Jodohost Security Breach: Receiving SPAM sent to HIDDEN email addresses

Jodohost Security Breach: Receiving SPAM sent to HIDDEN forward-only email addresses

As of 6:30-7:30 PM MST today, 02/24/07, I’ve been receiving SPAM to multiple hidden forwarding email accounts, created specifically for individual websites.

IE: Signing up on Fedex.com, I created: [email protected]… signing up on WellsFargo.com, I created: [email protected]… signing up for something on Microsoft.com, I created [email protected], and on and on… over 100 email addresses for individual websites… all forwarding to my main email account ([email protected] - that I don’t want to directly get spammed). By creating these forwarding accounts, I am able to track which sites are spamming me and delete the email forwarding account associated with that site.

BUT… as of today I have been spammed directly to these specific email addresses… used solely on legitimate websites… some of the SPAM emails contain MORE THAN ONE OF MY ADDRESSES as either the Recipient or CC recipient; these are completely unrelated forwarding accounts (IE: [email protected] & [email protected]). How is this possible without a breach in the Jodohost/Hsphere security? These spammers do not have access to these email accounts, nor have I ever sent a single email using any one of these forwarding accounts. The only way the spammers could have gotten access to these forwarding accounts is by gaining access to Hsphere.

Here’s a list of the accounts that have gotten spammed so far:

[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]

BTW: These forwarding accounts forward to a Yahoo.com email account which has a password consisting of letters, numbers and symbols. I have never given the password out nor have I accessed my email account using a public computer. Further, I change my password frequently. I am ruling out the possibility of a spammer breaking into my email account and harvesting these email addresses from my received emails. I am also ruling out the possibility of Yahoo Email getting hacked. Lastly, I don’t think a spammer gained access to my specific Hsphere login/password either.

Please look into this immediately.

Best regards,

/WebDeveloper

Re: Jodohost Security Breach: Receiving SPAM sent to HIDDEN forward-only email addresses

Spammers never need access to your account or mailboxes to enlist them. They have developed some specialised techniques to harvest them. A few of them are listed here:
How do spammers harvest email addresses ?
Why Am I Getting All This Spam?

I’ve sent you details of one possible way and how to prove the situation.
That being said, the new antispam gateway should help in some ways.
But mostly it is to the user, something you seem to have taken care of already.

Tanmaya,

Thank you for looking into this situation and offering possible answers. I have never posted any of these email addresses in a public location nor have I ever sent email from them. I have used them only on the designated website which I know, based on their privacy policy, does not sell email addresses or spam (IE: Palm, Microsoft, Dell, etc.).

I think that your “dictionary attack” method may be what’s responsible. I don’t understand how creating a catch-all will solve the situation. Can you please explain? What should I do with these forwarding addresses that have been spammed, should I delete them?

Thank you for your assistance.

/WebDeveloper

At this moment you will be no better by deleting them, but yes forwards to Yahoo!(offtopic, but i thought i should mention) aren’t good as they have started to rate limit per IP.
Also, i’m not asking to use catch-all as they will just give you more spam. It will be good if you can wait for us to do the new anti-spam for this mailserver.

what does this mean exactly?

It means yahoo! mail servers only allow a certain amount of mails from each IP per hour, day, etc. They have not publicly said what figure this is, so it is not readily available for us to say “150 mail per ip per hour”, as we don’t know the figure.

One of my client complained about receiving mail in a non public account. i checked it was catch all. I made another catch all account for him, he still gets mail of that account. hows this possible?

because it is a catchall?