're having a bash on eventbee.com too.http://www.eventbee.com/v/pharm/event?eid=839465373http://www.eventbee.com/v/pharm/event?eid=809069363http://www.eventbee.com/v/pharm/event?eid=830974301http://www.eventbee.com/v/pharm/event?eid=849867363http://www.eventbee.com/v/pharm/event?eid=879564391http://www.eventbee.com/v/

Thứ Ba, 17 tháng 1, 2012

As of this morning, the current tally for 2012 (Formspring were dropped an e-mail yesterday, and will be dropped another one in a few minutes as whatever they're doing to prevent this, evidently isn't working);18/01/2012 01:15    http://www.formspring.me/warphororo18/01/2012 01:12    http://www.formspring.me/derslitemppe18/01/2012 01:08    http://www.formspring.me/heitaistorab18/01/2012 01:05    
Looks like there's problems in the DomainMonster.com camp today. Their phones are coming back as temporarily unavailable, and whilst their website is working, mail servers seem to be down. The it-mate.co.uk incoming mail server is through DomainMonster, and sporadically failing, which sadly means I can send e-mails (different server), but can't receive them.I've tried both numbers available for

Thứ Hai, 16 tháng 1, 2012

Looks like Formspring still haven't pulled their finger out as the abuse over there is still drastically on-going, with no signs of anything changing.The latest batch includes;http://www.formspring.me/goamithedehttp://www.formspring.me/abteaneebehttp://www.formspring.me/adcommingsyndhttp://www.formspring.me/afodgageshttp://www.formspring.me/aftethenlanghttp://www.formspring.me/agunprosorhttp://

Thứ Hai, 2 tháng 1, 2012

Checking a newly registered site (videocelebritynews.com), I stumbled upon what I thought at first, was going to be the usual fake codec notice that tends to lead to a trojan. Hovering over the image however, immediately pointed to its being an advert, rather than the typical fake codec stuff we're used to seeing.Following the URL led straight to an iLivid executable;1. hxxp://