<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Richy&#039;s Random Ramblings &#187; Net: Spam</title>
	<atom:link href="http://blog.rac.me.uk/category/net-spam/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.rac.me.uk</link>
	<description>Random ramblings and ravings of Richy C</description>
	<lastBuildDate>Mon, 16 Jan 2012 12:16:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Spam: Text Message Spam</title>
		<link>http://blog.rac.me.uk/2003/12/30/spam-text-message-spam/</link>
		<comments>http://blog.rac.me.uk/2003/12/30/spam-text-message-spam/#comments</comments>
		<pubDate>Tue, 30 Dec 2003 19:29:07 +0000</pubDate>
		<dc:creator>Richy C.</dc:creator>
				<category><![CDATA[Net: Spam]]></category>

		<guid isPermaLink="false">http://blog.rac.me.uk/?p=586</guid>
		<description><![CDATA[This entry is mainly for my records, but it&#8217;s here if anybody else requires reference&#8230; Basically, at 19.20, I made the following complaint to ICSTIS and The Telephone Preference Service in relation to a spammy text (SMS) message I received: A SMS text message was sent at around 19:05 GMT (although the timestamp on the [...]]]></description>
			<content:encoded><![CDATA[<p>This entry is mainly for my records, but it&#8217;s here if anybody else requires reference&#8230;</p>
<p>Basically, at 19.20, I made the following complaint to <a href="http://www.icstis.org/icstis2002/default.asp?node=34">ICSTIS</a> and <a href="http://www.tpsonline.org.uk/tpsr/html/ComplaintForm.asp" class="broken_link">The Telephone Preference Service</a> in relation to a spammy text (SMS) message I received:</p>
<blockquote><p>A SMS text message was sent at around 19:05 GMT (although the timestamp on the message reads 00:43:53 31-12-2003) from +08717120395 to my telephone preference service registered mobile phone (07732XXXXXX) with the message:<br />
&#8220;You have 1 new BPQ voicemail message. Please call 0871 712 0395 to listen to it.&#8221;</p>
<p>When calling the number it says (in a format similar to a voicemail) &#8220;Sheila Brown of the BPQ awards department&#8221; tried calling and for me &#8220;reagrding an award prize which has to be claimed within 48hours&#8221; and for me to call 090 65393698 with NO cost of call disclosed.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://blog.rac.me.uk/2003/12/30/spam-text-message-spam/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Spam: I&#8217;m giving up&#8230;.</title>
		<link>http://blog.rac.me.uk/2003/12/29/spam-im-giving-up/</link>
		<comments>http://blog.rac.me.uk/2003/12/29/spam-im-giving-up/#comments</comments>
		<pubDate>Mon, 29 Dec 2003 00:59:26 +0000</pubDate>
		<dc:creator>Richy C.</dc:creator>
				<category><![CDATA[Net: Spam]]></category>

		<guid isPermaLink="false">http://blog.rac.me.uk/?p=585</guid>
		<description><![CDATA[I think I&#8217;m just about to give up on the email addresses provided by my ADSL provider (Demon). Why? Well, over Christmas Eve (from 4pm) to Boxing Day (2pm), I received nearly 25,000 emails. That&#8217;s a lot &#8211; but I&#8217;ve got a couple of custom Perl scripts which can crawl through my POP3 email box [...]]]></description>
			<content:encoded><![CDATA[<p>I think I&#8217;m just about to give up on the email addresses provided by my ADSL provider (Demon). Why? Well, over Christmas Eve (from 4pm) to Boxing Day (2pm), I received nearly 25,000 emails. That&#8217;s a lot &#8211; but I&#8217;ve got a couple of custom Perl scripts which can crawl through my POP3 email box and zap spam (as it&#8217;ll probably be dictionary attack sort of spam).</p>
<p>It&#8217;s now 4 days on and I&#8217;ve managed to delete over 44,450 emails and there are another 47,552 still awaiting deletion. Yep &#8211; that&#8217;s over 90,000 emails in a space of a few days(!) I&#8217;ve spent most of today re-writing my email zapper (it&#8217;s called cleardemon.pl by the way) to be more efficient (previously it was making a separate connection to the mail server for each &#8220;attack name&#8221;: but now the last of &#8220;spammed addresses&#8221; is over 1,400 I needed to make it work on the mail as a group). But still running TOP on the emails in 1,000 blocks and then sending the DELETE command didn&#8217;t have much affect (it was taking around a quarter of a second to a second to send the delete command for each email: in that time 2 more emails came in!).</p>
<p>I&#8217;m now running a quick script to try and clear the POP3 mailbox down a bit more (by just sending 50,000 &#8220;DELETE&#8221; commands to the server), but I don&#8217;t hold up much hope. It&#8217;s looking like I&#8217;m going to have to give tech support a call tomorrow to get them just to flush my mailbox.</p>
<p>Why don&#8217;t I run something like SpamAssassin? Well, I would if I could. But it&#8217;s a &#8220;dialup/ADSL&#8221; POP3 email account, Demon don&#8217;t provide SMTP delivery to ADSL customers (but they do to conventional dial-up Modem users: go figure!) and I can&#8217;t change the MX records either. The good news is is that in the new year, they are introducing <a href="http://www.brightmail.com">Brightmail</a> filtering which should hopefully see spam drop (I&#8217;ve heard of figures between 75% and 98% with less than 1 in one million false positives!).</p>
<p>Ho hum. Oh, since typing the last two paragraphs I&#8217;ve now got 47,729 emails awaiting deletion: that&#8217;s nearly 200 emails in a matter of minutes(!).</p>
<p>[add] Actually, I&#8217;ve just taken a five minute average from 00:52 to 00:57 and I&#8217;m getting 16.6 emails per minute: that&#8217;s 996 per hour or 23,904 per day! Gulp!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.rac.me.uk/2003/12/29/spam-im-giving-up/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Spam: Customer Data, Let&#8217;s Sell It!</title>
		<link>http://blog.rac.me.uk/2003/11/24/spam-customer-data-lets-sell-it/</link>
		<comments>http://blog.rac.me.uk/2003/11/24/spam-customer-data-lets-sell-it/#comments</comments>
		<pubDate>Mon, 24 Nov 2003 23:24:10 +0000</pubDate>
		<dc:creator>Richy C.</dc:creator>
				<category><![CDATA[Net: Spam]]></category>

		<guid isPermaLink="false">http://blog.rac.me.uk/?p=574</guid>
		<description><![CDATA[My system has just tagged that Driveway.com (aka IBackup.com) and Sandbox.com have sold on their mailing lists with one of my email addresses to a spammer. I receive almost identical emails to two tagged addresses: one I used on driveway.com, the other sandbox.com: contents follow&#8230;. Both were sent from were &#8220;injected&#8221; directly into my incoming [...]]]></description>
			<content:encoded><![CDATA[<p>My system has just tagged that Driveway.com (aka IBackup.com) and Sandbox.com have sold on their mailing lists with one of my email addresses to a spammer. I receive almost identical emails to two tagged addresses: one I used on driveway.com, the other sandbox.com: contents follow&#8230;.</p>
<p>Both were sent from were &#8220;injected&#8221; directly into my incoming SMTP server (instead of being sent via their ISP), both claimed to have been sent via Eudora, and both had incorrect/faked Message-Ids (that message ID&#8217;s were actually created by my mail server). Oh &#8211; and they were both in HTML format and had &#8220;web bugs&#8221; in them (images loaded from a remote server which would enable the spammer to see who opened the email and therefore whose email address was valid).</p>
<p>Needless to say, both spams got reported via <a href="http://spamcop.net/">Spamcop.net</a> to their upstream providers.<br />
<span id="more-574"></span><br />
Driveway.com spam email (my details XXXX&#8217;d out)</p>
<blockquote><p>
Return-path: &lt;kq@freeality.com&gt;<br />
[snip]<br />
Received: from [68.51.147.107] (helo=freeality.com)<br />
	by XXXXXwith smtp id 1AONaE-0002&#215;7-Ah<br />
	for XXXX@XXXXX; Mon, 24 Nov 2003 20:45:22 +0000<br />
From: Medical Miracle &lt;VrCzJNd@freeality.com&gt;<br />
To: XXXX@XXXXX<br />
Subject: Sexual Sensations come only once in a lifetime ..<br />
Date: Mon, 24 Nov 2003 16:45:56 -0500<br />
Mime-Version: 1.0<br />
X-Priority: 3 (Normal)<br />
X-MSMail-Priority: Normal<br />
X-Mailer: QUALCOMM Windows Eudora Version 5.1<br />
Content-Type: text/html; charset=&#8221;iso-8859-1&#8243;<br />
Content-Transfer-Encoding: 7bit<br />
Message-Id: </p>
<p>&lt;HTML&gt;<br />
&lt;head&gt;<br />
&lt;body bgcolor=&#8221;WHITE&#8221;&gt;<br />
&lt;/head&gt;<br />
&lt;div ALIGN=&#8217;CENTER&#8217;&gt;&lt;A HREF=&#8221;http://m3z.biz/vpoil/?eLRJ&#8221;&gt;&lt;IMG ALT=&#8221;Loading..&#8221; SRC=&#8221;http://211.162.108.122/L/2/Zitx.gif&#8221; BORDER=&#8217;0&#8242;&gt;&lt;/A&gt;&lt;/div&gt;<br />
&lt;br&gt;&lt;br&gt;<br />
&lt;DIV align=&#8221;CENTER&#8221;&gt;&lt;A href=&#8221;http://211.162.108.122/o.html?gHezqi&#8221;&gt;Stop&lt;/a&gt; future announcements&lt;/DIV&gt;<br />
&lt;br&gt;&lt;br&gt;<br />
&lt;/BODY&gt;<br />
&lt;/HTML&gt;
</p></blockquote>
<p>Sandbox.com spam email (again my details XXXX&#8217;d out)</p>
<blockquote><p>
Return-path: &lt;mAWrV@kindredkonnections.com&gt;<br />
[snip]<br />
Received: from [82.131.5.40] (helo=fotf.org)<br />
	by XXXXXX with smtp id 1AONfQ-0002z0-FH<br />
	for XXXX@XXXX; Mon, 24 Nov 2003 20:50:44 +0000<br />
From: Medical Phenomenon &lt;ZM@freeality.com&gt;<br />
To: XXXX@XXXX<br />
Subject: Bedroom Sensations only come once<br />
Date: Mon, 24 Nov 2003 16:51:18 -0500<br />
Mime-Version: 1.0<br />
X-Priority: 3 (Normal)<br />
X-MSMail-Priority: Normal<br />
X-Mailer: QUALCOMM Windows Eudora Version 5.1<br />
Content-Type: text/html; charset=&#8221;iso-8859-1&#8243;<br />
Content-Transfer-Encoding: 7bit<br />
Message-Id: &lt;E1AONfQ-0002z0-FH@XXXX&gt;</p>
<p>&lt;html&gt;<br />
&lt;HEAD&gt;<br />
&lt;BODY BGCOLOR=&#8221;WHITE&#8221;&gt;<br />
&lt;/head&gt;<br />
&lt;div align=&#8217;CENTER&#8217;&gt;&lt;a HREF=&#8221;http://m3z.biz/vpoil/?IqquR&#8221;&gt;&lt;IMG ALT=&#8221;Loading..&#8221; src=&#8221;http://211.162.108.122/L/2/KvHSxnx.gif&#8221; border=&#8217;0&#8242;&gt;&lt;/a&gt;&lt;/DIV&gt;<br />
&lt;br&gt;&lt;BR&gt;<br />
&lt;DIV align=&#8217;CENTER&#8217;&gt;&lt;A href=&#8221;http://211.162.108.122/o.html?sMzlVr&#8221;&gt;Stop&lt;/a&gt; future announcements&lt;/DIV&gt;<br />
&lt;br&gt;&lt;br&gt;<br />
&lt;/BODY&gt;<br />
&lt;/HTML&gt;
</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://blog.rac.me.uk/2003/11/24/spam-customer-data-lets-sell-it/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Spam: Telephone Soliciting II</title>
		<link>http://blog.rac.me.uk/2003/10/25/spam-telephone-soliciting-ii/</link>
		<comments>http://blog.rac.me.uk/2003/10/25/spam-telephone-soliciting-ii/#comments</comments>
		<pubDate>Sat, 25 Oct 2003 19:15:20 +0000</pubDate>
		<dc:creator>Richy C.</dc:creator>
				<category><![CDATA[Net: Spam]]></category>

		<guid isPermaLink="false">http://blog.rac.me.uk/?p=562</guid>
		<description><![CDATA[Further to a telephone call I received (along with some of you) on the 16th of September, I have just received the following letter from ICSTIS (the regulatory of premium rate telephone numbers in the UK) which basically states the company has been fined &#163;10,000 and barred access to &#8220;The Prize Warehouse&#8221;&#8216;s service for twelve [...]]]></description>
			<content:encoded><![CDATA[<p>Further to a telephone call I received (along with some of you) on the <a href="http://blog.rac.me.uk/archives/000547.html">16th of September</a>, I have just received the following letter from <a href="http://www.icstis.org.uk/">ICSTIS</a> (the regulatory of premium rate telephone numbers in the UK) which basically states the company has been fined &pound;10,000 and barred access to &#8220;The Prize Warehouse&#8221;&#8216;s service for twelve months (so it&#8217;s quite a breach: checking action they&#8217;ve taken against <a href="http://www.icstis.org.uk/icstis2002/default.asp?node=48">other companies</a> shows an &#8220;average&#8221; of around &pound;1,000 fine and 6 months barring).</p>
<p>Success! Just shows &#8211; if you complain to the right people you can get the scumbags removed! I&#8217;m just waiting for the response from <a href="http://www.tpsonline.org.uk">The Telephone Preference Service</a> and mwhhaa! I&#8217;ve actually just received a spam SMS text message to my mobile phone (which is registered with TPS) so I&#8217;ll be sending off another complaint in the next day or so.</p>
<p>Read on for a copy of the letter.<br />
<span id="more-562"></span></p>
<blockquote>
<p align="right">ICSTIS<br />
The Independent Committee for the Supervision of<br />
Standards of Telephone Information Services<br />
4th Floor, Clover Building, 4 Maguire Street, London, SE1 2NQ<br />
Tel: 020 7940 7474. Fax: 020 7940 7456<br />
Press Office: 020 7940 7408<br />
Email: secretariat@icstis.org.uk<br />
Web: www.icstis.org.uk</p>
<p>Dr Mr xxxxxxx,</p>
<p><b>Unsolicited Telephone Marketing &#8211; prize competition</b></p>
<p>I am writing with reference to your complaint about the receipt of an unsolicited telephone call advising the recipient that they had won a prize and which asked them to dial a premium rate number in order to make a claim. Please accept my apologies for the delay in my reply that is unfortunately due to a backlog of complaints.</p>
<p>As you may now be aware, ICSTIS supervises both the content and advertising for premium rate services. ICSTIS develops and applies a Code of Practice to the companies that operate premium rate services (service providers). These companies are bound by their contract with the network operators such as BT, Cable &amp; Wireless and Vodafone to comply with the requirements of this Code. Premium rate numbers are usually prefixed with the 090 code.</p>
<p>An investigation has been undertaken into the promotion of an unsolicited automated telephone message about which you have complained and the ICSTIS Committee has recently found breaches of the ICSTIS Code Of Practice. The promotion of a recorded competition information line was found have been done so inappropriately, as well as being found to be misleading. The promotion failed to meet a number of specific provisions that apply to competition services and the content of the recorded message was found to be unduly delayed. In view of the breaches found, the Committee decided that a fine of &pound;10,000 should be imposed and that access to the service should be barred for twelve months.</p>
<p>Should you wish to purse redress or to ensure that your details have been removed from a company&#8217;s databases, we recommend that you contact the company responsible for the service and message directly. In this case, the details we have for the company in question are as follows:</p>
<p>The Prize Warehouse<br />
PO BOX 6017<br />
Basingstoke<br />
RG21 4ZB</p>
<p>You can register your wish not to receive unsolicited telephone marketing calls by contacting the Telephone Preference Service (TPS) on 020 7291 3300.</p>
<p>Individuals whose numbers are already registered with the TPS should contact the Office of the Information Commissioner, the body that enforces data protection and privacy legislation, to register a formal complaint on 01625 545 700.</p>
<p>I hope that this is clear and we would like to thank you for taking the time to contact us.</p>
<p>Yours sincerely,</p>
<p>xxx xxxx<br />
Case Officer
</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://blog.rac.me.uk/2003/10/25/spam-telephone-soliciting-ii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spam: 15k Emails&#8230;</title>
		<link>http://blog.rac.me.uk/2003/10/19/spam-15k-emails/</link>
		<comments>http://blog.rac.me.uk/2003/10/19/spam-15k-emails/#comments</comments>
		<pubDate>Sun, 19 Oct 2003 17:18:49 +0000</pubDate>
		<dc:creator>Richy C.</dc:creator>
				<category><![CDATA[Net: Spam]]></category>

		<guid isPermaLink="false">http://blog.rac.me.uk/?p=557</guid>
		<description><![CDATA[Quick notification: if you&#8217;ve got an email address for me ending in .demon.co.uk (such as example.demon.co.uk) please change it to just .com (so an email address of joebloggs@example.demon.co.uk will change to joebloggs@example.com ). I&#8217;m having to migrate all my email accounts to my main server from my 8year old+ Demon ISP mailbox as the spam [...]]]></description>
			<content:encoded><![CDATA[<p>Quick notification: if you&#8217;ve got an email address for me ending in .demon.co.uk (such as example.demon.co.uk) please change it to just .com (so an email address of joebloggs@example.demon.co.uk will change to joebloggs@example.com ). I&#8217;m having to migrate all my email accounts to my main server from my 8year old+ Demon ISP mailbox as the spam levels have just got too high. Yesterday I deleted over 15,000 emails from my Demon ISP account leaving less than 5,000 to delete today: by the time I woke up the levels were back up to 14,700 and growing <img src='http://blog.rac.me.uk/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<p>This wouldn&#8217;t be too bad apart from the fact Demon&#8217;s mail servers are suffering from the load &#8211; as <a href="http://www.gradwell.com/mail-rtt/web.pl" class="broken_link">Gradwell&#8217;s ISP Mail System Performance</a> chart shows, emails sent to demon.co.uk email addresses are taking over 6 hours <b>on average</b> to arrive: and that&#8217;s just not good enough for me (plus the lack of &#8220;server side filtering&#8221; makes things even worse).</p>
<p>I&#8217;m still planning on keeping Demon for my ADSL connectivity at the moment (I haven&#8217;t got time to currently hunt ADSL providers that can offer over 3Gb/traffic per day), but I no longer trust them with my email.</p>
<p>However &#8211; the Gradwell chart shows that one of our (ie my employers) main rivals in one portion of their business &#8211; UK2.net &#8211; is just as bad as Demon. 5hours+ delays and 13 missing emails.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.rac.me.uk/2003/10/19/spam-15k-emails/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Game: SpamWars</title>
		<link>http://blog.rac.me.uk/2002/12/31/game-spamwars/</link>
		<comments>http://blog.rac.me.uk/2002/12/31/game-spamwars/#comments</comments>
		<pubDate>Tue, 31 Dec 2002 17:28:08 +0000</pubDate>
		<dc:creator>Richy C.</dc:creator>
				<category><![CDATA[Net: Spam]]></category>

		<guid isPermaLink="false">http://blog.rac.me.uk/?p=179</guid>
		<description><![CDATA[This game reminds me so much of real life. In SpamWars you control a gun and have got to stop the spam from reaching the keyboard by shooting at it. You&#8217;ve also got to try and aim at Sid the Spammer to try and kill him and stop him sending the stuff &#8211; as the [...]]]></description>
			<content:encoded><![CDATA[<p><img alt="[Spamwars]" src="http://blog.rac.me.uk/photos/spamwars.jpg" width="110" height="75" border="0" align="left" />This game reminds me so much of real life. In <a href="http://www.elated.com/spamwars/">SpamWars</a> you control a gun and have got to stop the spam from reaching the keyboard by shooting at it. You&#8217;ve also got to try and aim at Sid the Spammer to try and kill him and stop him sending the stuff &#8211; as the levels progress he starts sending you viruii/viruses as well: not fun.</p>
<p>On seconds thoughts, it is a fun game &#8211; I scored 3,860 on my first go and 10,430 on my second. Once you get a machine gun or flame-thrower (yep, you can get &#8220;gun upgrades&#8221;) you can easily kill Sid straight away before he sends you any spam and get bonus points.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.rac.me.uk/2002/12/31/game-spamwars/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spam: SpamCop Statistics: A Month On</title>
		<link>http://blog.rac.me.uk/2002/12/18/spam-spamcop-statistics-a-month-on/</link>
		<comments>http://blog.rac.me.uk/2002/12/18/spam-spamcop-statistics-a-month-on/#comments</comments>
		<pubDate>Wed, 18 Dec 2002 11:13:10 +0000</pubDate>
		<dc:creator>Richy C.</dc:creator>
				<category><![CDATA[Net: Spam]]></category>

		<guid isPermaLink="false">http://blog.rac.me.uk/?p=133</guid>
		<description><![CDATA[Well, it&#8217;s now been a month since I commenced reporting a selection of my spam to Spamcop (see the results of my first week reporting). My spam levels have been quivering between only about a dozen a day (usually at weekends) to the deluge I got yesterday of around 800 I tend to report each [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://spamcop.net/"><img alt="[Spamcop]" src="http://blog.rac.me.uk/photos/spamcop.gif" width="89" height="81" border="0" align="left" /></a>Well, it&#8217;s now been a <a href="http://blog.rac.me.uk/archives/000057.html">month</a> since I commenced reporting a selection of my spam to <a href="http://www.spamcop.net/">Spamcop</a> (see the results of my <a href="http://blog.rac.me.uk/archives/000072.html">first week reporting</a>).</p>
<p>My spam levels have been quivering between only about a dozen a day (usually at weekends) to the deluge I got yesterday of around 800 <img src='http://blog.rac.me.uk/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />  I tend to report each &#8220;unique&#8221; message to Spamcop (selected on the criteria of &#8220;To:&#8221; address and &#8220;Subject:&#8221; being different from the spam I have in my mailbox at that time &#8211; some spammers send around 20 mails to the same address with the same subject: only one of those gets reported).</p>
<p>Ok, a month and a day ago (yep, I should have done this entry yesterday) I purchased 25Mb of &#8220;Spamcop reporting&#8221; (<a href="http://spamcop.net/accountadd.shtml">paying</a> for membership just adds a few fancy things such as &#8216;past reports&#8217; and &#8216;amount of spam reported&#8217; &#8211; it also removes a few ads and the &#8220;parse&#8221; time delay). I now have just 10.3Mb left. Yep &#8211; in a month, I&#8217;ve <b>reported</b> just under 15Mb of spam. My &#8220;average usage rate&#8221; is 5.53bytes per second or 14.3Mb per month or a massive 174.4Mb per year (that&#8217;s an increase of 50.5Mb per year since <a href="http://blog.rac.me.uk/archives/000072.html">3 weeks ago</a>).</p>
<p>At the moment, I seem to be reporting more like 10% of my spam to Spamcop &#8211; therefore I <b>receive</b> around 55.3bytes of spam EVERY SECOND: that&#8217;s 4.5Mb a day. A month, that&#8217;s 136Mb. So &#8211; therefore, I receive in the region of 1.63Gb of spam a year.</p>
<p>The good news is that after the well known spammer <a href="http://www.spamhaus.org/rokso/search.lasso?evidencefile=1761" class="broken_link">Alan Ralksy</a> was featured on a <a href="http://slashdot.org/article.pl?sid=02/11/22/1658256">Slashdot article</a> (referring to a <a href="http://www.freep.com/money/tech/mwend22_20021122.htm" class="broken_link">freep</a> interview) several Slashdot visitors decided to &#8220;turn the tables&#8221; on him. They&#8217;ve <a href="http://www.freep.com/money/tech/mwend6_20021206.htm" class="broken_link">signed him up</a> with <a href="http://www.ajb.com.au/news.asp?nid=262" class="broken_link">practically</a> every form of &#8220;snail mail&#8221; to his home address of 6747 Minnow Pond Drive, West Bloomfield, Michigan, MI 48322, USA. Of course, the other Slashdotters <a href="http://slashdot.org/article.pl?sid=02/12/06/1554227">were happy</a> to hear this <img src='http://blog.rac.me.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><a href="http://www.cmsconnect.com/News/CMSInPrint/DN-020804-pg2.htm">Ralsky</a> was actually sued by the <a href="http://www.verizon.com/">Verizon</a> company and is barred <a href="http://yro.slashdot.org/yro/02/10/30/2137233.shtml">from sending</a> their customers spam <a href="http://www.washingtonpost.com/ac2/wp-dyn?pagename=article&amp;node=&amp;contentId=A38429-2002Oct29&amp;notFound=true">late in October</a>&#8230; Ralsky doesn&#8217;t, however, <a href="http://www.freep.com/money/tech/mwend13_20021213.htm" class="broken_link">seem too</a> happy about people taking photographs of his house &#8211; <a href="http://www.vatnebok.no/eggplant/" class="broken_link">Rich Clark</a> has received some threatening phone calls within 24 hours of taking some quite nice <a href="http://www.vatnebok.no/eggplant/gallery.html" class="broken_link">photographs</a>.</p>
<p>Oh &#8211; and <a href="http://legal.web.aol.com/decisions/dljunk/cnprod.html">AOL</a> <a href="http://news.com.com/2100-1023-978019.html?tag=fd_top">also</a> <a href="http://www.washtimes.com/business/20021218-7356418.htm" class="broken_link">won</a> <a href="http://msnbc.com/news/848386.asp?0dm=C12LT" class="broken_link">a</a> <a href="http://www.forbes.com/technology/newswire/2002/12/16/rtr825128.html" class="broken_link">spam</a> <a href="http://www.theregister.co.uk/content/6/28600.html">case</a> <a href="http://yro.slashdot.org/article.pl?sid=02/12/16/2150255">against</a> the spammer outfit CN Productions and owner Jay Nelson.</p>
<p>Are the tables turning against the spammers after so long? I hope so&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.rac.me.uk/2002/12/18/spam-spamcop-statistics-a-month-on/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Spam: An anatomy of a spam</title>
		<link>http://blog.rac.me.uk/2002/11/26/spam-an-anatomy-of-a-spam/</link>
		<comments>http://blog.rac.me.uk/2002/11/26/spam-an-anatomy-of-a-spam/#comments</comments>
		<pubDate>Tue, 26 Nov 2002 18:55:52 +0000</pubDate>
		<dc:creator>Richy C.</dc:creator>
				<category><![CDATA[Net: Spam]]></category>

		<guid isPermaLink="false">http://blog.rac.me.uk/?p=75</guid>
		<description><![CDATA[Damn! I&#8217;ve just been hit by another &#8220;hit-and-run&#8221; spammer. They sent around 900 spam emails to me in little under an hour (I was busy doing other things so I didn&#8217;t notice the start of the run). Drat! Only 76 got reported to SpamCop though. What really got annoyed was the fact that they had [...]]]></description>
			<content:encoded><![CDATA[<p><img alt="[Spam headed computer]" src="http://blog.rac.me.uk/photos/spamshootcomputer.jpg" width="93" height="89" border="0" align="left" />Damn! I&#8217;ve just been hit by another &#8220;hit-and-run&#8221; spammer. They sent around 900 spam emails to me in little under an hour (I was busy doing other things so I didn&#8217;t notice the start of the run). Drat! Only 76 got reported to SpamCop though.</p>
<p>What really got annoyed was the fact that they had sent 20 identical messages to the same email address each time. And they had an average size of 20.7Kb each. *Richy nashes teeth*</p>
<p>So, for your &#8220;amusement&#8221; and interest, I have &#8220;captured&#8221; one of the spams and &#8220;disassembled&#8221; it for you.<br />
<span id="more-75"></span><br />
An anatomy of the spam I received&#8230;.</p>
<blockquote><p>Received: from punt-1.mail.demon.net by mailstore for <a href="mailto:submit@spamarchive.org">submit@spamarchive.org</a><br />
   id 1038227951:10:13224:267; Mon, 25 Nov 2002 12:39:11 GMT</p></blockquote>
<p>This, although it is the first Received: line, is technically the last one. This shows that one my POP3 mail servers (ya know, the servers which you &#8216;normally&#8217; pick up your email from) received a message destined for my email address (here substituted with <a href="mailto:submit@spamarchive.org">submit@spamarchive.org</a> to try and catch spammers) at 12:39:11GMT on Monday.</p>
<blockquote><p>Received: from [203.206.197.10] ([203.206.197.10]) by punt-1.mail.demon.net<br />
   id aa1018094; 25 Nov 2002 12:38 GMT</p></blockquote>
<p>This line shows the mail server (punt-1.mail.demon.net) actually receiving the spam from the spammer&#8217;s server. You&#8217;ll notice that there are two sets of IP addresses shown: the first is what the sending mail server &#8220;claims&#8221; to be, the the second (in brackets) is what &#8220;my&#8221; mail server recognised the sending server as. Usually you may see something like &#8220;outbound.example.com ([127.0.0.1])&#8221; &#8211; this shows that the sending mail server claimed to be the server at &#8220;outbound.example.com&#8221; and &#8220;my&#8221; mail server detected its IP as 127.0.0.1 (which is wouldn&#8217;t do normally as the 127.x.x.x is a reserved &#8220;netblock&#8221; for loopback testing and hence shouldn&#8217;t be seen in &#8220;the wild&#8221;: other reserved netblocks are 10.x.x.x, 172.(16-31).x.x, and 192.168.x.x). Example.com is a &#8220;reserved&#8221; domain name as well.</p>
<p>Since I know I can &#8220;trust&#8221; punt-1.mail.demon.net to correctly report the IP address of the sending server and since this is the first Received: line, I know that the spam was sent for 203.206.197.10. Looking up the IP address via <a href="http://www.samspade.org/">SamSpade</a> reveals that it belongs to the netrange 202.0.0.0 to 203.255.255.255 which is suballocated by the <a href="http://www.apnic.net/">APNIC</a> (Asia Pacific Network Information Centre). So off we pop to their website do a quick WhoIs search and we find out that the sub-range 203.206.0.0 to 203.206.255.255 is allocated to &#8220;<a href="http://www.flow.com.au/">Flow Communications</a>&#8221; in Sydney, Australia. So we&#8217;ll notify them of this abuse of their &#8220;<a href="http://www.flow.com.au/products/internet/broadband/terms" class="broken_link">Terms And Conditions Of Usage</a>&#8221;</p>
<p>Checking the IP address against a the <a href="http://rbls.org/">Multi-RBLs</a> list of open relays reveals the company that uses 203.206.197.10 (as Flow Communications are just their ISP) are operating what is called an &#8216;open-relay&#8217;: a email server that will allow anyone to send email through it. In the early days of the internet, this was a good thing as mail would get to the destination no matter what: but they were so abused that running an open relay mail server is &#8220;bad&#8221; and there are a number of <a href="http://ch.dmoz.org/Computers/Internet/Abuse/Spam/Blacklists/" class="broken_link">blacklists</a> listing these abused servers.</p>
<blockquote><p>Reply-To: &lt;alerene22qxi328@example.com&gt;</p></blockquote>
<p>Many spammers use fake &#8216;Reply-To:&#8217; and &#8216;From:&#8217; lines to ensure that bounced mail and complaints don&#8217;t come back to them. If their product/service was so good, why go through the effort of hiding who you are? In this instance, we do not complain to &#8220;example.com&#8221; (not the original domain) as they are an innocent bystander who is probably already p&#8212;d off with the number of complaints they have received.</p>
<blockquote><p>Message-ID: &lt;031d55d43e2e$5838d4a5$7cc23bc1@owhsfv&gt;</p></blockquote>
<p>The message ID can be ignored 99.99% of the time &#8211; it is extremely rare that it provides any useful information &#8211; occasionally you may be able to recognise the &#8220;pattern&#8221; of the message ID and work out which item of <a href="http://www.sengir.demon.co.uk/spam_sites.html" class="broken_link">SpamWare</a> software the spammer is using to send the message, but even that information is near enough worthless.</p>
<blockquote><p>From: &lt;alerene22qxi328@example.com&gt;</p></blockquote>
<p>See &#8220;Reply-To:&#8221; above.</p>
<blockquote><p>To: &lt;submit@spamarchive.org&gt;</p></blockquote>
<p>Now, this is unusual &#8211; a &#8220;To: &#8221; line with the email address that the spam was sent to correctly filled in! Usually, you may find a whole list of email addresses in this field (or the &#8220;CC:&#8221; field), or something like &#8220;Undisclosed Recipient&#8221; as the spammer used a similar system to BCC: (Blind Carbon Copy) to send out the spams. A &#8220;unique&#8221; To: line like this indicates that the spam was sent in a manner of one-at-a-time: for bulk emailing, this is slower (as instead of sending one spam to several million addresses, you send one spam to a single address repeated several million times), but it does get through some peoples spam filters (as they filter on the basis &#8220;Is my email address in to To: field&#8221;).</p>
<blockquote><p>Subject: Need a Mortgage Loan That Works For You, 5.25% 30 yr. Fixed Rate.</p></blockquote>
<p>A mortgage for 30years? *shudder* No thanks, my now <a href="http://blog.rac.me.uk/archives/000033.html">23 year mortgage</a> is more than long enough! Plus, it&#8217;ll probably only be only applicable to US residents (although they sent the spam to email addresses ending in .co.uk)</p>
<blockquote><p>Date: Mon, 25 Nov 2002 12:34:02 -0000<br />
MiME-Version: 1.0<br />
Content-Type: multipart/mixed;<br />
	boundary=&#8221;&#8212;-=_NextPart_000_00E3_62A22B6D.B7818C24&#8243;<br />
X-Priority: 3 (Normal)</p></blockquote>
<p>Standard email headers &#8211; but the multipart/mixed line indicates that this message <b>could</b> could have attachments to it.</p>
<blockquote><p>X-MSMail-Priority: Normal<br />
X-Mailer: Microsoft Outlook Express 5.00.2919.6700<br />
Importance: Normal</p></blockquote>
<p>Whilst it is possible for someone to send bulk email using Microsoft Outlook Express, it isn&#8217;t conceivable that someone would do this as it would be too time-consuming. Therefore, it is common for spammers to set lines like X-Mailer: to &#8216;imitate&#8217; or &#8216;fake&#8217; a valid email program&#8217;s details: after all, lots of spam sent out tagged &#8216;X-Mailer: SpamWare 1.94 Super!&#8217; would soon be filtered and blocked&#8230;</p>
<blockquote><p>&lt;html&gt;</p></blockquote>
<p>Nooo! HTML email! Do NOT ever send me HTML email: email was designed to be plain ASCII text which can be read by practically anything. HTML mail limits you to using things like Microsoft Outlook and similar programs which support HTML inline. If I decide to read my email &#8220;on the server&#8221; or via <a href="http://www.mailwasher.net/">MailWasher</a>, then I just get a bunch of HTML code.</p>
<p>Plus, the fact that HTML mail can contain <a href="http://www.privacyfoundation.org/resources/webbug.asp#10">web bugs</a> &#8211; which are references to little images on the spammer&#8217;s server which will allow them to see who has &#8216;opened&#8217; their email. Oh, and HTML mail <b>could</b> also include Javascript/ActiveX style components which could do all sorts of nasty things to your machine (see the <a href="http://securityresponse.symantec.com/avcenter/venc/data/wscript.kakworm.html">KAK Worm</a> for an example of this). Just to let you all know, I&#8217;ve disabled all &#8216;scripting&#8217; components from running in my mail client (I personally would prefer to use <a href="http://www.ant.co.uk/" class="broken_link">ANT&#8217;s</a> Marcel email client as it is a &#8216;no-frills&#8217; package which doesn&#8217;t support HTML) and I&#8217;ve also limited the ports+machines my email client can attach to: therefore web bugs, &#8220;inline graphics&#8221; etc just will not run on my machine.</p>
<blockquote><p>[snipped large chunk of email]<br />
&lt;a title=&#8221;http://rd.yahoo.com/468/103/*http://INNOCENT.EXAMPLE.com/m1000/&#8221;<br />
href=&#8221;http://EXAMPLE.COM/d/mortgage3&#8243;&gt;</p></blockquote>
<p>Here we see signs of the spammer being crafty. The &lt;a title&gt; just acts as an indicator to where this link leads to: it will appear on the users screen and in their &#8216;status&#8217; bar and is usually used for &#8216;informative&#8217; items. However, in this case, the spammer is framing TWO innocent parters: Yahoo and &#8220;Innocent Example&#8221;.</p>
<p>For &#8220;user-tracking&#8221; purposes, <a href="http://www.yahoo.com/">Yahoo</a> redirects people following certain links from their site through their &#8220;redirection&#8221; server http://rd.yahoo.com &#8211; however, it is easy to change the parameters of the &#8220;destination&#8221; the redirect is going to and hence anyone visiting that link will go to the http://innocent.example.com/ site via Yahoo!. However, and this is the sneaky part, spam complaints MAY get directed to Yahoo! as their URL is being &#8220;spamvertised&#8221; in this manner &#8211; luckily, <a href="http://spamcop.net/">SpamCop</a> and many other semi-automated systems are &#8220;wise&#8221; to this trick and don&#8217;t send complaints to Yahoo.</p>
<p>The &#8220;real&#8221; URL of the spammers site is shown in the &#8216;href&#8217; section &#8211; in this case it would be http://EXAMPLE.COM/d/mortgage3 (the real URL has now been shut-down by the spammer&#8217;s ISP).</p>
<blockquote><p>Anti-SPAM Policy Disclaimer: Under Bill s.1618 Title III passed by the 105th U.S. Congress, mail cannot be considered spam as long as we include contact information and a remove link for removal from this mailing list. If this e-mail is unsolicited, please accept our apologies. Per the proposed H.R. 3113 Unsolicited Commercial Electronic Mail Act of 2000, further transmission to you by the sender may be stopped at NO COST to you! &lt;a href=&#8221;mailto:chrisericson6@hotmail.example.com&#8221;&gt;Remove&lt;/a&gt;</p></blockquote>
<p>Ok, first of all, I&#8217;m UK based so this is not relevant to me (but the UK <a href="http://www.hmso.gov.uk/acts/acts1990/Ukpga_19900018_en_1.htm">Computer Misuse Act</a> section 3.2 does apply to my systems &#8211; and I never authorised the spammer to use them!), secondly this was advertising a mortgage service and advertisements for said services in the UK need a disclaimer such as: &#8220;<i>YOUR HOME IS AT RISK IF YOU DO NOT KEEP UP YOUR REPAYMENTS ON A MORTGAGE OR OTHER LOAN SECURED ON IT</i> and thirdly &#8211; S1618 was never passed as a law!</p>
<p>Yep, that&#8217;s what &#8211; the spammer is lying to us &#8220;big time&#8221;, here&#8217;s the background:<br />
The <a href="http://ch.dmoz.org/Regional/North_America/United_States/Government/Legislative_Branch/Senate/" class="broken_link">US Senate</a> Bill <a href="http://thomas.loc.gov/cgi-bin/bdquery/z?d107:s.01618:">1618</a> (aka &#8220;S.1618&#8243;) had a section (301) referring to transmissions of unsolicited commercial email (aka &#8220;spam&#8221; to me). It <b>was</b> approved by the US Senate on the 12th of May 1998 and referred to the <a href="http://energycommerce.house.gov/">House Committee On Commerce</a> on 21st October 1998. However, the Bill then &#8220;died&#8221; and did not become law. And as <a href="http://www.d-pendablelibrary.com/reinboldcongress.htm" class="broken_link">this article states</a>, to actually comply with this non-existent law, spammers would have to include their name, physical address, email address and telephone number at the beginning of the email. So, bang, this email definitely does NOT comply with the law.</p>
<p>Continuing on &#8220;<i>Per the proposed</i>&#8221; &#8211; proposed: i.e. not law &#8220;<i>further transmission to you by the sender may be stopped at NO COST to you</i>&#8220;, so my bandwidth, time and storage (because I keep all copies of outgoing email) is no worthless? I think I can count all of those as valid costs&#8230; </p>
<p>It then gives me a &#8220;email drop box&#8221; address (on <a href="http://www.hotmail.com/">Hotmail</a>) to send an email to if I want to get off their list (a list I never asked to be on in the first place). I have never responded in this manner for the reasons <a href="http://spam.abuse.net/overview/remove.shtml">Abuse.net</a> outlines: basically it is not in a spammers best interest for people to be able to remove their addresses and just going to their site/emailing them just confirms that somebody read their email. And anyway, the &#8220;default&#8221; Hotmail account size is just 2Mb: imagine if everybody sent a removal request to that account-it&#8217;ll soon fill up wouldn&#8217;t it? I doubt that this email address actually ever existed, and if it did Hotmail (again innocent &#8220;bystanders&#8221; just like Yahoo!) have probably shut it down by now anyway.</p>
<blockquote><p>&lt;!&#8211;START Zcounter.com COUNTER CODE, DO NOT MODIFY&#8211;&gt;[snipped]<br />
&lt;a<br />
href=&#8221;http://www.zcounter.com/c2/statsviewer.cgi?page=barrycooper&#8221;&gt;&lt;img<br />
src=&#8221;http://www.zcounter.com/c2/stats.cgi?page=barrycooper&#8221; height=&#8221;15&#8243;<br />
width=&#8221;15&#8243; border=0 alt=&#8221;View Stats&#8221;&gt;&lt;/a&amp;gt</p></blockquote>
<p>This is crafter- using a third party as a &#8216;web-bug&#8217; host. Basically, every time this email is opened using a &#8220;HTML-aware&#8221; email client (such as Microsoft Outlook) it will try and fetch an image from Zcounter&#8217;s server (which appears to be dead at this moment in time) and it will &#8220;count&#8221; that the person has read the email. Therefore the spammer can work out some statistics such as &#8216;number of emails sent, number of emails read, number of responses&#8217;.</p>
<p>If they were crafter and could find a reliable webhost that was willing to become known as hosting spamvertised websites, then they could have set up a similar tracking system and find out exactly who read the email&#8230;.</p>
<p>And there concludes &#8220;An Anatomy of a Spam&#8221;. Next time on &#8220;The Online School of Hard Knocks &#8211; Department Common Sense&#8221;, I will be telling you how it is a bad idea to get reaallllyyy drunk&#8230;.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.rac.me.uk/2002/11/26/spam-an-anatomy-of-a-spam/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Spam: SpamCop Statistics</title>
		<link>http://blog.rac.me.uk/2002/11/24/spam-spamcop-statistics/</link>
		<comments>http://blog.rac.me.uk/2002/11/24/spam-spamcop-statistics/#comments</comments>
		<pubDate>Sun, 24 Nov 2002 15:16:42 +0000</pubDate>
		<dc:creator>Richy C.</dc:creator>
				<category><![CDATA[Net: Spam]]></category>

		<guid isPermaLink="false">http://blog.rac.me.uk/?p=72</guid>
		<description><![CDATA[Well, it&#8217;s now been a week since I started using SpamCop in a &#8216;paid for sense&#8217; to report unsolicited email that I&#8217;ve been receiving, and the statistics are quite scary. In a recent deluge of spam, I got 245 messages &#8211; of those I report only 16 of them to SpamCop (6.53%): and that&#8217;s just [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://spamcop.net/"><img alt="[Spamcop]" src="http://blog.rac.me.uk/photos/spamcop.gif" width="89" height="81" border="0" align="left" /></a>Well, it&#8217;s now been <a href="http://blog.rac.me.uk/archives/000057.html">a week</a> since I started using <a href="http://spamcop.net/">SpamCop</a> in a &#8216;paid for sense&#8217; to report unsolicited email that I&#8217;ve been receiving, and the statistics are quite scary. In a recent deluge of spam, I got 245 messages &#8211; of those I report only 16 of them to SpamCop (6.53%): and that&#8217;s just about average for me. Exactly a week ago (give or take a few minutes), I &#8220;purchased&#8221; 25Mb of SpamCop usage, I&#8217;ve now only got 22.6Mb left. That means my &#8220;average usage rate&#8221; is 3.93 bytes/per second or 10.2Mb a month or 123.9Mb a year.</p>
<p>Now, remember that I only report an average of 6% to SpamCop, that means that I get around 65.5bytes of spam per second, 3.83Kb per minute, 230Kb of spam per hour, and 5.53 Mb of spam per day. That&#8217;s a lot of crap in my mailbox <img src='http://blog.rac.me.uk/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />  Now to escalate that up to a yearly figure and I receive around 2.02Gb of spam! Sheesh! That&#8217;s over 3 CDs full of spam. Take in to account all the bandwidth and storage fees &#8211; PLUS my time spent sorting through it all (you could also include the SpamCop reporting fee) and it does add up: so much for the spammers excuse that &#8220;you shouldn&#8217;t complain as it doesn&#8217;t cost you anything&#8221;&#8230;.</p>
<p>Oh yes, and because of an <a href="http://slashdot.org/article.pl?sid=02/11/21/028220&amp;mode=nested&amp;tid=111">article on</a> Slashdot, I&#8217;m now CC&#8217;ing most of the reports I send to SpamCop to <a href="http://www.spamarchive.org/">SpamArchive</a>. I don&#8217;t know what they are planning on doing with all the spam that gets sent to <a href="mailto:submit@spamarchive.org">submit@spamarchive.org</a>, but at least they&#8217;re getting lots of it now <img src='http://blog.rac.me.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Now, if I could only get my hands on people like <a href="http://www.freep.com/money/tech/mwend22_20021122.htm" class="broken_link">Alan Ralsky</a> and <a href="http://online.wsj.com/article_email/0,,SB1037138679220447148,00.html">Laura Betterly</a> (two big time spammers) *grr*. If any spammers (or, if you must, &#8220;senders of unsolicited commercial or bulk email&#8221;) are reading this: I DO NOT buy ANYTHING that has been advertised via these methods and I DO report it to your ISPs. Please stop wasting my time, your time and your ISPs&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.rac.me.uk/2002/11/24/spam-spamcop-statistics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spam: Nigerian Jerry Duruibe: Day 6</title>
		<link>http://blog.rac.me.uk/2002/11/23/spam-nigerian-jerry-duruibe-day-6/</link>
		<comments>http://blog.rac.me.uk/2002/11/23/spam-nigerian-jerry-duruibe-day-6/#comments</comments>
		<pubDate>Sat, 23 Nov 2002 18:31:41 +0000</pubDate>
		<dc:creator>Richy C.</dc:creator>
				<category><![CDATA[Net: Spam]]></category>

		<guid isPermaLink="false">http://blog.rac.me.uk/?p=67</guid>
		<description><![CDATA[I&#8217;ve been a bit busy the past few days, but I&#8217;ll bring you up to speed with what&#8217;s happening with Jerry, and how helpful he&#8217;s been (he&#8217;s sent some documents &#8211; a copy of &#8216;Albert Pilchards&#8217; will, his death certificate and a certificate of deposit) so let&#8217;s continue the tale of the Nigerian spammer who [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.rac.me.uk/photos/jerry/CERTDEP.JPG"><img alt="CERTDEP.JPG" src="http://blog.rac.me.uk/photos/jerry/CERTDEP-thumb.JPG" width="88" height="120" border="0" align="left" /></a>I&#8217;ve been a bit busy the past few days, but I&#8217;ll bring you up to speed with what&#8217;s happening with <a href="http://blog.rac.me.uk/archives/000052.html">Jerry</a>, and how helpful he&#8217;s been (he&#8217;s sent some documents &#8211; a copy of &#8216;Albert Pilchards&#8217; will, his death certificate and a certificate of deposit) so let&#8217;s continue the tale of the Nigerian spammer who claims I could inherit a fortune (for background information see <a href="http://blog.rac.me.uk/archives/000052.html">day 5</a>, <a href="http://blog.rac.me.uk/archives/000047.html">day 4</a>, <a href="http://blog.rac.me.uk/archives/000046.html">day 3</a>, <a href="http://blog.rac.me.uk/archives/000034.html">day 2</a> or go right back to the very start with <a href="http://blog.rac.me.uk/archives/000030.html">day 1</a>).</p>
<p>Oh, and yes, transcripts of all the documents he sent (all were JPG format) have been made &#8211; ideal if you are received the same files from the spammer and were doing a search to find some &#8220;background data&#8221;&#8230;.<br />
<span id="more-67"></span><br />
My emails to Jerry at jerry.duruibe@email.ro seem to be hitting delays while being delivered by <a href="http://lc2.law5.hotmail.passport.com/cgi-bin/login" class="broken_link">HotMail</a> to Jerry&#8217;s mail drop on <a href="http://www.email.ro/eindex.shtml" class="broken_link">Astral FreeMail</a>, but after the delays he&#8217;s managed to get back to me with some &#8220;helpful&#8221; details.</p>
<p>First of all, I have a response from my <a href="http://blog.rac.me.uk/archives/000052.html#jerry_day5_mechanical_failure">day 5</a> message claiming that I my plane to New Zealand had been delayed by &#8220;mechanical failure&#8221;:</p>
<blockquote><p>From : Jerry Duruibe<br />
Subject : Pls Call Soonest<br />
Date : Tue, 19 Nov 2002 01:53:50 +0200<br />
MIME-Version: 1.0<br />
X-Originating-IP: [216.139.170.12]<br />
Received: from zerg.codec.ro ([193.230.240.30]) by mc1-f32.law16.hotmail.com with Microsoft SMTPSVC(5.0.2195.5600); Mon, 18 Nov 2002 15:52:15 -0800<br />
Received: (from httpd@localhost)by zerg.codec.ro (8.11.6/8.11.4) id gAINro420272;Tue, 19 Nov 2002 01:53:50 +0200<br />
Message-Id:<br />
X-Mailer: freemail 0.9.8<br />
X-User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt; YComp 5.0.2.6)<br />
X-Organization: ASTRAL FreeMail<br />
Return-Path: jerry.duruibe@email.ro<br />
X-OriginalArrivalTime: 18 Nov 2002 23:52:15.0353 (UTC) FILETIME=[85747E90:01C28F5D]</p>
<p>Dear Mr. Pilchard,</p>
<p>How are you? I believe by now you must have gotten my voice message. Please<br />
endeavour to call me as soon as you are back from your trip and amny thanks for<br />
your sincere mail.</p>
<p>I will fax over the documents to you as soon as I get to my office tomorrow,<br />
the court held my whole day. Have you heard from the security company? Please<br />
you must not respond them without reaching me first okay. I want us to work<br />
closely in this pursuit.</p>
<p>Have a nice business time over. Anticipating your call.</p>
<p>Regards,</p>
<p>Jerry Duruibe ESQ.</p>
<p>&gt; Dear Jerry,<br />
&gt;<br />
&gt; Luckily I&#8217;ve been informed that my plane&#8217;s been delayed by 12 hours due to<br />
[snipped]</p></blockquote>
<p>And then a little later on, true to his word, his responds to my &#8220;<a href="http://blog.rac.me.uk/archives/000052.html#jerry_day5_replsconfirmsafety">Re: Pls Confirm Safety</a>&#8221; email also sent on <a href="http://blog.rac.me.uk/archives/000052.html">day 5</a> (when I landed at &#8220;Pudnuowg Nibru&#8221; in New Zealand):</p>
<blockquote><p><a name="jerry_day6_documents">From : Jerry Duruibe</a><br />
Subject : Documents<br />
Date : Tue, 19 Nov 2002 20:28:09 +0200<br />
MIME-Version: 1.0<br />
X-Originating-IP: [217.117.9.86]<br />
Received: from zerg.codec.ro ([193.230.240.30]) by mc8-f25.law1.hotmail.com with Microsoft SMTPSVC(5.0.2195.5600); Tue, 19 Nov 2002 10:27:25 -0800<br />
Received: (from httpd@localhost)by zerg.codec.ro (8.11.6/8.11.4) id gAJISBC28451;Tue, 19 Nov 2002 20:28:11 +0200<br />
Message-Id:<br />
X-Mailer: freemail 0.9.8<br />
X-User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)<br />
X-Organization: ASTRAL FreeMail<br />
Return-Path: jerry.duruibe@email.ro<br />
X-OriginalArrivalTime: 19 Nov 2002 18:27:25.0835 (UTC) FILETIME=[4F35CDB0:01C28FF9]</p>
<p>Hello Rich,</p>
<p>I have been trying to send these attached files for the past five hours but the<br />
Internet connection got so bad that it could come. Please find the attched<br />
documents and please call me at any time to confirm the receipt.</p>
<p>I hope your day was good, I wish you best of the trip. When do feel you can be<br />
back?</p>
<p>Expecting your response.</p>
<p>Regards,</p>
<p>Jerry.</p>
<p>&gt; Hi Jerry,<br />
&gt;<br />
&gt; I haven&#8217;t long landed in Pudnuowg Nibru in New Zealand &#8211; why they have to<br />
[snipped]</p></blockquote>
<p>I don&#8217;t know exactly what went wrong on the email transmission, but the attached files he sent were slightly mangled and I had to download the raw email from HotMail and then use &#8220;<a href="http://www.pcworld.com/downloads/file_description/0,fid,1951,00.asp">munpack</a>&#8221; to get hold of them. But here they are: <a href="#jerry_day6_certdep">certdep</a> (certificate of deposit), <a href="#jerry_day6_deathcer">deathcer</a> (death certificate) and the will <a href="#jerry_day6_will1">will1</a> and <a href="#jerry_day6_will2">will2</a>.</p>
<p><a name="jerry_day6_navigation">Stay tuned for what happened next&#8230;</a><br />
[<a href="http://blog.rac.me.uk/archives/000052.html">Back to day 5</a>]</p>
<hr noshade="noshade" width="50%">
Documents sent by &#8220;Jerry Duruibe&#8221; on <a href="#jerry_day6_documents">day 6</a>:</p>
<ul>
<li><a href="http://blog.rac.me.uk/photos/jerry/CERTDEP.JPG" name="jerry_day6_certdep">certdep.jpg</a> 80Kb (Certificate of Deposit)<br />
<a href="http://blog.rac.me.uk/photos/jerry/CERTDEP.JPG"><img alt="CERTDEP.JPG" src="http://blog.rac.me.uk/photos/jerry/CERTDEP-thumb.JPG" width="88" height="120" border="0" align="left" /></a>As you can see, it does look quite &#8220;official&#8221; and real looking doesn&#8217;t it. Well, I&#8217;ll hate the shatter any illusions, but as we know, there is no one could &#8220;Richard Pilchard&#8221; (as he&#8217;s an imaginary person created by me) and &#8220;Albert Doto Pilchard&#8221; on the certificate is a faked name (see <a href="http://blog.rac.me.uk/archives/000030.html">day 1</a> for details). If &#8220;City Securities&#8221; did actually print this out and scan it, it must have cost them a whole 12p &#8211; after all, since these are scanned copies we can&#8217;t tell if the &#8220;microprint&#8221; on the certificate is actually real or if it&#8217;s just been printed on the paper after being reduced in something like Photoshop. And anyway, once it gets to the point where &#8220;City Securities/Jerry&#8221; have to start providing &#8220;evidence&#8221;, they are quite sure they&#8217;ve got a victim and are going to get quite a bit of money from them.</p>
<p>I&#8217;ve transcribed the document as well as I can here:</p>
<blockquote><p>CITY SECURITIES LIMITED<br />
Certificate of Deposit</p>
<p>City Securities Limited<br />
CSL00177813521/97<br />
XXBCSL0093411XB<br />
CODES XB00117D0Q93<br />
CBZ1400XXXB2</p>
<p>No: CSLVD/007342219</p>
<p>Name: ALBERT DOTO PILCHARD<br />
Address: NO. 48 THOMAS AKINJIDE STREET VICTORIA ISLAND LAGOS<br />
Telephone: 01 613663<br />
Fax: 01 613663</p>
<p>This is to certify that the above firm/person(s) have deposited a consignment tagged B-GA 19391/97<br />
Declared as CASH DEPOSIT (MONEY) on this date mentioned 15TH OCTOBER 1997</p>
<p>[signed] Depositor [signed] Witness [signed] For: City Securities Limited<br />
[ ] Thumbprint</p>
<p>* This deposit is made and acceptable under the strict terms and conditions stipulated in the deposit agreement</p></blockquote>
</li>
<li><a href="http://blog.rac.me.uk/photos/jerry/DEATHCER.JPG" name="jerry_day6_deathcer">deathcer.jpg</a> 45.6Kb (Death Certificate) <br />
<a href="http://blog.rac.me.uk/photos/jerry/DEATHCER.JPG"><img alt="DEATHCER.JPG" src="http://blog.rac.me.uk/photos/jerry/DEATHCER-thumb.JPG" width="92" height="120" border="0" align="left" /></a>I&#8217;ve got no idea what a Nigerian death certificate looks like, but I&#8217;m sure it looks better than this! Again, it does look officialish &#8211; complete with a &#8220;Sagbama Local Government Council Death Registration Dept&#8221; stamp on the bottom of it. But surely such an &#8216;official&#8217; document (especially since it&#8217;s stamped &#8216;Original&#8217;) would have some sort of watermarking to make the word &#8220;Copy&#8221; or similar show up (usually in red) if it is copied &#8211; and surely the death certificate should of a &#8216;date and place of birth&#8217; on it as well&#8230; Anyway, here&#8217;s the transcript:</p>
<blockquote><p>Form D.2<br />
ORIGINAL</p>
<p>FEDERAL REPUBLIC OF NIGERIA<br />
SAGBAMA LOCAL GOVERNMENT COUNCIL<br />
SHOMOLUE, RIVER STATE-NIGERIA<br />
Birth/Death Registry<br />
DEATH CERTIFICATE</p>
<p>Issued under the Births and Deaths Etc. (Compulsory Registration) Decree 69 of 1992</p>
<p>Registration Centre SAGBAMA L.G.A. COUNCIL    Certificate Number D NO: 648936<br />
Town/Village SHOMOLUG<br />
L.G.A. SAGBAMA L.G.A.           Volume SLG018 YEAR 1998 ENTRY NO DR-969246<br />
State RIVERS STATE</p>
<p>This is to certify that the death, details of which are recorded herein has been registered on<br />
28th Day        APRIL Month     1998 Year<br />
at this Registration Centre</p>
<p>1. Full Name: (surname First) (in block letters) PILCHARD D. ALBERT<br />
2. Sex: Male (M)<br />
3. Date Of Death 21st Day APRIL Month 1998 Year<br />
4. Age at Death: 57Yrs<br />
5. Place of Death: SAGBAMA L.G.A<br />
6. Full Address of Usual Place of Residence of Deceased: No 48 THOMAS<br />
AKINJIDK STREET VICTORIA-ISLAND LAGOS<br />
Place of Issue: SAGBAMA L.G.A. COUNCIL<br />
Name of Registrar: Rufus Okorie<br />
Date: 28/04/1998<br />
Signature of Registrar: [signed - dated 28-04-98]<br />
[stamp: SAGBAMA LOCAL GOVERNMENT COUNCIL DEATH REGISTRATION DEPT]
</p></blockquote>
</li>
<li><a href="http://blog.rac.me.uk/photos/jerry/WILL1.1.jpg" name="jerry_day6_will1">will1.1.jpg</a> 68.1Kb and <a href="http://blog.rac.me.uk/photos/jerry/WILL2.JPG" name="jerry_day6_will2">56.5Kb</a><br />
<a href="http://blog.rac.me.uk/photos/jerry/WILL1.1.jpg"><img alt="WILL1.1.jpg" src="http://blog.rac.me.uk/photos/jerry/WILL1.1-thumb.jpg" width="85" height="120" border="0"></a>And a copy of Albert Pilchard&#8217;s Will:</p>
<blockquote><p>THE WILL AND TESTAMENT OF MR ALBERT PILCHARD<br />
I Mr. ALBERT PILCHARD of No 48 Thomas Akinjide Street, Victoria Island, and<br />
Lagos State hereby revoke all former testamentary disposition made by me and<br />
declare this to be my last will.</p>
<p>(1) I appoint Mr. JERRY DURUIBE ESQ. OF OLISA AGBAKOBA &amp;<br />
ASSOCIATES of 21 Ahmed Onibudo Crescent Victoria Island, Lagos State<br />
and Mr J.C. Okereke of 41 Ryle street Ikeja Lagos state (hereinafter called my<br />
trustees which expressions shall include the trustees for the time being here of]<br />
to be the executors and trustees of this my will</p>
<p>(2) I give to my trustees all my real and personal property whatsoever and<br />
wheresover [including all entailed property of which I have power to expose<br />
by will] viz<br />
a) A deposit with city securities limited valued at $7,800,000 USD.<br />
b) One duplex unit situated at no 13 Ogundele Street Ikeja Lagos.<br />
c) One twin duplex at no 16 Whyte Street Port Harcourt Rivers state.<br />
d) Stocks with Mobil Nigeria Unlimited, Union Dicon Salt Limited, UAC<br />
PLC and First Bank plc. Valued at $180,000USD<br />
e) A deposit with Global Diplomatic Services &#8211; UK valued at &pound;380,000.</p>
<p>3) My trustees shall hold the said property upon trust to sell the same with power<br />
in the absolute discretion to postpone such sale for so long as they shall think<br />
fit without being liable for loss.</p>
<p>4) My trustees shall hold the proceeds of sale on all unsold property and my<br />
ready money upon the following trusts.<br />
a) To pay my debts, funeral and testamentary expenses.<br />
b) Subject there to my wife VIRGINIA PILCHARD if she survives me one<br />
month after my death absolutely<br />
c) Subject there to my two children GERALD PILCHARD and ADLINE<br />
PILCHARD if they survive me one month after my death absolutely.<br />
d) Provided that if my two children already mentioned shall die in my life<br />
time or after my death under the age of eighteen years and unmarried<br />
then the said proceeds of sale and all unsold property shall be held for<br />
any person or group of persons my trustee deems appropriate absolutely</p></blockquote>
<p><a href="http://blog.rac.me.uk/photos/jerry/WILL2.JPG"><img alt="WILL2.JPG" src="http://blog.rac.me.uk/photos/jerry/WILL2-thumb.JPG" width="85" height="120" border="0"></a></p>
<blockquote><p>5) Any trustee being a solicitor or other person engaged in any profession or business<br />
may be so employed or act and shall be entitled to charge and be paid all professional<br />
or other charges for all business or acts done by him in connection with the trust here<br />
of including acts which a trustee could have done personally.</p>
<p>IN WITNESS whereof I have hereunto set my hand this 13th day of January 1998<br />
[signature] ALBERT PILCHARD</p>
<p>SIGNED by the above- mentioned<br />
ALBERT PILCHARD as his last will in<br />
the presence of us present at the<br />
same time who at his request in<br />
his presence and in the presence<br />
of each other have subscribed<br />
our names as witness.</p>
<p>IN THE PRESENCE of<br />
NAME: J.C.OKEREKE<br />
SIGNATURE: [signature]<br />
DATE: 13th January 1998<br />
ADDRESS: NO 41 Ryle Street Ikeja Lagos State.<br />
OCCUPATION: Stock broker</p>
<p>IN THE PRESENCE of<br />
NAME: Mr.OKEY IKE<br />
SIGNATURE: [signature]<br />
DATE: 13th January 1998<br />
ADDRESS: NO 19 Boyle Street Apapa Lagos State<br />
OCCUPTION: Accountant.</p>
<p>PREPARED BY: Mr. JERRY DURUIBE OF OLISA AGBAKOBA &amp;<br />
ASSOCIATES (Legal Practitioner) of Anthony Village Lagos state Nigeria.</p></blockquote>
</li>
</ul>
<p><a href="#jerry_day6_navigation">Return to navigation</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.rac.me.uk/2002/11/23/spam-nigerian-jerry-duruibe-day-6/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

