Slashdot Mirror


Scamming Spammer Hooks the Wrong Person

CrypticSpawn writes "Read on SecurityFocus, a 55 year old woman spammed an FBI computer crime agent. She got caught mailing off a credit card scam to AOL users." Her scam targeted AOL users with messages saying their credit cards were refused during the last billing cycle, and linked to a false billing center page which demanded private information.

408 comments

  1. How gullable can people be? by Quasar1999 · · Score: 4, Interesting

    Really... We have just charged your credit card for 19.95... if you want to cancel the transaction, enter your card number, full name, and expiry date below...

    With the same logic, phone someone up, and tell them that if they don't want to be 0wN3d, they should disable their firewall, and tell you their IP address...

    The darwin award exists for those who kill them selves in stupid ways... we need to invent an award for idiots that fall for obvious scams like this.

    --

    ---
    Programming is like sex... Make one mistake and support it the rest of your life.
    1. Re:How gullable can people be? by YanceyAI · · Score: 2, Informative

      Actually, If you read the article, it says that they posed as AOL and said the card had been charge for a legitimate service, but the card was not accepted and they need to submit another card for processing. Seems to be a possible scenario for the average user who has online subscriptions that they normally pay online.

      --
      Can I bum a sig?
    2. Re:How gullable can people be? by skinfitz · · Score: 4, Funny

      The darwin award exists for those who kill them selves in stupid ways... we need to invent an award for idiots that fall for obvious scams like this.

      There is - it's called "Manager".

    3. Re:How gullable can people be? by Quasar1999 · · Score: 2, Insightful

      I was thinking of a different scam I ran across... This one is still pretty transparent though, considering that AOL (and every other ISP I know) clearly state time and time again that they will never ask you for your password, credit card info, hell, even your name in an email.

      --

      ---
      Programming is like sex... Make one mistake and support it the rest of your life.
    4. Re:How gullable can people be? by YanceyAI · · Score: 1, Informative
      I did say "average" user.

      :)

      --
      Can I bum a sig?
    5. Re:How gullable can people be? by Qzukk · · Score: 1, Interesting

      Amusingly enough my boss's wife (an OB doctor) got an email saying that her credit card was charged to cover up her child pornography web site and asked for a credit card number and expiration date. Given that her clinic's website doesn't have any child porn (not even the stupid "baby in the bathtub" kind that only scaremongers and D.A.s call child porn - every baby picture on the site was fully clothed), and the fact that it was asking for her CC# even though it claimed she was already charged, she showed it to me for laughs then deleted it.

      --
      If I have been able to see further than others, it is because I bought a pair of binoculars.
    6. Re:How gullable can people be? by Anonymous Coward · · Score: 3, Insightful

      Part of the problem is that the people who DO know about the workings of these sorts of things don't educate others on the matter.

      Think about it, how many /.ers are frustrated with friends and family not understanding why they should patch regularly? Now, think of how many /.ers are completely ineffective at presenting a simple argument on an annonymous message board.

      The fact of the matter is, most of us geeks just aren't good communicators and teachers when it comes to people outside of the community. We assume that the person we're educating has a modicum of understanding from the get go. What we need are more geeks who can communicate and teach effectively to the entire populace and help get the word out about such things.

      Hell, if /. managed a series of funny and educational public service announcements, I'd be in seventh heaven.

    7. Re:How gullable can people be? by saden1 · · Score: 1

      Grandma has to pay here medical bills some how you know. I knew the older folks were desperate but not this desperate. I must say though I impressed by how sophisticated grandma and grandpa have become.

      --

      -----
      One is born into aristocracy, but mediocrity can only be achieved through hard work.
    8. Re:How gullable can people be? by silentbozo · · Score: 2, Interesting

      Grandma nothing. This woman is a professional scam artist and thief. Phishing is just a new way for her to scam targets en masse. I'll bet you she was kiting checks long before most of us were born...

    9. Re:How gullable can people be? by baywulf · · Score: 1

      These criminals go to great lengths to trick people using cleverly parsed URLs, links back to the original website, etc. They also will have a plausable reason for entering the information. In one case, it was for ebay which I haven't used in a year. The email said that I haven't used the account in more than a year and they wanted to reregister and confirm my information. I almost bought it hook line and sinker until I realized that they asked for a lot of personal information such as back account and credit card number details all at one. I think this is were these guys get discovered... they get too greedy in trying to get your personal information and blow their cover.

    10. Re:How gullable can people be? by kfg · · Score: 2, Funny

      Oh yeah? Well you,. . . ummmmmmmmmm, what I mean to say is. . .

      NAZI!!!!!

      Yeah, I think that's it.

      Oh, wait. I can't talk now, there's an important message on the TV just for me and they're waving something shiney that goes "Ping!" It's not even $100, just 79 payments of $19.95.

      Wow! I can afford $19.95

      Gotta go.

      KFG

    11. Re:How gullable can people be? by Anonymous Coward · · Score: 1, Insightful

      Well, the churches are fillied with millions of gullible people...

    12. Re:How gullable can people be? by DrDebug · · Score: 1

      The problem with your premise is that the people KNOW the difference between someone spouting crap and someone who knows what they are talking about. While /. generally has a lower noise to signal ratio, there are still those out there that don't know the difference.

      Gullible? Yeah, everyone is, at least once.

      Isn't that why these 'phishers' exist?

    13. Re:How gullable can people be? by HungWeiLo · · Score: 2, Interesting

      Actually, what many people don't know is that many businesses don't actually check the expiration date. I've worked with banks before and have discovered that a number of them do not validate the expiration date on credit cards. Blame the incompetent IT monkeys who slinged that code together.

      --
      There are a huge number of yeast infections in this county. Probably because we're downriver from the bread factory.
    14. Re:How gullable can people be? by cmacb · · Score: 1

      "The darwin award exists for those who kill them selves in stupid ways... we need to invent an award for idiots that fall for obvious scams like this."

      Funny you should say that, my first reaction to this was that we should invent some new punishments for these scum-bags that at minimum involves removal of their reproductive organs.

      Both the victims and the perpetrators of such crimes would seem to be a threat to our species.

    15. Re:How gullable can people be? by GlassUser · · Score: 1

      I used to try. I got tired of hearing excuses like "that only happens in the movies", "I can always dispute the charges", and "Norton will protect me".

    16. Re:How gullable can people be? by NanoGator · · Score: 1

      "The fact of the matter is, most of us geeks just aren't good communicators and teachers when it comes to people outside of the community. We assume that the person we're educating has a modicum of understanding from the get go."

      That lack of understanding comes from lack of interest in understanding it. Computers are not exciting toys for everybody. In some ways, they are downright abstract. It's sort of like how you feel when your girlfriend babbles about Big Brother.

      --
      "Derp de derp."
    17. Re:How gullable can people be? by the+unbeliever · · Score: 1
      Blame the incompetent IT monkeys who slinged that code together.


      Er, no. Blame the incompetent credit card companies who don't make it mandatory to validate expiration dates in a transaction.

    18. Re:How gullable can people be? by halr9000 · · Score: 1

      I just got a phone call three days ago from a scammer pretending to be my credit card company. He said we were 6 days late on our bill, "just give me your checking account number and I'll take care of things".

      What kind of retard do you think I am? But I bet people fall for it...

    19. Re:How gullable can people be? by Anonymous Coward · · Score: 0

      Computers are not exciting toys for everybody. In some ways, they are downright abstract. It's sort of like how you feel when your girlfriend babbles about Big Brother.

      I was thrilled when my girlfriend started talking about Big Brother. Another common interest!!! But she seemed all confused when i explained my theory about the government plan to infiltrate groups of punk 'rebels' and other malcontents by placing miniature transmitting microphones and cyanide dispensors in tongue studs and labrets. Think about it, it's ultimate speach control. The outside has the microphone so you hear everything they say. And if they start talking smack about the government, the other side has the remote controlled poison dispensor - push one button and you sne d asignal to release the poison. The best part is, you don't have to put any effort into planting it on them. Without even realizing it, they pay you to put it in!! It's brilliant.
      Yeah, that relationship didn't last long. I might have been better off trying to explain computer security to her.

    20. Re:How gullable can people be? by instarx · · Score: 1

      All you slashdotters who scream "Darwin Aawrd" whenever someone get scammed have to remember that you have the advantage in knowing that it was a scam. Seems obvious to you because it IS obvious to you - you were told.

      Professional scammers are often extremely smart, would make good psychologists, appear very honest and trustworthy, and are very, very good at separating people and their money. Scammers will do things like record office noise to play in the background to make their call sound like it is coming from an official call-center. They don't say "Hey, yuk,yuk will you give me your heh,heh credit card number? I'm from uh...oh yeah...the credit card company".

    21. Re:How gullable can people be? by Anonymous Coward · · Score: 0

      Seems obvious to you because it IS obvious to you - you were told.

      Yeah because whenever I get an email out of the blue asking for my credit card details, I always reply right away. How silly I feel when I'm finally told it's a scam!

      Oh wait, that never fucking happens. Probably because I don't have the IQ of a warm glass of water.

    22. Re:How gullable can people be? by Anonymous Coward · · Score: 0

      People don't change just because they get old.

    23. Re:How gullable can people be? by rootyard · · Score: 1
      "The darwin award exists for those who kill them selves in stupid ways... we need to invent an award for idiots that fall for obvious scams like this."

      It is entirely the fault of the person who was scammed and not the person who sent the email. The spammer is just exercising his/her rights to part money from the foolish. When is western society going to start seeing things correctly? Someone or some repository should be commissioned to annually award a "Darwin" award to people who act stupidly. The scammer should be glorified. What the hell is the matter with everyone? Is it only Quasar1999 and myself who see things as they are?

  2. Spammers and law enforcement by ergo98 · · Score: 4, Insightful

    I suspect that a vast majority of spams hit a large number of law enforcement inboxes - it isn't like spammers are selectively making hand-crafted to lists. Of the spams I get (of which there has been a marked increase in the past month), a good percentage are illegal or gray-legal pennystock pump and dumps, PayPal imitators attempting to get your information, or our good Nigerian friends looking for some assistance in rescuing their money.

    1. Re:Spammers and law enforcement by Detritus · · Score: 1

      When I had a .gov email address, I almost never received spam, and it wasn't because my email address wasn't available to the spammers, or that the mail server was filtering out spam. I suspect that even the stupider spammers realize that spamming .gov domains is a bad idea.

      --
      Mea navis aericumbens anguillis abundat
    2. Re:Spammers and law enforcement by Anonymous Coward · · Score: 1

      And the only way that anything ever gets done about it is when an FBI agent gets spammed. Suddenly they take a personal interest. Nevermind the crap that millions of us have been putting up with for years.

      Can you imagine calling up your local FBI office with a spam complaint? "Hi, I received a spam phishing for my credit card number. It's the tenth one over the past year, so it's obviously an ongoing and successful operation. Would you please check it out?"

      Ha! They wouldn't give you or me the time of day.

      How about "Hi, my DNS servers, along with thousands of others, are being used by the perpetrator of a large scale DDOS attack against 66.98.152.55 and a few other IPs in ev1.net space. It's been going on for months now. Would you please identify the perpetrator and prosecute them?"

      Yeah, right. The only way they'd take any interest whatsoever would be if THEIR DNS servers were being abused.

    3. Re:Spammers and law enforcement by lgftsa · · Score: 1

      .gov.au does not enjoy a similar reduction of spam. I'm happy to say that our users get a many and varied selection of crap every day.

  3. FBI uses AOL by vspazv · · Score: 5, Funny

    I can't be the only one that finds it disturbing that the FBI uses AOL.

    1. Re:FBI uses AOL by Anonymous Coward · · Score: 0

      Did you ACTUALLY read the article? Off-duty FBI agent... Does that mean that she mailed the person at their workplace? Probably not... Think a little before you press "Submit"

    2. Re:FBI uses AOL by Anonymous Coward · · Score: 0

      well...

      one thing going for AOL...trying to figure out source IPs and geographical locations is a real bitch.

      tracking down some recent bogus emails was pretty damn hard when the senders were on AOL.

      the other three? no prob.

      road runner. texas. houston.

    3. Re:FBI uses AOL by yintercept · · Score: 5, Funny
      I can't be the only one that finds it disturbing that the FBI uses AOL.
      You mean you missed the Time/AOL/FBI merger?
    4. Re:FBI uses AOL by Anonymous Coward · · Score: 0

      Did you ACTUALLY read what the poster said?

      I too find it distrubing that FBI employees AOL using agents

    5. Re:FBI uses AOL by seriv · · Score: 3, Funny

      I am surprised the fbi is able to function in the computer world at all. Their internal search was really bad for so long, and the fact that an FBI agent uses AOL comes as no surprise.
      -Seriv

    6. Re:FBI uses AOL by emilng · · Score: 1

      The first line of the article:
      An Ohio woman whose credit card fraud schemes began to unravel when she unwittingly spammed an off-duty FBI computer crime agent pleaded guilty to a federal conspiracy charge Tuesday, and potentially faces years in prison.

      off-duty FBI computer crime agent

    7. Re:FBI uses AOL by MosesJones · · Score: 4, Funny

      They've given up on that name...

      Now they are going for

      "Investigation Time for America"

      --
      An Eye for an Eye will make the whole world blind - Gandhi
    8. Re:FBI uses AOL by Anonymous Coward · · Score: 0

      Yeah, he did. "...that the FBI". He wasn't referring to an FBI employee, he was reffering to FBI, the organization. Dumbass.

    9. Re:FBI uses AOL by Daniel+Dvorkin · · Score: 4, Funny

      "You've got a subpoena!"

      --
      The correlation between ignorance of statistics and using "correlation is not causation" as an argument is close to 1.
    10. Re:FBI uses AOL by InfiniteWisdom · · Score: 1

      RFTA... oh wait this is Slashdot. My bad. But... ...when she unwittingly spammed an off-duty FBI computer crime agent...

      The FBI probably doesn't use AOL. At least no reason to infer that they do from THIS article.

    11. Re:FBI uses AOL by TRS80NT · · Score: 1

      Hey, give him a break. Maybe there's only dialup in his neighborhood and he happens to use AOL. He clocks out, and like the rest of us: some email, check the scores, a little pr0n, a little Slashdot...

      --
      Lorem ipsum dolor sit amet.
    12. Re:FBI uses AOL by menscher · · Score: 1
      I can't be the only one that finds it disturbing that the FBI uses AOL.

      What I found more disturbing was that they don't have any clue about computers whatsoever. I interacted with them once to report progress on tracking an intruder, and to request help. They didn't understand anything I was telling them, since I was using advanced words like "DoS", "packet sniffer", etc. They asked me to mail them my logs... as in print them out an send them by post. They said they didn't have the ability to receive email.

      Needless to say, I didn't bother. It was much more productive (and enjoyable!) to track the intruder myself, and make him suffer. ;)

    13. Re:FBI uses AOL by Anonymous Coward · · Score: 1, Funny

      Yeah, you seem pretty typical. High UID, n othing of value in the history. You're not a fan of the guvment, are ya? Not that the UID says much on its own, but damn if some of the stupidest crap on this site isn't posted by the Over 600s, to say nothing of the 700s.

      Anyway, FBI agents are people too. As much as your dystopian fashionable hatred will not allow you to believe. They have family, the two story in some gentrified slice of suburbia, the works. Families like AOL.

      In summary, go to hell.

    14. Re:FBI uses AOL by Anonymous Coward · · Score: 0
      oh yah! H4xx0r.

      Did you ping him to death?

    15. Re:FBI uses AOL by Anonymous Coward · · Score: 0

      "We've got your mail!"

    16. Re:FBI uses AOL by Anonymous Coward · · Score: 0

      You've got jail!

    17. Re:FBI uses AOL by david@ecsd.com · · Score: 1

      I don't use AOL, and I got (probably) the exact same e-mail. Curious, I followed the link and checked out what they wanted. If a person was naive (yes, there are plenty of naive people out there), then they'd fill out the secure form and the scammer would have their number; so my bet is we have an idiot scammer on our hands sending out their spam to non user@aol.com addresses rather than an idiot FBI special agent who's checking his personal e-mail while "on the clock."

      Besides, L337 internet users bitching about the stupid aolers is passe.

    18. Re:FBI uses AOL by tds67 · · Score: 1
      You mean you missed the Time/AOL/FBI merger?

      What? Oh great, I bet there's going to be listening devices in all those AOL CDs that I get in the mail from now on...

    19. Re:FBI uses AOL by Guppy06 · · Score: 1

      "I can't be the only one that finds it disturbing that the FBI uses AOL."

      How else are they going to catch pedophiles?

    20. Re:FBI uses AOL by Anonymous Coward · · Score: 0

      No more rhymes, and I mean it!

    21. Re:FBI uses AOL by Anonymous Coward · · Score: 0

      *sigh* The name is "Due-marce."

    22. Re:FBI uses AOL by Paradise+Pete · · Score: 1
      I too find it distrubing that FBI employees AOL using agents

      Man, that is one crappy sentence. Distrubing, even.

    23. Re:FBI uses AOL by Anonymous Coward · · Score: 0

      Anybody want a peanut?

    24. Re:FBI uses AOL by Anonymous Coward · · Score: 0

      That's because it's taken for granted that they're stupid. It's one of those things that sounds like a false stereotype, but every AOL user I've seen convinces me that America Online is like the Special Olympics of ISPs.

    25. Re:FBI uses AOL by hankaholic · · Score: 1

      Rumor has it that a few years ago when they were constructing a new FBI building in Pittsburgh, one of the FBI bigwhigs wanted to look into getting every computer in the building access through cable modems.

      That's right, not shared access from behind a firewall which was connected through a cable modem, but he wanted to have one per system.

      I say that this is a rumor because I heard it from an older gentleman who worked for the FBI (a big ham radio fan, as well) over lunch when he and my then-employer were swapping stories of cluelessness, and I'm not sure how close to implementing this setup they actually were. It's amusing nonetheless.

      --
      Somebody get that guy an ambulance!
    26. Re:FBI uses AOL by jaysones · · Score: 2, Funny
      You mean you missed the Time/AOL/FBI merger?
      Yeah, it takes forever to convict and if you ever do get convicted, they kick you out after a few minutes.
    27. Re:FBI uses AOL by Schemat1c · · Score: 1
      Rumor has it that a few years ago when they were constructing a new FBI building in Pittsburgh, one of the FBI bigwhigs wanted to look into getting every computer in the building access through cable modems.

      Maybe it was to make the agents appear as regular users when undercover. Plus by having regular ISP accounts they would be the recipients of some of the email scams and be more aware of them.

      --

      "Nobody knows the age of the human race, but everybody agrees that it is old enough to know better." - Unknown
    28. Re:FBI uses AOL by Random832 · · Score: 1

      High UID, n othing of value in the history.

      one possible translation: Long-time reader, recent poster.

      --
      We've secretly replaced Slashdot with new Folgers Crystals - let's see if it notices.
    29. Re:FBI uses AOL by Knetzar · · Score: 1

      I'm just amused that this person posted as an AC...and as far as we know has no number yet.

    30. Re:FBI uses AOL by YOU+ARE+SO+SUED! · · Score: 1
      Yeah, you seem pretty typical. High UID, n othing of value in the history. You're not a fan of the guvment, are ya? Not that the UID says much on its own, but damn if some of the stupidest crap on this site isn't posted by the Over 600s, to say nothing of the 700s.

      And your UID?! Notihng, you're posting anon. Yep. pretty typical indeed. Anonymous Coward, nothing of value in the scrotal department. Not that you can generalise about AC's, but damn if some of the stupidest crap on this site isn't posted by the AC's.

      At least the logged in trolls have the balls.

    31. Re:FBI uses AOL by hankaholic · · Score: 1

      No, this wasn't for a computer-crime division, or anything meant for the technically savvy. It was intended for normal users -- think secretaries and PHBs, not kiddie-porn and online scam hunters.

      --
      Somebody get that guy an ambulance!
    32. Re:FBI uses AOL by Anonymous Coward · · Score: 0

      It's probably his personal or family account. I doubt the FBI itself uses AOL. Come on people.

    33. Re:FBI uses AOL by Anonymous Coward · · Score: 0

      Wow... right after i read this i heard about "a suspicious man adressing girls" on the local police radio...
      How's that for a coincidence?

  4. bigger catch than just that by ethelred · · Score: 5, Insightful

    An electronic trail of stolen AOL accounts and free Web pages led agents to raid the homes of a professional spammer and a credit card thief, both of whom snitched on Carr, naming her as the ringleader of the operation

    She isn't the only one going down. But, sadly, there are still many more to go...

    --

    Remember: If you buy anything from spammers, you have a small penis.
    1. Re:bigger catch than just that by nutsy · · Score: 2, Insightful

      a professional spammer and a credit card thief, both of whom snitched on Carr

      Of course, this goes to show that there is no honour among spammers, either.

  5. Phish by apraetor · · Score: 2, Funny

    Uh oh, looks like Phish has made the headlines AGAIN. Ah well.

    --matt

  6. People aren't what you'd expect by Rosco+P.+Coltrane · · Score: 3, Insightful

    a 55 year old woman spammed an FBI computer crime agent. She got caught mailing off a credit card scam to AOL users.

    What this story teaches us:

    - Little middle-aged (well, quite ripe already) ladies are not to be trusted

    - AOL users are idiots, since they are prime targets of even little middle-aged lady spamsters

    - FBI agents too open AOL accounts, which is worrying in a sense

    --
    "A door is what a dog is perpetually on the wrong side of" - Ogden Nash
    1. Re:People aren't what you'd expect by d-man · · Score: 1

      FBI agents too open AOL accounts, which is worrying in a sense

      I would imagine that FBI agents have AOL accounts to track people who are attempting to commit computer crimes, since AOL is probably a very target-rich environment.

      --
      Unix: Where /sbin/init is still Job 1.
    2. Re:People aren't what you'd expect by Anonymous Coward · · Score: 0

      I would imagine that FBI agents have AOL accounts to track people who are attempting to commit computer crimes, since AOL is probably a very target-rich environment.

      Yes, that too, but the story says the agent was off-duty. So I imagine it was his home account.

    3. Re:People aren't what you'd expect by Nykon · · Score: 1

      Yes but keep in mind,just because the agent may be computer savvy, does nto mean his family is. Government workers don't always make us much as us tech-weenies, so chances are he probably uses what ever is the best for his whole family.

      --
      "It's better to be a pirate then join the Navy"
    4. Re:People aren't what you'd expect by sweetooth · · Score: 1

      Makes sense except for one thing. The article clearly states this agent was OFF-DUTY! Implying of course that this was the agents personal method of Internet access.

    5. Re:People aren't what you'd expect by MegaManInferno · · Score: 1

      Jeez, why do you keep saying the agent was off duty?
      It dosen't matter if the agent wass off duty, this lady was commiting credit card fraud, which is aginst the law.

    6. Re:People aren't what you'd expect by sweetooth · · Score: 1

      No, it doesn't matter if the agent was on or off duty in the context you are talking about however, that's not what the parent poster was talking about. The parent poster is saying that he bets the FBI uses AOL accounts to catch people commiting these types of crimes. Which may or may not be the case. What I was pointing out is that in this case the only reason the FBI is involved is because an Agent recieved the spam. The article specifically mentions that the agent was off-duty. This implies that it was the agents personal account. So, even if the FBI does use AOL accounts internally for the sole purpose of catching spam that doesn't apply to this instance, noe is your comment relavent to my reply. We were talking about if the FBI uses AOL to catch scammers, not whether the person was commiting a crime.

    7. Re:People aren't what you'd expect by gnu-generation-one · · Score: 0

      - FBI agents too open AOL accounts, which is worrying in a sense

      Or, to quote the Onion? headine:
      50% of people in chatrooms are FBI agents posing as teenage girls, trying to date the other 50%, which are FBI agents posing as teenage boys.

  7. Let em guess she was American ? by Anonymous Coward · · Score: 0, Flamebait

    only in America could someone be stupid enough to do this

    luckily i blocked 99.9% of spammers pathetic attempts by blocking the $ and cent sign, voila no spam, no false positives, no frauds , no americans :)

    1. Re:Let em guess she was American ? by Rosco+P.+Coltrane · · Score: 2, Insightful

      No, she was smart, she sent her scam mails to AOL users, who are notorious credulous computer idiots. She didn't send it to postmaster@homelandsecurity.gov. She was just unlucky that an FBI agent was on AOL too.

      --
      "A door is what a dog is perpetually on the wrong side of" - Ogden Nash
    2. Re:Let em guess she was American ? by Anonymous Coward · · Score: 0

      How were you able to block the 'cent sign' when you can't even find on your keyboard?

    3. Re:Let em guess she was American ? by MillionthMonkey · · Score: 1

      She didn't send it to postmaster@homelandsecurity.gov.

      I bet postmaster@homelandsecurity.gov gets plenty of spam...

      Postmaster, Instant Pleasures ........ TYcw4ixg
      Hey Postmaster! We were waiting for you last night
      Postmaster, v^iagra is cheapest here............2qx3
      postivic@homelandsecurity.go v, thanks for your purchase
      100% satisfaction guaranteed on inkjet cartridges, postmaster xd ds jj1esdzzb
      Postmaster, get home delivery of V a l i u m and V i a g a r a
      Postmaster You could have money coming blackbody
      posman, Tired of deleting spam? egmgsdoptoreoq
      postmaster, Government grants are easier to get than you think

    4. Re:Let em guess she was American ? by ljavelin · · Score: 4, Insightful

      Sorry, but it is incredibly naive of you to assume that only "computer idiots" fall for these scams.

      They are very convincing... stealing all the branding of a legit informational email. I'll tell you, my mom and dad just cannot tell the difference between http://www.citibank.com/signup/account.jsp and http://www.citibank.com@192.168.0.1/acct.jsp.

      These scams can be compelling to people who don't understand that ALL email should be untrusted, and that all URLs within email should be untrusted, and that all forms that you fill out should be untrusted.

    5. Re:Let em guess she was American ? by Anonymous Coward · · Score: 0

      Yes, because nobody gets scam emails from Africa or anything like that. Fucking leftist Eurotrash, go crawl back into the whole you came from and keep patiently waiting for your grand Socialist vision to materialize. Then do us all a favor and die a painful death.

    6. Re:Let em guess she was American ? by Rosco+P.+Coltrane · · Score: 1

      Well okay, you're right actually. I really should have written "computer users". There are a lot of people who get scammed with snail mail too and they're not necessarily idiots.

      --
      "A door is what a dog is perpetually on the wrong side of" - Ogden Nash
    7. Re:Let em guess she was American ? by Anonymous Coward · · Score: 1, Insightful

      Good guess. I never would have figured that out. Well, except for the part where it says she is from OHIO!

      This never happens anywhere else. Except for all those countries that collapse because so much of the population is taken by a single scam! Albania

    8. Re:Let em guess she was American ? by kfg · · Score: 5, Funny

      There are certain items of the arcana that are only available to the wise. Ok, some MCSEs know them too, but only a few.

      Do wish to have arcane knowledge and be the envy of your 133t friends? How on earth those spammers, well know for deep knowledge of the darkside, produce a cent sign when it isn't on the keyboard?

      You (sir/madam) have been carefully selected as one the few who have what it takes to secret forces and such power right at your fingertips!

      Don't be a clueless dork anymore. Just send $19.95. Your seat at the table of the Illuminati is waiting. . . for you (sir/madam)!!!

      KFG

    9. Re:Let em guess she was American ? by Anonymous Coward · · Score: 0

      by blocking the $ and cent sign, voila no spam, no false positives

      No false positives? "$" is used for a lot more than American currency.

      I guess you wouldn't know that since your blocking the character.

    10. Re:Let em guess she was American ? by Anonymous Coward · · Score: 0

      They are very convincing... stealing all the branding of a legit informational email. I'll tell you, my mom and dad just cannot tell the difference between http://www.citibank.com/signup/account.jsp and http://www.citibank.com@192.168.0.1/acct.jsp.
      I have a message for your mom and dad - THE SCAM ARTIST IS ON THEIR INTERNAL LAN!

    11. Re:Let em guess she was American ? by nnnneedles · · Score: 1
      "go crawl back into the whole you came from"???

      It's hole, you moran!

      --
      Will code a sig generator for food
    12. Re:Let em guess she was American ? by Anonymous Coward · · Score: 0

      Yeah, it's used to identify string variables in obsolete versions of BASIC. And God knows, I get lines of BASIC used as subject lines all the time!

    13. Re:Let em guess she was American ? by russx2 · · Score: 1

      "It's hole, you moran!" It's moron, you idiat!

    14. Re:Let em guess she was American ? by Knife_Edge · · Score: 1
      http://www.citibank.com@192.168.0.1/acct.jsp

      What is the deal with this, anyway? I've never seen an URL like this before. Looks like a combination of an URL and an email address. Obviously what is happening is that the link actually leads to the ip address and not www.citibank.com. However, I realized this only because of the context of the conversation here, not because I knew what it was beforehand.

      Is the reason you can still use www.citibank.com because on that IP address (which is fake) there is a listening web server that accepts connections for www.citibank.com, even though it is not really www.citibank.com?

      Man, this might have fooled me, and I'm considerably savvier than the average person. I might have wondered about the odd domain in the browser. Doing a DNS lookup of the real www.citibank.com would give away the scam, but generally I assumed that domains cannot be hijacked this way.

      Someone with less knowledge of computers would be most unlikely to think the `@` symbol was anything more unusual than anything else in a domain name. Let's stay ahead of the scammers, people. Inform your less experienced friends and relatives.

    15. Re:Let em guess she was American ? by Anonymous Coward · · Score: 0

      It's moron you "moran."

    16. Re:Let em guess she was American ? by lizrd · · Score: 2, Informative
      @ is a valid character in any url. Anything preceeding the @ sign is considered as a username and the part following the @ sign is the url that it will be used for. The actual useful application for this is in ftp:// urls. For example, you might use a url like ftp://warez:mp3@riaa.org/metallical.mp3 do download Metallica mp3z from the riaa. In the example above warez would be used for the username and mp3 for the password. Since the vast majority of http:// type urls don't require a username and password, it just gets thrown away by your browser since it wasn't needed. It's a very common tactic in spam e-mails.

      Now you know that. I know that, but most people don't and it would still be pretty easy to convince someone to visit The Linux kernel website (I think that /. may have sanitized the misleading like, it should read http://www.kernel.org@3632843893/ copy and paste it yourself to find out) and find themselvse at freebsd.org instead. It all comes back to the first rule of Spam, "Spammers Lie.", when in doubt, see rule 1.

      --
      I don't want free as in beer. I just want free beer.
    17. Re:Let em guess she was American ? by Anonymous Coward · · Score: 0
      Interesting stuff, and very impressive.

      But how did you go from www.freebsd.org to get 3632843893?

      Please educate a newbie...! ;-) Thanks in advance.

    18. Re:Let em guess she was American ? by Mikeydude750 · · Score: 0

      It's the IP address of the site minus the periods.

    19. Re:Let em guess she was American ? by Anonymous Coward · · Score: 0


      its the ip address but in octal format

    20. Re:Let em guess she was American ? by Anonymous Coward · · Score: 0

      if you can read simple code this might help :) (javascript)

      function IpToLong(s){
      for(var i=r=0,aI=String(s).split("."),l=aI.length;i<l;i++) r+=parseInt(aI[i])*Math.pow(256,(l-1)-i);
      return r;
      }

      //google is 216.239.57.99
      //its long ip is 3639556451

      document.write("<a href=http://"+IpToLong("216.239.57.99")+">"+IpToLo ng("216.239.57.99")+"</a><br>")

    21. Re:Let em guess she was American ? by Anonymous Coward · · Score: 0
      Ok, thanks, to you and the above posters.
      Javascript is not my strong side but I understand enough to see that is has something to do with converting of IP to another format; octal form aka base 8.

      And found a site about this:
      http://0xCE.191.0236.0x37/obscure.htm
      (pc-help.org)

      URL with hex, decimal and octal numbers. :-)

    22. Re:Let em guess she was American ? by droleary · · Score: 1

      Sorry, but it is incredibly naive of you to assume that only "computer idiots" fall for these scams.

      No, that is instead an incredibly accurate statement. The dirty secret is that 90% of users are "computer idiots", despite their feeling otherwise. It's just like how the vast majority of people think they're above average drivers.

      They are very convincing... stealing all the branding of a legit informational email. I'll tell you, my mom and dad just cannot tell the difference between http://www.citibank.com/signup/account.jsp and http://www.citibank.com@192.168.0.1/acct.jsp.

      Then that would then make them computer idiots. But that shouldn't even matter. It should be a simple issue of common sense. These scams contain any number of logical fallacies, mostly in the use of threat and authority in an attempt to be convincing.

      These scams can be compelling to people who don't understand that ALL email should be untrusted, and that all URLs within email should be untrusted, and that all forms that you fill out should be untrusted.

      In other word, compelling to idiots. And not just computer idiots, but general idiots. This whole thing has nothing to do with computers. If someone calls on the phone claiming to be from Citibank and demanding information, do you just give it to them? What if it's just a guy on the street in a suit with a name tag that says Citibank and a clip board? The email is no different a scam.

      A lot of people like to bitch and moan about patent stupidity when someone tags "on a computer" to an old idea, but here you are trying to claim there is a significant difference between email and other types of social contract. That is just not the case. If your parents fall for a "give me your credit card number or spoooooooky bad things are going to happen!" scam, they are idiots. If you fail to acknowledge that, the problem might just have a genetic component.

    23. Re:Let em guess she was American ? by Anonymous Coward · · Score: 0
      "It's hole, you moran!" It's moron, you idiat!

      Yes it is but it's idiot, you imbecile!!

    24. Re:Let em guess she was American ? by dontbgay · · Score: 0

      yanno.. i was scammed like that too. i saw a GNAA link to yahoo and it took me to the goatse guy... i still have nightmares. oh the humanity ;\

      --
      Sig not found.
  8. maximum of five years? by ajuda · · Score: 0, Flamebait

    The maximum penalty seems rather meager. She can't exactly argue self-defense, lack of understanding, or accidental-negligence. This is a case of deliberate fraud, a case in which she obviously knew that what she was doing was both immoral and illegal. In my opinion, they should kill her. Really. It's people like her that really make this world suck more than it has to.

    1. Re:maximum of five years? by dreadnougat · · Score: 1

      You think that any of those countries has an exemplary legal system? You must be joking. Hear of William Sampson and those others caught in Saudi Arabia and framed for a crime they didn't commit? Know what they kill you for in China?

    2. Re:maximum of five years? by Anonymous Coward · · Score: 0

      What does one do if law enforcement made a mistake and helped set a case against the wrong person?

      Until we have re-animation, the only answer is to kill police officers for their mistakes, too. Then nobody would be a police officer. Then there'd be no more criminals caught. Then we have anarchy.

    3. Re:maximum of five years? by Dragon218 · · Score: 1

      you're not funny, so stop trying.

      --

      "It's the little touches that make a future solid enough to be destroyed" --William S. Bourroughs
    4. Re:maximum of five years? by azav · · Score: 1

      You and I support the death penalty for spammers. If we could only convince the rest of the world.

      Seriously, knock off a few spammers and see what happens.

      They way they are being treated now, it looks like the law looks the other way. Spamming is several crimes. Misrepresentation, fraud and theft of services to start.

      --
      - Zav - Imagine a Beowulf cluster of insensitive clods...
    5. Re:maximum of five years? by TheMidget · · Score: 1
      Just one keyword to show you this is a bad idea: joe-jobs!

      You don't wanna end up on the death-row because a particularly savvy spammer managed to pull off the perfect forgery with your name on it...

    6. Re:maximum of five years? by vicparedes · · Score: 1

      Heh. If this person was your nanna, you wouldn't be bitching now would you? Think of all the goodies you'll get on your birthday and Christmas.

    7. Re:maximum of five years? by azav · · Score: 1

      Please inform me about this joe-jobs thing.

      Really. I don't know what it is.

      --
      - Zav - Imagine a Beowulf cluster of insensitive clods...
    8. Re:maximum of five years? by Anonymous Coward · · Score: 0

      Yeah.... Well I guess we're just different people. If my grandma gave me pictures of hot wet asian teens, and a bag of penis-grow as we all gathered round the christmas tree I can't say I'd be filled with the christmas spirit.

    9. Re:maximum of five years? by anubi · · Score: 2, Informative
      A "joe-job' is what its called when a spammer encodes someone's ( the 'joe' ) address who the spammer would like to cause immense harm to in the 'reply-to' field of his spam message.

      Millions of spam go out, and the named joe gets hit with all the ire and bounced-mail replies. His ISP usually becomes quite upset with him as well, and he's left trying to explain to everyone that he doesn't even know what the hell is going on.

      Its a really neat way of framing somebody on the internet - making it appear to all the outside world that 'joe' did it, when in reality joe was completely uninvolved.

      --
      "Prove all things; hold fast that which is good." [KJV: I Thessalonians 5:21]

    10. Re:maximum of five years? by LearnToSpell · · Score: 1
    11. Re:maximum of five years? by Anonymous Coward · · Score: 0

      Sampson was an alcohol smuggler, plain and simple. The only question is the extent of his role in the murder of the Englishman.

    12. Re:maximum of five years? by geekoid · · Score: 1

      I clicked www.brycchouse.org link, and it seemed like a scam. I meant it is in the root directory, says they need money for some 'Non profit' thing, but doesn't say what it is, exactly.

      --
      The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
    13. Re:maximum of five years? by Maserati · · Score: 1

      How about this ?

      http://www.snopes.com/inboxer/outrage/darkprofit s. asp

      --
      Veteran, Bermuda Triangle Expeditionary Force, 1992-1951
    14. Re:maximum of five years? by crabpeople · · Score: 1

      "Think of all the goodies you'll get on your birthday and Christmas." oh boy mommy! 3 inches of some guys wang!

      --
      I'll just use my special getting high powers one more time...
    15. Re:maximum of five years? by Anonymous Coward · · Score: 0

      I have to agree that those people who prey on innocent citizens with frauduent scams are worse than thieves. They are too rarely pursued by our law enforcement, their punishments are too lenient.

      If someone took up a collection to fund some vigilantes whose sole purpose was to find these people and make them suffer terrifying, painful and/or humiliating punishments (cutting off the right hand or at least a few digits) I would probably toss in $100 and feel not feel any guilt.

      Me, angry? No, "anger" doesn't even begin to describe it.

    16. Re:maximum of five years? by Harinezumi · · Score: 1

      Sending her to prison for 5 years sounds about right. Just have to make sure they send her to a men's prison.

    17. Re:maximum of five years? by dreadnougat · · Score: 1

      They forced a confession out of him, which is to say, they fabricated one. Think about that: they fabricated a confession. They framed him. They tortured him until he read it for them on video. You think that's a good system?

  9. No wonder! by l3prador · · Score: 4, Funny

    No wonder I get so many email offers for Viagra and low-cost prescription drugs!

    1. Re:No wonder! by The+Fink · · Score: 1

      Or larger breasts for that matter...

  10. MOD PARENT UP by Anonymous Coward · · Score: 0

    nt

  11. Earthlink users are getting similar spam by Cujo · · Score: 3, Informative

    I've had about 2 e-mails a day of this ilk with respect to my Earthlink account for at least 3 months. A similar scam is in work with respect to Paypal. You don't need to be a total dunce to fall for this, either. Just naive and not savvy with raw e-mail source.

    --

    Helium balloons want to be free.

    1. Re:Earthlink users are getting similar spam by ceejayoz · · Score: 1

      Most of the large web communities are - they're easy targets.

      eBay gets 'em a lot, I've seen some exceedingly slick ones.

    2. Re:Earthlink users are getting similar spam by Licinius · · Score: 2
      That's nothing compared to what I get. Some person using a Road Runner account has been sending me, on average, 7000-9000 (yes, thousand) e-mails per week containing a virus/trojan or the like. I've contacted the RR abuse department twice already and they haven't done anything about it (and I gave them time, it's been about 2 months since I first contacted them). It makes me doubt that they'll do anything at all.


      Does anyone know how I could block this guy from sending me e-mails? Not just in the e-mail client, but at the server level (or whatever) so I don't have to download all of his crap. Anyone at all? Please help.

      --
      My other SIG is a 9mm.
    3. Re:Earthlink users are getting similar spam by EvanED · · Score: 1

      How 'bout set up a filter that will automatically send all of these to the abuse department of both RR and the original source (if the headers aren't too forged)?

    4. Re:Earthlink users are getting similar spam by Guppy06 · · Score: 2, Informative

      "I've had about 2 e-mails a day of this ilk with respect to my Earthlink account for at least 3 months."

      You know, there's a real easy way to stop that...

      Seriously, I find that challenge-response e-mail does to spam what Moz does to pop-ups.

    5. Re:Earthlink users are getting similar spam by crucini · · Score: 1

      First, how do you know the sender is "using a Road Runner account"? Are you going off the From: header? That's usually forged. Look at the Received headers, and see if the last server before yours is constant. If so, you have an easy criterion for blocking.

      Second, you didn't specify how you're getting your mail. Do you run your own mail server? If so, add an ipchains/iptables rule to block the offending IP. If you're getting your mail via POP/IMAP from someone else's server, I don't see how you can do server-side blocking.

    6. Re:Earthlink users are getting similar spam by Licinius · · Score: 1
      RR apparently monitors attachments for known virus/trojan/junk files and takes them out if one is found. Here's the text they put in to each of the messages:

      ALERT!

      This e-mail, in its original form, contained one or more attached files that were infected with a virus, worm, or other type of security threat. This e-mail was sent from a Road Runner IP address. As part of our continuing initiative to stop the spread of malicious viruses, Road Runner scans all outbound e-mail attachments. If a virus, worm, or other security threat is found, Road Runner cleans or deletes the infected attachments as necessary, but continues to send the original message content to the recipient. Further information on this initiative can be found at http://help.rr.com/faqs/e_mgsp.html.
      Please be advised that Road Runner does not contact the original sender of the e-mail as part of the scanning process. Road Runner recommends that if the sender is known to you, you contact them directly and advise them of their issue. If you do not know the sender, we advise you to forward this message in its entirety (including full headers) to the Road Runner Abuse Department, at abuse@rr.com.


      They said it was coming from a RR IP address, so I'm fairly certain.

      Unfortunately, I'm not running my own mail server, I'm using a POP3 account, so I can't block like that myself. Is there any other way I could block a certain address?
      --
      My other SIG is a 9mm.
    7. Re:Earthlink users are getting similar spam by WuphonsReach · · Score: 1

      And unfortunately, since e-mail FROM addresses tend to be forged, you're spamming some poor joe with your challenge messages. (Or else you're generating an e-mail that's going to bounce.)

      C/R systems just push the problem around... if the from domain could be trusted (ala one of the reverse-MX proposals), C/R systems would be a smarter bet.

      --
      Wolde you bothe eate your cake, and have your cake?
    8. Re:Earthlink users are getting similar spam by Guppy06 · · Score: 1

      "And unfortunately, since e-mail FROM addresses tend to be forged, you're spamming some poor joe with your challenge messages."

      Generally speaking, the challenges are issued once per e-mail address, not once per e-mail. If you send another e-mail while the system is still waiting for your response from the first one, you don't get another challenge.

      Or, if the poor schmuck also has a c/r system, both c/r systems talk to each other while neither end user sees much of anything.

    9. Re:Earthlink users are getting similar spam by crucini · · Score: 1

      Sounds like popfile would work for you. Unfortunately, as far as I can tell it must still download the spam messages before discarding them. At least that can occur silently in the background.

  12. Hooks the wrong person? by Zuke8675309 · · Score: 5, Insightful

    The article makes it sound like she wouldn't have got caught if an FBI agent hadn't been a recepient of the email. I hope this isn't the case and that the FBI is taking a more pro-active attack on this kind of thing than what the article seems to say.

    1. Re:Hooks the wrong person? by hazem · · Score: 1

      I think that is the case. From the article:

      Carr's undoing began when an FBI agent in the Norfolk, Virginia field office received one of her e-mails in February, 2001, and launched an investigation.

      Do you think anyone at the FBI would listen if you, an ordinary tax-paying citizen, called to report the same e-mail? They'd probably laugh and tell you that they were busy fighting *real* terrorists.

    2. Re:Hooks the wrong person? by Anonymous Coward · · Score: 0

      Read these for more details:

      Indictment

      Affidat

      Press Release

    3. Re:Hooks the wrong person? by Anonymous Coward · · Score: 0

      The article makes it sound like she wouldn't have got caught if an FBI agent hadn't been a recepient of the email....

      All your emails belong to us !!

      Luv FBIman

    4. Re:Hooks the wrong person? by ralphus · · Score: 1
      She likely would have been caught at some point but it would require her being but when she is stupid enough to committ a crime RIGHT IN FRONT OF AN FBI AGENT, of course she's going to get caught quickly. Normally things transpire roughly as follows:
      1. Scammer trying to scam a bunch of users
      2. some subset of the users getting scammed
      3. some subset of the scammed realizing that they were scammed and reporting it, or some of the bright non-scammed user reporting it
      4. The FBI seeing the report
      5. FBI deciding to take action
      6. Following their internal investigative procedures
      7. gathering evidence
      8. making a case
      9. prosecuting scammer

      In the case we have here, a FBI agent gets in the loop directly and is able to jump into this process at step 6.

      The scammer would have gotten caught eventually if she kept running her scam. She just got un-lucky in this case and was caught as a result.

      --
      Revolutions are never about freedom or justice. They're about who's going to be top dog. -- Kilgore Trout
    5. Re:Hooks the wrong person? by Anonymous Coward · · Score: 0

      They may still have gotten caught. For example, all my cards have a toll free number. For example the Discover card uses the easy to rember 1-800-DISCOVER. I always call them with any card issues. I'm sure if I called regarding the scam, it would have headed straight to the fraud department. Unfortunately not enough people know to call their card carriers directly and are too easly directed to a fake site. Remember people, call the card company directly and confirm any claimed or real unauthorised charges. The CC company knows where they payments go to. They can shut down all payments to a scam artist when they get proof of the scam. You may save not only your account but many others also.

      So seriously, do you have the number to call for each of your cards on hand? They are the first point of contact, not a website.

  13. Let me be the first to say by NightWulf · · Score: 1, Troll
    Ha-HA!

    /nelson muntz voice

    I mean really how stupid can you be to actually "phish" for credit card numbers now, that's so 1997. She should have become involved in a much safer fraud, like identity theft, penny stock pump and dump, or creating a company...sending a donation to the Bush election fund...getting 8 billion dollar contract for rebuilding iraq. Come on people, use your head!

    1. Re:Let me be the first to say by Anonymous Coward · · Score: 0

      not to nitpick (well, yes, to nitpick) but the emphasis is on the first HA in the muntz laugh.

  14. Face of a scammer by Saeger · · Score: 1
    Whenever I hear about these scammer stories I often wonder what the face of scum looks like-- if maybe I could tell it apart from the average car salesman's. So I wonder if this 55 year old woman has got the permanently furrowed eyebrows (like most news anchors), and those squinty, contemptuous eyes.

    --

    --
    Power to the Peaceful
    1. Re:Face of a scammer by Anonymous Coward · · Score: 0

      I prefer to judge the criminality of a person by the bumps on their head. Maybe I'm just old school.

  15. Geez... by Cytlid · · Score: 5, Interesting

    ... sounds like she got off a lot easier than those caught sharing music via p2p programs. Either the FBI should hire the MPAA or anyone swapping music online should start credit card fraud, it sounds like the lesser offense.

    --
    FLR
    1. Re:Geez... by TooManyNames · · Score: 1

      You've got your agencies mixed up there... I think you were possibly looking for the RIAA. Or has the MPAA expanded recently?

      --
      "Is not a sentence" is not a sentence. Well damn.
    2. Re:Geez... by Cytlid · · Score: 1
      You've got your agencies mixed up there... I think you were possibly looking for the RIAA. Or has the MPAA expanded recently?


      Same smell, different orifice. Next time I'll put *AA or perhaps (MP|RI)AA... ;oD
      --
      FLR
    3. Re:Geez... by Night+Goat · · Score: 1

      Yeah, except this lady's getting a criminal record, whereas the people getting busted for swapping mp3s are just getting a civil tort filed against them. If you get a felony, your life is a lot shittier. Harder to get a job, you better believe it. And in some places you can't vote if you're a felon.

  16. Haha by Anonymous Coward · · Score: 0

    Take that grandma

  17. See for your selves by littleRedFriend · · Score: 5, Informative

    AOL Billing center sample page.

    --
    IANAL, but imagine a beowulf cluster of in Soviet Russia all your belong are base to us welcoming the new SCO overlords.
    1. Re:See for your selves by acidfast7 · · Score: 1

      Do poeple not catch spelling errors as a tip-off for an internet scam:

      On the top of the form: ASTERIK?

      What's a social insurance number (SIN)?

      Do people actually fall for this?

    2. Re:See for your selves by Celt · · Score: 2, Funny

      My fav line out of that page has to be this
      "Your current information will be stored in a 256-bit encrypted protected server." :)

      --
      "WebTV: bringing the Internet into the shallow end of the gene pool since 1995" - Martin Bishop
    3. Re:See for your selves by Dun+Malg · · Score: 2, Funny
      AOL Billing center sample page.

      Honestly, is amazes me that people fall for crap like this. It always reads like someone in bulgaria wrote it with with an English/Bulgarian dictionary. My favorite misspellings/miswordings are "asterik" and "social insurance number".

      --
      If a job's not worth doing, it's not worth doing right.
    4. Re:See for your selves by thinkninja · · Score: 1

      Mine was:
      "*Providing false or fraudulent information will be prosecuted to the fullest extent of the law*"

      --
      "The number of Unix installations has grown to ten, with more expected." (Unix Programmer's Manual, 2nd ed.; june 1972)
    5. Re:See for your selves by littleRedFriend · · Score: 1

      Yeah it's amazing. The page wants to know all details, including your mother maiden name. I mean, come on this must be more obvious than Nigerian scam.

      It also says: WARNING: Credit-card fraud is a criminal offense. For your protection all transactions are carefully monitored and logged including IP adresses, ISP, and other pertinent information.

      Hilarious! Ironic?

      If you do view source, you'll notice that the javascript used on the form is quite lame as well.

      --
      IANAL, but imagine a beowulf cluster of in Soviet Russia all your belong are base to us welcoming the new SCO overlords.
    6. Re:See for your selves by thrill12 · · Score: 1

      Now wait: even though this is a "sample" scam page, which does not "store" information, the access_logs should still simply reveal which page was requested including all variables GETted with it.
      But luckily, us /.-ers are way too smart to fall for that...

      --
      Slashdot: stuff for news, nerds that matter, matter for news, stuff that nerd
    7. Re:See for your selves by Anonymous Coward · · Score: 0

      Heh, it claims to be from AOL and then further claims that it must log the ISP. Sounds like it was based off a spam scam template.

    8. Re:See for your selves by akeyes · · Score: 1

      Couldn't they at least use a current page as an outline for it? "Copyright (C) 2000 America Online, Inc. All rights reserved. Legal Notices Privacy Policy Try AOL 5.0"

    9. Re:See for your selves by Hadur · · Score: 1



      Well, at least she got into the mindset of the standard AOL user... After all, where would we be without Frontpage and no-right-click scripts?

    10. Re:See for your selves by Snowdrake · · Score: 1

      Except that, in what I thought one of the more masterful touches of scammery, it says persecuted, as in wronged.

    11. Re:See for your selves by andrewagill · · Score: 1

      Or how about the Mr T Name Generator?

      Enter your date of birth, Foo!

    12. Re:See for your selves by Anonymous Coward · · Score: 0

      ... not to mention mispelling the URL, too. What's secority?

    13. Re:See for your selves by gklinger · · Score: 1

      SIN = Social Insurance Number which is the Canadian equivalant of an SSN (Social Security Number). Perhaps the scammers were Canadian?

    14. Re:See for your selves by I+Be+Hatin' · · Score: 2, Funny
      Do poeple (sic) not catch spelling errors as a tip-off for an internet scam:

      No, poeple don't. They're probably very used to seeing spelling errors on the Internet, so it doesn't phase them.

      --
      I know god exists. I read it on the internet, so it must be true.
    15. Re:See for your selves by I+Be+Hatin' · · Score: 1
      Honestly, is (sic) amazes me that people fall for crap like this. It always reads like someone in bulgaria wrote it with with an English/Bulgarian dictionary.

      So does your post. You're the second guy to respond to the parent saying "how come people don't pick up on the spelling/grammar errors?", and both of you had spelling errors in your posts! Not that most people know how to spell 'asterisk' anyway...

      --
      I know god exists. I read it on the internet, so it must be true.
    16. Re:See for your selves by Anonymous Coward · · Score: 0

      Man, your blog is hilarious. I've been pissing my pants...

    17. Re:See for your selves by Anonymous Coward · · Score: 0

      so it doesn't phase [sic] them.

      Apparently using the wrong words doesn't bother anyone either.

      faze (faz) verb, transitive
      fazed, fazing, fazes
      To disrupt the composure of; disconcert. See synonyms at embarrass.

      [Middle English fesen, to drive away, frighten, from Old English fesian.]

      Excerpted from The American Heritage Dictionary of the English Language, Third Edition

    18. Re:See for your selves by I+Be+Hatin' · · Score: 1

      "Webster's Revised Unabridged Dictionary (1913)"
      Phase Phase, v. t. Cf. Feeze.
      To disturb the composure of; to disconcert; to nonplus.
      Colloq.

      So fuckin' bite me, asswipe.

      --
      I know god exists. I read it on the internet, so it must be true.
    19. Re:See for your selves by I+Be+Hatin' · · Score: 1
      Heh... it's not mine, though. I suppose I should change my sig so that it doesn't look like I'm claiming it, eh?

      --
      I know god exists. I read it on the internet, so it must be true.
    20. Re:See for your selves by Anonymous Coward · · Score: 0

      I think the dead giveaway though is the big red box with the words "Sample Scam Page" flashing inside.

    21. Re:See for your selves by squiggleslash · · Score: 1

      If you happily enter your name, social security number, and credit card, into a website that clearly doesn't need it, doesn't ask for it, and has "SAMPLE SCAM PAGE" written on it in huge flashing letters, then I think you deserve to have your details stolen!

      --
      You are not alone. This is not normal. None of this is normal.
    22. Re:See for your selves by crabpeople · · Score: 1

      whats wrong with social insurance number thats spelled perfectly right. i have never had a company on the net ask me for my SIN tho..

      --
      I'll just use my special getting high powers one more time...
    23. Re:See for your selves by Unregistered · · Score: 1

      They're not even subtle. Card limit? Can you be more obvious it's a scam?

    24. Re:See for your selves by lgftsa · · Score: 1

      Wow! There's people who've never heard of Rene Goscinny and Albert Uderzo? What a grey, joyless childhood they must have had.

    25. Re:See for your selves by Reziac · · Score: 1

      That should be "doesn't *faze* them", since we're holding a spelling bee ;)

      --
      ~REZ~ #43301. Who'd fake being me anyway?
    26. Re:See for your selves by jonbryce · · Score: 1

      Amateurs. They forgot to ask for the bank username and password / pin.

    27. Re:See for your selves by badzilla · · Score: 1

      That page triggers my virus checker, I am alerted to presence of "Trojan JS.Cardst"

      --
      "Don't belong. Never join. Think for yourself. Peace." V.Stone, Microsoft Corporation
    28. Re:See for your selves by WWWWolf · · Score: 1
      My favorite misspellings/miswordings are "asterik" and "social insurance number".

      My favorite was "Verified at 11/2/103 12:22:41 P.M.". I thought I'd never see stuff like this again, but I was wrong =)

    29. Re:See for your selves by topdawg044 · · Score: 1

      Would be more believable if they learned the proper spelling of *asterisk*

    30. Re:See for your selves by Dun+Malg · · Score: 1
      You're the second guy to respond to the parent saying "how come people don't pick up on the spelling/grammar errors?", and both of you had spelling errors in your posts!

      People should expect/overlook spelling errors in something as ephemeral as a /. post. My point is, that something as important as a credit card info page by AOL would undoubtedly be proofread at least once, and thefact that it's rife with errors should have tipped them off that it was a scam. Cripes, I didn't say I was going to spell everything right in my post, did I? Get with the program, man.

      --
      If a job's not worth doing, it's not worth doing right.
    31. Re:See for your selves by I+Be+Hatin' · · Score: 1
      People should expect/overlook spelling errors in something as ephemeral as a /. post. My point is, that something as important as a credit card info page by AOL would undoubtedly be proofread at least once, and thefact that it's rife with errors should have tipped them off that it was a scam.

      You're right, it should tip them off that it's a scam. However, most people have atrocious spelling skills, and so would miss some of these errors (esp. asterisk). Second, once you get used to reading over spelling errors (i.e. over IM, in email, on /.), it becomes easier to read over spelling errors all the time. I don't think that people have contextual spelling error detection (tm). Rather, I think people have one "mode" of reading, and that their tolerance for spelling errors is growing as they read more unedited material. So ultimately, I don't think that people even saw the spelling errors, thus it didn't tip them off.

      --
      I know god exists. I read it on the internet, so it must be true.
    32. Re:See for your selves by I+Be+Hatin' · · Score: 1
      That should be "doesn't *faze* them", since we're holding a spelling bee ;)

      Before correcting someone's spelling, you should check that they're actually wrong, Dan...

      From http://dictionary.reference.com/search?q=phase:

      phase

      \Phase\, v. t. [Cf. Feeze.] To disturb the composure of; to disconcert; to nonplus. [Colloq.]

      Source: Webster's Revised Unabridged Dictionary, (C) 1996, 1998 MICRA, Inc.
      --
      I know god exists. I read it on the internet, so it must be true.
    33. Re:See for your selves by Reziac · · Score: 1

      "Phase" in that context is a relatively new spelling, and is a mistaken use of a homonym, NOT as a proper alternate spelling. See http://dictionary.reference.com/search?q=faze -- and note spelling of the word from which it's derived: "Middle English fesen, to drive away, frighten, from Old English fesian."

      And yes, I'm old enough to remember when "faze" was in common usage.

      --
      ~REZ~ #43301. Who'd fake being me anyway?
    34. Re:See for your selves by Dun+Malg · · Score: 1
      My point is, that something as important as a credit card info page by AOL would undoubtedly be proofread at least once, and thefact that it's rife with errors should have tipped them off that it was a scam.

      You're right, it should tip them off that it's a scam. However, most people have atrocious spelling skills, and so would miss some of these errors (esp. asterisk). Second, once you get used to reading over spelling errors (i.e. over IM, in email, on /.), it becomes easier to read over spelling errors all the time. I don't think that people have contextual spelling error detection (tm). Rather, I think people have one "mode" of reading, and that their tolerance for spelling errors is growing as they read more unedited material. So ultimately, I don't think that people even saw the spelling errors, thus it didn't tip them off.

      Good points. I'm one of those people who can spell, so the idea that someone can look at a bunch of misspelled words and not notice sometimes strikes me as inconceivable. Of course, then I run into the same thing (in reverse) from guys at work when they find out I don't know how to play "futbol"....

      --
      If a job's not worth doing, it's not worth doing right.
  18. apathy in law enforcement by SuperBanana · · Score: 4, Interesting

    Danger Will Robinson, Danger! Rant Ahead!

    Read on SecurityFocus, a 55 year old woman spammed an FBI computer crime agent.

    Great. So what about:

    • the thousands of people getting ripped off daily on eBay
    • the DDoS's against blackhole list services
    • the thousands of script kiddies running loose

    ...? It seems like every day I'm reading about how some guy got screwed over and the FBI/SP/Local cops just didn't give a shit enough to do anything about it, whether it was technology related or otherwise, because it wasn't sexy enough. Crime is crime is crime.

    Case and point, you can pretty much scam anyone outside of your state and get away with it because interstate fraud laws have a $5,000 'ground floor'. That single law is probably the most responsible for the prolific fraud we've ever seen, virtual or otherwise. I could loose $4900 tomorrow and the FBI won't do jack shit. Some FBI nerd gets a scam email any moron would know not to answer, and they call out the swat teams. Faaaaantastic.

    It's like the local cops who don't give a shit if your laptop, your radio, etc were stolen and hundreds of dollars in damage done to your car. But, mind you, they've got all day to sit out on 'speed patrol'...

    1. Re:apathy in law enforcement by azav · · Score: 1

      Let me respond to this with two points.

      Crime is crime is crime but there is too much of it and not enough money/resources/people/time to stop it. So you go where your effort has the most impact.

      Cops DON'T care about the little things because they have bigger ones to deal with. It's true. I had to track down a laptop thief myself (and I got my laptop back) because I knew the cops wouldn't do anything about it. When something of yours gets stolen, you need to get on it right away and get it back. Hire an investigator if you can. You've gotta take action yourself because you can't be sure that anyone else will look out for your interests like you will.

      --
      - Zav - Imagine a Beowulf cluster of insensitive clods...
    2. Re:apathy in law enforcement by Xerithane · · Score: 1

      I've had things stolen, and had a neighbor whose car was stolen, and had a boss whose car was broken into. You need to move to a better city, because this has been spanning 3 states and I've never had them not care.

      Besides, you may want to learn the difference between a traffic patrol officer and a detective.

      --
      Dacels Jewelers can't be trusted.
    3. Re:apathy in law enforcement by Radical+Rad · · Score: 1
      I could loose $4900 tomorrow and the FBI won't do jack shit. Some FBI nerd gets a scam email any moron would know not to answer, and they call out the swat teams. Faaaaantastic.

      I think you missed the point here. This con artist got caught. It is news because we can all take revenge on spammers vicariously through reading this. It feels better than the end of a bruce willis movie.

    4. Re:apathy in law enforcement by Anonymous Coward · · Score: 0

      A rip-off by an eBay merchant falls under the category of "buyer beware" - if you send someone money, you should have a damn good idea of who it is.

      On the other hand, this woman was trying to convince people that she was a large corporate entity (or even the government), and then coercing people to give her private financial data.

      The difference is clear. In the first case, people hope to be buying something and just sending out money. In the 2nd case, people think they're not spending anything, and in fact think they're protecting themselves... but they are being ripped off by a well orcestrated scam.

    5. Re:apathy in law enforcement by kfg · · Score: 1

      Let the buyer beware is a maxim of age old wisdom that applie in all business dealings of any kind. If someone asks you for money, beware.

      It is not a tenet of American law. Far from it. The tenet of American law is "Good faith," the exact opposite of let the buyer beware. Assumption of innocence until proven guilty, as it were, applied to civil matters, but the onus is not on the buyer to not get taken. Not getting taken is the legal assumption of the buyer.

      However doofey it is to leave the keys in the ignition of your car it is your car and your keys. You may do with them as you will. Anyone who sees your keys in the ignition and takes your car is what we call "a thief."

      When one party violates good faith that is called "fraud." If the fraud comes to various dollar amounts than various forces of law and penalties come in to play.

      Failing to deliver promised goods when one has accepted payment for such and when one never intended to deliver such goods is fraud.

      Lying about a payment you don't deserve in order to recieve it is fraud.

      Both are "well orchestrated" scams. Both are equal in the eyes and ears of the law. Only the relative dollar amounts differentiate the two from that point on.

      KFG

    6. Re:apathy in law enforcement by Anonymous Coward · · Score: 0

      Yeah, but with that attitude, why would they give a shit about whether or not you are being scammed? If I was FBI and you got scammed, I sure as hell wouldn't want to deal with you. "Speed patrol" has more impact on public safety than your car or radio. They *know* that there will be people speeding, and just sit patiently to nab them. When your car gets keyed, all they can really do is keep an eye open hoping that maybe the person(s) responsible are dumb enough to come back. If they key every car on the block, though, or if it is an act of vandalism in progress, they usually act because there is a higher probability of "not wasting time." Yeah, it would suck to lose $4900 dollars. But it would suck a lot more to have the FBI spending most of their time going after "little" scams, given the proliferation of them. So who actually goes after them? Local law enforcement? Somebody does, just not the feds.

    7. Re:apathy in law enforcement by Anonymous Coward · · Score: 0

      It's like the local cops who don't give a shit if your laptop, your radio, etc were stolen and hundreds of dollars in damage done to your car. But, mind you, they've got all day to sit out on 'speed patrol'...

      It's not that they don't care, it's that there's nothing they can do about it. Someone nabs your laptop, takes it to the pawn shop, and sells it. At best, the police can get to the pawn shop before they sell it, so you get your laptop back and the shop owner goes to jail, but that involves an officer going to every pawn shop in a 20 mile radius and looking at every laptop on the off chance of finding yours. Very low return, and they still won't catch the theif.

      As for your 'speed patrol' guy, I wish there were more of them. Every day in this country there are over 100million people who flagrantly and willfully break the law, costing thousands of lives yearly and millions of economic damage. If the traffic laws got strictly enforced people might actually drive sanely, and I might not hate driving so much. Unfortunately, most cops won't bother to pull over someone who is only breaking a few traffic laws, because they have too much of a backlog of real work to do.

    8. Re:apathy in law enforcement by Anonnymous+Coward · · Score: 1

      Maybe there wouldn't be so many "little scams" if the people perpatrating them couldn't be as sure as they can now that they won't be caught and prosecuted. Food for thought.

    9. Re:apathy in law enforcement by Artifakt · · Score: 1

      The real cut off is higher than that 5,000 US$ limit. It costs the FBI about 15,000, on average, to persue a typical fraud case, and their internal auditing process pushes agents towards investigating cases that have a potential return, in fines and penalties, greater than that limit. This also applies to other departments, such as treasury, for the crimes they investigate, although the exact limit varies a bit. To tie this to another Slashdot favorite topic, now you know why the DCMA is so scary - the 150,000$ per violation limit on possible penalties means federal law enforcement will selectively investigate copyright violation ahead of wire fraud, mail fraud and even some extortion, evidence tampering or securities cases.

      --
      Who is John Cabal?
    10. Re:apathy in law enforcement by Anonymous Coward · · Score: 0

      Yeah, if you live in a upper class suburb, you'll have plenty of cops who are only there to smile at local drunk drivers and keep the negros out. They're happy to waste an hour or two filling out reports because it's something to do.

    11. Re:apathy in law enforcement by Anonymous Coward · · Score: 0

      Nobody cares that you didn't get your Beanie Baby.

    12. Re:apathy in law enforcement by phorm · · Score: 1

      Come to Canada, particularly BC. We're getting police enforcement cut, but an extra (at least) 100 officers coming into "traffic patrol" next year, coincidentally also when speednig fines are supposed to take a big jump.

  19. Logic 101... by MosesJones · · Score: 5, Insightful


    Actually what it teaches us is

    - Criminals don't wear stripes and sound like Cagney

    - For any scam the best approach is to target the largest user group... more people means more idiots

    - The FBI staff use personal email

    This is exactly what you should expect, the FBI aren't a mixed race of mutant beings, and large crimes can be commited by pretty much anyone.

    --
    An Eye for an Eye will make the whole world blind - Gandhi
    1. Re:Logic 101... by bstadil · · Score: 1
      Criminals don't wear stripes

      Notice the Stripe on the Hat

      --
      Help fight continental drift.
    2. Re:Logic 101... by kidlinux · · Score: 1

      Why is everyone associating the FBI agent's email use with the FBI??

      "An Ohio woman whose credit card fraud schemes began to unravel when she unwittingly spammed an off-duty FBI computer crime agent..."
      The article mentions the agent as being off duty. So first of all, this AOL email account is personal, and secondly, if this person wants internet access at home, they've got to get it somewhere, and why not AOL, it's a huge ISP.

      "The FBI uses AOL, oh shit!" The FBI doesn't use AOL. People who happen to work for FBI might use AOL for personal internet access, but what the fuck does that have to do with the FBI??

      However, come to think of it, the FBI having some AOL accounts as honeypots might not be a bad idea. AOL users are a good (and large) target for scams, so the FBI computer crime dept. might catch a few of them.

      --
      -kidlinux.
    3. Re:Logic 101... by Anonymous Coward · · Score: 0

      the FBI aren't a mixed race of mutant beings

      They're not? I suddenly feel so stupid wearing this tinfoil hat. Oh well, better safe than sorry!

    4. Re:Logic 101... by Doctor+Crocodile · · Score: 1

      - Criminals don't wear stripes and sound like Cagney

      Not even Cagney & Lacey?....

  20. There are so many... by MisanthropicProggram · · Score: 5, Informative
    Let's see:

    I once received an email with a link that said that I needed to "update" my eBay account with a new: credit card #, my SSN, DOB. The funny thing is I never had an eBay account - ever.

    I was at a hotel in Houston one time and I wanted to use my calling card to call home. After following the directions listed on the phone a few times, i was redirected to some telco that I've never heard of, and someone came on the phone, asked for the number I was calling and my calling card number. He then asked for my PIN. I said no way. He then told me that he couldn't make the call. I hung up.
    Later, at the airport, my card worked perfectly. I wish I got the name of the telco that was blocking access to my long distance company so I could have filed some sort of complaint with the FTC.
    Is it common practice for hotels to block access to your long distance provider so that you have to use their company for help that they charge you for?

    I've gotten so paranoid, I've repeatedly hung up on legitimate calls. It's unfortunate, but this shit is hurting legitimate businesses and making it harder for us consumers to know if we're being taken or not.

    --

    There is no spoon or sig.

    1. Re:There are so many... by eMartin · · Score: 4, Interesting

      After following the directions listed on the phone a few times, i was redirected to some telco that I've never heard of, and someone came on the phone, asked for the number I was calling and my calling card number.

      Maybe a scammer just put his own sticker on the phone when he had the room before you. I doubt that housekeeping checks for that kind of thing.

    2. Re:There are so many... by S.Lemmon · · Score: 1

      Ever wonder if maybe the person before you changed the instructions on the phone? It could be awhile before the hotel even noticed.

      Maybe it was an attempt to route you through one of those scam phone "services". I know there were several other scams that involved tricking you into dialing some special number first.

    3. Re:There are so many... by Anonymous Coward · · Score: 0

      I have heard of disreputable hotels putting Faraday shielding around bar areas so that mobile phones won't work, forcing you to use the payphones, which are turned up to extortionate rates. Of course, this may be simply an unintended consequence of using metal mesh covered with plaster to neaten up uneven walls.

    4. Re:There are so many... by Detritus · · Score: 1
      Is it common practice for hotels to block access to your long distance provider so that you have to use their company for help that they charge you for?

      Yes, and it's illegal.

      Complaints should be filed with the FCC.

      --
      Mea navis aericumbens anguillis abundat
    5. Re:There are so many... by Anonymous Coward · · Score: 0

      That's not such a bad idea (save the part about extortionate payphone charges). Maybe restaurants could do the same?

    6. Re:There are so many... by Elbow+Macaroni · · Score: 1
      I had a similar thing happen to me, with the cell phones, some other company was attaching themselves into the middle of the signals and taking over legitimate business. And where is the government and law enforcement? Are they just too stupid to catch these criminals or what?

      I meant they can't even control Verisign or the crap that goes on with domain names. But boy if you smoke a little marijuana they'll put you away for 10 years. That's real intelligent.

      --
      -------------------------------------
      Technically, we are beyond survival.
  21. Social Engineering by Detritus · · Score: 2, Informative
    Don't be so sure that you would never fall for such an obvious scam.

    I received an email that was purportedly from Citibank, saying that I had received a money transfer. It was slick. The scammer had gone to a great deal of trouble to make it look like a real email from Citibank. The associated web site also looked real.

    What tipped me off? The email asked for too much information, the scammer was being greedy. Examining the HTML source of the email revealed that the web site was in the wrong domain for Citibank.

    --
    Mea navis aericumbens anguillis abundat
    1. Re:Social Engineering by Anonymous Coward · · Score: 0

      What tipped me off? The email asked for too much information, the scammer was being greedy. Examining the HTML source of the email revealed that the web site was in the wrong domain for Citibank.

      Yep, http://www.geocities.com/MyCitibankConJob is the wrong domain for Citibank.

    2. Re:Social Engineering by LearnToSpell · · Score: 1

      I got one of those too, but I had my doubts when the email came from a dial-up in Germany. Oh, and my lack of a Citibank account.

    3. Re:Social Engineering by Detritus · · Score: 2, Informative
      According to Alex Salkever in BusinessWeek Online:
      A QUESTION OF JUDGMENT. In a study conducted earlier this year by MailFrontier, 40% of people who read a fraudulent Citibank e-mail were fooled into thinking it was real. "What we found is that the fraudsters have gotten smarter over time. It's very similar to spammers," says Budman.
      --
      Mea navis aericumbens anguillis abundat
    4. Re:Social Engineering by techt · · Score: 5, Informative

      No. The ones I've seen use this:
      http://www.myrealbankname.com:whatever@real IPaddre ssindotlessformat/

      The "www.myrealbankname.com:whatever" before the @ is not a URL, but a value sent to the real site which is denoted by the "realIPaddressindotlessformat".

      For example, cut and paste this into your browser:

      http://www.kuro5hin.org:section@1109654166/

      The above URL doesn't take you to Kuro5hin, it takes you to the Slashdot main page.

    5. Re:Social Engineering by ymgve · · Score: 1

      Opera warns you every time you try to access a site with a username in the URL - does Mozilla do this too? I know for certain IE doesn't ;)

    6. Re:Social Engineering by techt · · Score: 1

      As far as I'm aware, Mozilla doesn't do this. It is a good idea, though.

    7. Re:Social Engineering by marnanel · · Score: 3, Informative

      Opera warns you every time you try to access a site with a username in the URL - does Mozilla do this too?

      No, it doesn't yet. I agree-- it should. Mozilla bug 122445 tracks this issue. I suggest voting for it.

      (Copy and paste
      http://bugzilla.mozilla.org/show_bug.cgi?id=122445
      into your browser to go there; Bugzilla doesn't allow links straight from slashdot.)

      --
      GROGGS: alive and well and living in
    8. Re:Social Engineering by Reziac · · Score: 1

      How do you determine the dotless number?
      Wondering if it would work to protect email addresses on websites from harvesting, when you can't obfucate them beyond what any browser can see (due to the client base you need to let contact you not having a technical clue).

      --
      ~REZ~ #43301. Who'd fake being me anyway?
    9. Re:Social Engineering by Random832 · · Score: 1

      given the IP a.b.c.d

      the dotless form is a*16777216 + b*65536 + c*256 + d

      --
      We've secretly replaced Slashdot with new Folgers Crystals - let's see if it notices.
    10. Re:Social Engineering by techt · · Score: 1

      How do you determine the dotless number?

      The dot-less number is a 32-bit unsigned integer.

      Slashdot's IP is 66.35.250.150. Each number is an 8-bit unsigned integer. In binary it would be:

      01000010.00100011.11111010.10010110

      remove the decimals

      01000010001000111111101010010110

      convert binary to base 10

      1109654166 is the answer.

      If you need to do it on paper, this way may be easier:

      66.35.250.150 =
      (66 * (256^3)) + (35 * (256^2)) + (250 * 256) + 150 =
      1109654166

      Wondering if it would work to protect email addresses on websites from harvesting, when you can't obfucate them beyond what any browser can see (due to the client base you need to let contact you not having a technical clue).

      While I don't know for certain since I don't know how the email harvester spiders work, I would think it probably wouldn't make a difference. You may try to use a disposable email address service like Sneakemail and generate a new contact address each time the older one gets too much spam.

    11. Re:Social Engineering by lpret · · Score: 1
      I have to comment and say that I use Opera and it popped up with a message box saying that I was connecting to the address 1109654166 using the Username kuro5hin.org and was I sure of that?

      Security in a browser does happen...

      --
      This is my digital signature. 10011011001
    12. Re:Social Engineering by kcb93x · · Score: 1

      I googled for:

      Dotless IP address -"Internet Explorer" (because IE came up too many times for the vulnerability in the first one)

      and got:
      http://www.google.com/search?num=100&hl=en&l r=lang _en&ie=UTF-8&oe=utf-8&q=Dotless+IP+address+-%22Int ernet+Explorer%22&btnG=Google+Search

      (Note- check for the blank space(s) /. added to the above)

      The following is taken from:

      http://www.beesky.com/newsite/howto_dotless_ip.h tm l

      How to make dotless IP URL's to amuse your friends

      Web URL's like www.microsoft.com are merely alphanumeric representations of IP octets. What I mean is that for every hostname, like beesky.com, there is a corresponding ip address. In our case it is 198.88.0.2. A dotless IP is a 32-bit number (http://3327655938) that the IP stack resolves into its equivalent dotted IP format (198.88.0.2).

      The dotless IP address, also called the "decimal address", can be easily calculated with this formula:

      decimal=aaa*16777216+bbb*65536+ccc*256+ddd

      If you get a url like http://3327655938/?key=5?index=beesky.rocks.com, just stick it in the first set of numbers, in this case 3327655938, into this form below to find out who it's really from.

      --
      There are 4 boxes to use in the defense of liberty: soap, ballot, jury, ammo. Use in that order. Starting now.
    13. Re:Social Engineering by badzilla · · Score: 2, Informative

      If you're bad at math and need a quick way to turn a numeric URL into a DNS-named one there is a handy tool ("decipher") at www.samspade.org

      --
      "Don't belong. Never join. Think for yourself. Peace." V.Stone, Microsoft Corporation
    14. Re:Social Engineering by WWWWolf · · Score: 1
      How do you determine the dotless number?

      Someone already posted the theoretical solution. Here's the practical solution:

      perl -MSocket -e "print unpack("N",inet_aton('slashdot.org'));"

      Wondering if it would work to protect email addresses on websites from harvesting,

      Uh, please don't. It's more pain than it's worth - You don't see many people using IP addresses for E-mail, don't you? There may be reasons for that.

    15. Re:Social Engineering by Reziac · · Score: 1

      Cool, thanks for the info!

      It even looks logical, now that I see it written out. :)

      --
      ~REZ~ #43301. Who'd fake being me anyway?
    16. Re:Social Engineering by Reziac · · Score: 1

      Aha, now I understand better. The converter would make the grunt work easier, yet :)

      AFAIK the harvesters look for any string in nameAThostDOT* format, so I'd think anything to confuse that would help. I know most have gotten smart enough to work around additions like "nospam". So far I haven't found a *reliable* substitution for the AT sign that works at the *docsource* level (bots don't parse just the visibles!)

      I can't use a disposable because I have clients that may be years between contacts and the old email has still got to work, and since I get every people using which browser, js obfuscation is no good either (aside from that I hate js). Even more, I resent being pushed out of my own namespace by spammers, and changing my email is the point where I dig in my heels -- kinda like, if someone steals your identity, should YOU have to change your name??

      Hmm, there's a thought... wonder if forging someone else's email address as part of a spam header could be bent into identity theft for the criminal courts? :D

      --
      ~REZ~ #43301. Who'd fake being me anyway?
    17. Re:Social Engineering by Reziac · · Score: 1

      Ya know, I'd completely forgotten about samspade.org -- thanks for the reminder!

      --
      ~REZ~ #43301. Who'd fake being me anyway?
    18. Re:Social Engineering by Reziac · · Score: 1

      Thanks! I see you've encountered the evil slashdot space before as well :)

      [reads beesky info] Oh -- some people might have applied a patch to cure the behaviour?! In that case, not useful for a mailto since it'll fail with some systems. :( Oh well, it was worth a thought.

      However, I'm glad I asked, since from all these replies I've actually learned useful stuff.

      --
      ~REZ~ #43301. Who'd fake being me anyway?
    19. Re:Social Engineering by Reziac · · Score: 1

      [laughing] Ah, a perl junkie :) Interesting, tho -- archived for reference.

      As to email addresses, per info someone else posted a link to, seems some folk might have applied a patch that disables dotless lookup, so no good to me anyway -- I want to find something that works in EVERY client from the most braindead antique to the latest and greatest, since that's the gamut my clients use, and I can't be locking anyone out due to "minimum technical requirements".

      Tho IS there some reason why IP addresses are not used for mail? I've seen it done in spam, tho that doesn't exactly count as a legit use.

      --
      ~REZ~ #43301. Who'd fake being me anyway?
    20. Re:Social Engineering by Anonymous Coward · · Score: 0

      Doesn't work with Internet Explorer 6. Haven't tested other versions.

    21. Re:Social Engineering by WuphonsReach · · Score: 1

      Possibly under a fraud law?

      Joe-jobs and domain forging are at least combatable via technology. It merely requires that the DNS system provide answers to the two following questions:

      1) Has this domain restricted which IPs are allowed to send e-mail on behalf of this domain?

      2) Is the IP address of the server that is currently talking to my SMTP server on that list?

      There are at least (4) proposals on the table currently (see my signature) for eliminating the ability to forge domains. It won't solve the spam problem, but it will at least put a serious dent in the problem.

      --
      Wolde you bothe eate your cake, and have your cake?
    22. Re:Social Engineering by Reziac · · Score: 1

      That's kinda what I was thinking, since identity theft boils down to fraud (you can CALL yourself anything you like, so long as there is no intent to defraud).

      Yeah, ISTM if email was merely confirmed as coming from where the header claims it does, a lot of the really obnoxious spam, and related thefts of services, would go away. ISTM if it's done right, it need not endanger anonymous remailers, either. I don't know enough about the technical side to make intelligent suggestions [g] but how about this: Merely confirm each individual hop in the chain -- but the next hop doesn't need to know anything about the previous hop; only that the immediately previous sender was the system it claimed to be.

      --
      ~REZ~ #43301. Who'd fake being me anyway?
    23. Re:Social Engineering by WWWWolf · · Score: 1
      Tho IS there some reason why IP addresses are not used for mail? I've seen it done in spam, tho that doesn't exactly count as a legit use.

      The same reason DNS is used in general: IP addresses are difficult to remember and they can change, while DNS names are easy to remember and can be made to point just about everywhere.

      And there's also the benefit of using MX records...

    24. Re:Social Engineering by Reziac · · Score: 1

      Oh, that's too obvious :) I was thinking only of the part of the mailto link that non-snoopy people don't see anyway. Problem being, yeah, who knows when ELN will up and change their mail servers, or if I'd hit a bad one (of the 18 or so, last I knew for sure), etc.

      What's the "benefit of using MX records" ?? (Getting out of my territory here :)

      --
      ~REZ~ #43301. Who'd fake being me anyway?
    25. Re:Social Engineering by WWWWolf · · Score: 1
      What's the "benefit of using MX records" ?? (Getting out of my territory here :)

      Mail for one domain can be handled by another. I don't know the specifics since I haven't looked at it that much, but it's probably something along the lines of "Mail for scienceguy@research.example.com is actually handled by mail.example.com".

    26. Re:Social Engineering by Reziac · · Score: 1

      Ah, okay, I know what you mean, even if I didn't know the acronym :)

      --
      ~REZ~ #43301. Who'd fake being me anyway?
  22. Bad argument by Anonymous Coward · · Score: 0
    I always get a chuckle about death penalty oppponents who use the irreversibility of the death penalty as an argument against it.

    It's not fundamentally different from any punishment - once you lock someone up for a period of time there is no way for that person to ever get that time back - even if they are innocent and later released and exonerated. They'll never get those years back, and that's just as irreversible as a death penalty. Likewise someone caned in Singapore - they can never be un-caned.

    1. Re:Bad argument by EvanED · · Score: 1

      But you can fix things for the future.

      You can't reverse all of the punishment, but you can reverse part of it.

    2. Re:Bad argument by Anonymous Coward · · Score: 0

      Like what saying "oh sorry bout that guess you were innocent after all!"

      Well the guy getting executed ALREADY KNOWS he's innocent, big consolation that is!

      Gee, after spending 25 years of my life in prison I know I am so happy to know that you figured out I was innocent! Thanks, cause I wasn't sure if i did it or not!

      blah.

    3. Re:Bad argument by EvanED · · Score: 1

      So in other words, if you were innocent, you wouldn't care if you were executed or put in jail for 25 years then released for the next 25 until your natural death?

    4. Re:Bad argument by Eccles · · Score: 1

      It's not fundamentally different from any punishment - once you lock someone up for a period of time there is no way for that person to ever get that time back - even if they are innocent and later released and exonerated.

      But you haven't lost everything. In Maryland, an man has been found innocent after 27 years in prison, and pardoned by the governor. He can now seek redress; a person in a similar situation received $45K per year of prison.

      Not wonderful, but it sure beats having the governor come to your grave and say "Oops!"...

      --
      Ooh, a sarcasm detector. Oh, that's a real useful invention.
    5. Re:Bad argument by Anonymous Coward · · Score: 0
      You can at least receive some compensation for the 25 years you've spent in prison.

      By comparison, with the Death Penalty, you can't. And current evidence suggests you're less likely to be cleared after conviction too, because nobody wants to admit they've killed the wrong person if it'll do no good to do so.

    6. Re:Bad argument by John+Courtland · · Score: 1

      Why would you? Have a great time getting any sort of real life started at the age of 50 or so. He might get a couple tens of thousands of dollars. Wow, big compensation. He's an OLD MAN now.

      They owe him half of a lifetime. He should never have to work, never have to worry. He paid the debt of a murderer, and now he's probably going to get shafted around until he dies.

      --
      Slashdot is proof that Sturgeon's Law applies to mankind.
    7. Re:Bad argument by hkmwbz · · Score: 1

      So he should have been executed for his own good? Wow, that is certainly a fresh look at capital punishment...

      --
      Clever signature text goes here.
    8. Re:Bad argument by John+Courtland · · Score: 1

      I would rather die than be locked away for 27.
      Especially for a crime I didn't commit.

      --
      Slashdot is proof that Sturgeon's Law applies to mankind.
    9. Re:Bad argument by hkmwbz · · Score: 1

      Good for you! But shouldn't this be up to you rather than the government? Maybe you would prefer to die, but not everyone thinks alike.

      --
      Clever signature text goes here.
    10. Re:Bad argument by John+Courtland · · Score: 1

      Not quite the point I was trying to make. I don't think he wanted to die, even though he was stuck somewhere for half a lifetime. But even though he is released, he isn't going to be compensated. I say that the punishment he recieved is the same as being put to death. At that point, it would be the same to me.

      --
      Slashdot is proof that Sturgeon's Law applies to mankind.
    11. Re:Bad argument by EvanED · · Score: 1

      And the point the parent was trying to make was that while it might be the same to *you*, you are probably in a very small minority. I, for instance, would *much* rather be released after time in prison than be put to death.

    12. Re:Bad argument by John+Courtland · · Score: 1

      I made the original point in the first place, so it's all just one big happy misunderstanding :)

      --
      Slashdot is proof that Sturgeon's Law applies to mankind.
  23. Re:hm by annielaurie · · Score: 2, Interesting

    Wanna bet?

    Read this. Be sure to read all the way to the end for fairly positive proof that the guilty party was, indeed, a woman. In fact, it was a woman-owned, woman-run, all-female spam gang.

    Regards,
    Anne

    --
    DUCT TAPE: The Election Supervisors' Secret Weapon
  24. amazing by Anonymous Coward · · Score: 0

    this is half troll half funny.

  25. it gets better by monkeySauce · · Score: 5, Informative

    The 22 year old guy she was working with thought he was breaking the law with a 20-something hottie instead of this 55 year old overweight felon from Akron. He must feel pretty stupid about now.
    this story has more detail

    1. Re:it gets better by lgftsa · · Score: 1

      From the linked article - Agents did learn that victims live all over the world, including three in Virginia Beach, one in Chesapeake and one in Newport News. None was identified in court.

      OK, everyone together(just the chorus):

      It's a small world after all
      It's a small world after all
      It's a small world after all
      It's a small, small world

  26. My sentiments exactly. by Anonymous Coward · · Score: 0

    If it hadn't been received by an agent, there would be nothing that an average citizen could do to the scammer. It is only because the scam target was an employee of the federal government that they were even able to make a case against that woman.

    The worst that anyone could do is to report them under state's anti-spam laws and get them fined them a couple of hundred $$ - which never gets collected because they never show up in court and it would cost more to collect than it's worth.

    Gee.. thanks American legal system!

    1. Re:My sentiments exactly. by Anonymous Coward · · Score: 0
      If it hadn't been received by an agent, there would be nothing that an average citizen could do to the scammer. It is only because the scam target was an employee of the federal government that they were even able to make a case against that woman.

      If that is the case, the logical thing to do is attempt to get as many FBI agents on spammer's lists as possible.

      How to get spammers to do this, I haven't a clue beyond posting email addresses similar to "fraud.agent7@fbi.gov" in as many public places as possible.

  27. Unfortunately it is the case by frovingslosh · · Score: 1
    The article makes it sound like she wouldn't have got caught if an FBI agent hadn't been a recepient of the email. I hope this isn't the case and that the FBI is taking a more pro-active attack on this kind of thing than what the article seems to say.

    The FBI clearly knows this kind of thing is going on, but they can't be bothered to do their job and protect US citizens (to be fair, they are too busy snooping on us and reading our private communications). Heck, you could have reported stuff like this and there would have been no follow-up at all. They only bother to go after someone like this when they piss them off and send the spam to an FBI agent.

    --
    I'm an American. I love this country and the freedoms that we used to have.
    1. Re:Unfortunately it is the case by GMontag · · Score: 2

      Same thoughts I had.

      I used to send crap like this to the FTC all of the time, but now I just send it to them if I accidentally open one instead of deleting. If I am using AOL I ureport the spam using the AOL utility. Does not seem to slow it down one bit.

  28. Re:Here is more info on her by monkeySauce · · Score: 2, Informative

    She appeared in federal court in Virginia but she is from Akron, Ohio so you're linking to someone else's contact info.

  29. [OT] More about spam by Anonymous Coward · · Score: 0

    I've found a nice article about spam methods. Actually, this grandma could be the attacker described in it.

  30. so it's only an issue if it's personal? by binarybum · · Score: 3, Insightful

    I don't get it. Is this all it takes to get spammers busted? Can I just forward the scams and spams I get to this guy and have all these people caught? Why did this only become an issue when it was a personal attack on someone in a position of power to do something about it. What about the rest of us, how can we fight back? And more importantly why isn't the FBI doing more to attack spammers other than when they're personally feeling the heat?

    --
    ôó
    1. Re:so it's only an issue if it's personal? by Patrik_AKA_RedX · · Score: 1

      You could try, but probably the spammer will sue you for redistributing its copyrighted material.

    2. Re:so it's only an issue if it's personal? by KillerHamster · · Score: 1

      Can I just forward the scams and spams I get to this guy and have all these people caught?

      Good idea. Let me know how that works.

  31. What's wrong with FBI having an AOL account!? by drkrool · · Score: 1

    Absolutely nothing! Maybe they have an account to monitor what happens on AOL.

    I don't know why /.ers freak out when they hear AOL.

    1. Re:What's wrong with FBI having an AOL account!? by Nintendork · · Score: 1
      "Maybe they have an account to monitor what happens on AOL."

      The FBI agent was off-duty.

      -Lucas

    2. Re:What's wrong with FBI having an AOL account!? by hypermike · · Score: 0

      Do you know what AOL is? cmon honestly - It stands for everything that is vial and evil. I Like M$ (ah shields the face) better than aol. heh

      --
    3. Re:What's wrong with FBI having an AOL account!? by drkrool · · Score: 1

      Your account doesn't go away when you are off duty. Maybe he was just checking his mail at home.

    4. Re:What's wrong with FBI having an AOL account!? by Catnapster · · Score: 1

      One more time: "AOL is the Special Olympics of ISPs".

      --
      The world can be wrong today for once.
  32. MOD PARENT DOWN! by Anonymous Coward · · Score: 0, Funny

    Your information conflicts with the dogma I have assimilated by reading slashdot. Your moderate response, in place of a knee-jerk over-reaction, has left me, angry, frustrated and impotent. FBI empolyes are evil, fly black helicopters powered by Microsoft and MSN, and are not to be treated with the even temperment I would expect of someone who didn't know me. As such, I must say you flamebait is not welcome, and will not be tolerated.

    1. Re:MOD PARENT DOWN! by Anonymous Coward · · Score: 0

      Idiot moderators. It's funny... it's a joke. Sigh you are SO stupid. Are you not ashamed of being so stupid?

  33. 55 year old woman going down? by Fubar411 · · Score: 1

    Hmmm, I think I have that spam around here somewhere. Not my thing though...

  34. just dumb luck... by Anonymous Coward · · Score: 0

    total luck that an FBI person received it and actually did anything about it...

    the community has been reporting tons of blatant phish scams over the last few years to ebay/paypal as well as the FBI, and neither entity ever did jack shite about it.

    1. Re:just dumb luck... by Anonymous Coward · · Score: 0

      Here's the answer....
      In .procmailrc...
      :0
      * ^X-Spam-Status: Yes
      ! fbiguy@aol.com


      Eh?

  35. Comment removed by account_deleted · · Score: 2, Informative

    Comment removed based on user account deletion

  36. But why.. by adeyadey · · Score: 2, Insightful

    does it take for a spammer to mail the FBI direct before they take action? Surely they must be aware of the volume of scam emails we *all* get, and be taking action anyway?

    Its like waiting for a police station to be burgled before the police take action..

    Some of these frauds are pretty blatent (penis enlargement pills etc), you dont need to be sherlock holmes to track them..

    --
    "You lied to me! There is a Swansea!"
    1. Re:But why.. by jpetts · · Score: 1

      Some of these frauds are pretty blatent (penis enlargement pills etc), you dont need to be sherlock holmes to track them..

      Are you saying Sherlock Holmes' little friend was really called Johnson, not Watson?

      --
      Call me old fashioned, but I like a dump to be as memorable as it is devastating - Bender
    2. Re:But why.. by Dhalka226 · · Score: 1

      does it take for a spammer to mail the FBI direct before they take action? Surely they must be aware of the volume of scam emails we *all* get, and be taking action anyway?

      Proof, probably. I believe I just read a few days ago that they caught (one of?) the people responsible for those Nigerian money scams, so it's not like they don't ever persue things first. But it's tricky on the Internet to track people down reliably. Somebody accused of bringing down computers in a shipping port was just accquited, saying that somebody had installed a trojan on his computer that did the job and which subsequently deleted itself. It's hard to prove otherwise.

    3. Re:But why.. by Anonymous Coward · · Score: 0

      I would think that if the spammer would actually sell anything, you would be able to get some of their details...Then again, do they actually get anyone buying enlargement pills or do they just like annoying us?

    4. Re:But why.. by rhyno46 · · Score: 1

      Come on...you know this isn't the only spam message this agent gets!

      I bet most agents get spam in their government mailboxes (unless the gov't uses something like www.postini.com).

  37. Oops... by Pan+T.+Hose · · Score: 5, Interesting

    I think everyone (not only "spammer") had such an "Oops" in her career. I remember when we counterattacked CIA agents scanning our network... I saw a host slowly and randomly syn/fin/null scanning (something like nmap --randomize_hosts -Tparanoid but with -sS, -sF and -sN changing randomly -- a custom patched nmap or something like that) our hosts, so I answered with directing a broadcast-magnified traffic to its class C (something like "smurf" but with custom tools using UDP and TCP as well as ICMP packets) to disable the offending host, having absolutely no idea that I saturated the backbone of ISP used by a CIA covert operation. Imagine my surprise when I saw agents knocking on my door... Fortunately after I described some of my techniques and explained to them that I am a security professional, not a cracker, they let me go but if I wasn't working for the government at that time I probably wouldn't write this now. I wonder what stories other slashdotters can tell about their biggest "Oops!"

    --
    Sincerely,
    Pan Tarhei Hosé, PhD.
    "Homo sum et cogito ergo odi profanum vulgus et libido."
    1. Re:Oops... by geekoid · · Score: 1

      let see, what did I do with the memo I was supposed to forward to the FBI, oh well, it can wait until Sept. 12th.

      --
      The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
    2. Re:Oops... by bluGill · · Score: 1

      You might suggest to them that next time you will be more careful - if you knew it was government snooping in your private network you would have called the newspaper. The CIA can't legally do this to any US citican, and no police force can do this type of invesitgation without a warrent. The so called patriot act doesn't give everything away.

      Of course this doesn't apply if you are in any other country, though you may have a different set of rights that would applly.

  38. smart lady by ratfynk · · Score: 1

    "Her scam targeted AOL users" nuf said

    --
    OH THE SHAME I fell off the wagon and use sigs again!
  39. Password Checker! by dolo666 · · Score: 4, Interesting

    You wanna know how gullable people are? As a joke last year, I coded a little password checking program, at my site. Users could check their password against a list of a million common English words, to see if their passwords were secure. There was a database with a million words in it, and each time someone put in their password, the site would tell them if it was in the list. It would also tell them that if they are stupid enough to give out the password to just anyone, then it's certainly not secure!

    People would show up and type in something that looked like a real password, and then type in another password as a message to me -- along the lines of Fuck You on a Silver Platter, Asshole.

    Hackinthebox.org posted the site and a pile of gullable flies* showed up to check their passwords. I'm guessing people from HiB would send the site to other unsuspecting people, as a joke. Thing is, eventually some pretty scared people were emailing me. I took it down after while. It was getting to be more annoying than fun.

    There is always someone out there who is greedy or scared enough to be scammed online -- it's just sad when it happens to someone you know.

    * flies: a fly is someone who gets stuck in the web, and a spider is someone who owns it.

    1. Re:Password Checker! by rawg · · Score: 1

      That's nothing. I wrote a pop up window that looked like a windows dialog. It said something about you were disconnected, please type in your username and password to continue. I would log all the usernames and passwords to a database with their IP address. I was getting about 10 a week.

      People are really stupid.

      --
      The above is not worth reading.
    2. Re:Password Checker! by Anonymous Coward · · Score: 2, Insightful

      People are really stupid.

      And some are dickheads who abuse a little bit of programming knowledge. Oh, what a wonderful world!

    3. Re:Password Checker! by strike2867 · · Score: 1

      Whats the point of knowing programming and having an IQ higher than room temperature if you cant abuse it?

      --

      Vote for new mod!!! Score:-2,Imbecile
    4. Re:Password Checker! by Aliencow · · Score: 1

      On my site I had a fake Hotmail recovery page that I supposedly "grabbed from hotmail.com and saved just before they removed it"...

      It had the style of a Hotmail page, and you had to enter "your" Hotmail account address, then another address to get the password emailed to... then the script would email the hotmail guy saying "Some bitch at blabla@email.com tried to steal your password.." .. and I had so many freaking hits.

    5. Re:Password Checker! by weave · · Score: 1
      People enter their passwords into other sites all the time. Basically, enter your email address and password and we'll collect your pop mail for you.

      All you have to do is set up a free webmail service and starting collecting the info and seem legit.

      Even if the site operators (and their sys admins) are legit and honest, you have to wonder if they encrypt that data and protect it. Even if encrypted, it still has to have a way to decrypt it to send it over the wire (almost always in plain text) to some other site's pop server.

    6. Re:Password Checker! by herrvinny · · Score: 1

      Cool. Could I get a copy of that million word db?

    7. Re:Password Checker! by dolo666 · · Score: 1

      I may post it sometime. I'll msg you if I do.

  40. Nice of you to smear a dozen unrelated Helen Carrs by Anonymous Coward · · Score: 0

    Good work, inspector. None of us could have Googled up a bunch of unrelated people ourselves.

  41. I don't think we should prosecute these people by TLouden · · Score: 1

    They help to get rid of the idiots that fall for that shit. Let them improve our spicies.

    --
    -Tim Louden
    1. Re:I don't think we should prosecute these people by zerOnIne · · Score: 1

      i still think that Curry is amonth the greatest of our spicies.

      --
      09
    2. Re:I don't think we should prosecute these people by Anonymous Coward · · Score: 0

      > They help to get rid of the idiots that fall for that shit. Let them improve our spicies.

      Thanks, but my species is doing just fine - how's yours (homo sapiens nospellcheckians)

    3. Re:I don't think we should prosecute these people by snarkh · · Score: 2, Insightful
      Your judgement is completely immature.
      I know some extremely intelligent people who fell for things like that.


      It is not about how smart you are, rather it is
      whether you choose to belive certain things or have the experience to tell the scam from the real thing.

    4. Re:I don't think we should prosecute these people by Anonymous Coward · · Score: 0

      Yeah, my spices are kinda bland as of late too. Weird.

  42. Fraud-ian slip by neirboj · · Score: 2, Funny

    "Entering Fraudulent information is against the law. If done so on this form you are now hereby notified that AOL will persecute, fine, and charge anybody trying to commit fraud with our accounts.

    persecute:

    1. To oppress or harass with ill-treatment, especially because of race, religion, gender, sexual orientation, or beliefs.
    2. To annoy persistently; bother.
  43. Old scam... by Anonymous Coward · · Score: 0

    This lady should have been more original... she copied her scam straight of the net: Results on google

  44. Re:Captain's Log: My Anus is too Fucking Tight by Anonymous Coward · · Score: 0

    I would like to remind you that this foul and insane troll is just acting according to the rights he was given in the U.S. constitution.

    I say that the amendments are really good regardless of what the government says.

    And the amendments are:

    Bill of Rights
    Amendment I

    Congress shall make no law respecting an establishment of religion, or prohibiting the free exercise thereof; or abridging the freedom of speech, or of the press; or the right of the people peaceably to assemble, and to petition the government for a redress of grievances.

    Amendment II

    A well regulated militia, being necessary to the security of a free state, the right of the people to keep and bear arms, shall not be infringed.

    Amendment III

    No soldier shall, in time of peace be quartered in any house, without the consent of the owner, nor in time of war, but in a manner to be prescribed by law.

    Amendment IV

    The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no warrants shall issue, but upon probable cause, supported by oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.

    Amendment V

    No person shall be held to answer for a capital, or otherwise infamous crime, unless on a presentment or indictment of a grand jury, except in cases arising in the land or naval forces, or in the militia, when in actual service in time of war or public danger; nor shall any person be subject for the same offense to be twice put in jeopardy of life or limb; nor shall be compelled in any criminal case to be a witness against himself, nor be deprived of life, liberty, or property, without due process of law; nor shall private property be taken for public use, without just compensation.

    Amendment VI

    In all criminal prosecutions, the accused shall enjoy the right to a speedy and public trial, by an impartial jury of the state and district wherein the crime shall have been committed, which district shall have been previously ascertained by law, and to be informed of the nature and cause of the accusation; to be confronted with the witnesses against him; to have compulsory process for obtaining witnesses in his favor, and to have the assistance of counsel for his defense.

    Amendment VII

    In suits at common law, where the value in controversy shall exceed twenty dollars, the right of trial by jury shall be preserved, and no fact tried by a jury, shall be otherwise reexamined in any court of the United States, than according to the rules of the common law.

    Amendment VIII

    Excessive bail shall not be required, nor excessive fines imposed, nor cruel and unusual punishments inflicted.

    Amendment IX

    The enumeration in the Constitution, of certain rights, shall not be construed to deny or disparage others retained by the people.

    Amendment X

    The powers not delegated to the United States by the Constitution, nor prohibited by it to the states, are reserved to the states respectively, or to the people.

  45. *bzzzzt* by devphil · · Score: 4, Informative


    I hear you on the FBI thing. But consider: somewhere a just-not-worth-the-taxpayer's-money line has to be drawn. The FBI is seriously understaffed. (Go figure. The technologically astute are too proud to work for a measly $35K FBI salary, investigating tech crimes. Nooooo, gotta be making glamourous six-digit salaries on high-visibility programming projects.) But anyhow, the reason I'm posting is...

    It's like the local cops who don't give a shit if your laptop, your radio, etc were stolen and hundreds of dollars in damage done to your car. But, mind you, they've got all day to sit out on 'speed patrol'...

    Unless you live in Andy Griffith Town, the officers who sit on speed trap duty are not the same ones who investigate theft. Different division, different rules, different salaries, therefore a different allocation of officers/resources/time/budget.

    A traffic cop "sitting all day" on watch costs less than an investigating agent spending even half a day looking for stolen laptops chock full o' pr0n. It's harder to hire investigative officers and detectives, it's more expensive to train them and pay them.

    --
    You cannot apply a technological solution to a sociological problem. (Edwards' Law)
    1. Re:*bzzzzt* by SIGBUS · · Score: 1
      The technologically astute are too proud to work for a measly $35K FBI salary, investigating tech crimes.

      I wonder how many people are out there who would love to do so, but don't want to end up being called upon to enforce laws they consider unjust, like the DMCA, laws against recreational drugs, etc.

      For that matter, how many are turned off by the possiblility of being used as political enforcers rather than law enforcers?

      --
      Oh, no! You have walked into the slavering fangs of a lurking grue!
    2. Re:*bzzzzt* by Anonymous Coward · · Score: 0

      The FBI's enterance requirements are rather stringent for the salary offered. As for the military -- if they needed technical assets that badly, they'd make allowances. $35K a year I'd accept if I were doing something useful. They're not interested. End of story.

    3. Re:*bzzzzt* by Mr.+Droopy+Drawers · · Score: 1

      Sure pal, I'll bet there's people out there both qualified and willing to do that job for $35K.

      Maybe you've noticed, the RIAA and MPAA lawsuits have been civil, not criminal, cases. These companies aren't in it for people to go to jail. They want $$.

      FBI tech engineers are going after the hackers breaking into systems and are investigating cases such as this. You'll notice they started investigating this case more than two years ago.

      --

      To Copy from One is Plagiarism; To Copy from Many is Research.

    4. Re:*bzzzzt* by weave · · Score: 1
      A traffic cop "sitting all day" on watch costs less than an investigating agent ...

      It'd be nice if these traffic cops could instead patrol some areas and catch someone in the act or at least prevent crime through high visibility.

      The only time a police car cruises through my neighborhood is when it's responding to a call.

    5. Re:*bzzzzt* by Niet3sche · · Score: 1

      Actually, most FBI folks are college graduates. This means that they're entitled to a GS-7 rating pretty much right off the bat. Also, if they go the Special Agent way (e.g. physical/mental/visual/auditory acuity testing, and carrying a firearm), that'll pump them up and put them in line for even higher GS pay grade designations. Consider:
      SysAdmin: $??? If you can get work, I've seen anything from $28K/year up.
      NetAdmin: $???
      Programmer I: $50K/year ... for ever. If you don't get laid off next Thursday.
      FBI Agent (GS7): $35,158 for the first year, terminating in $45,706 after year 10.
      FBI Special Agent (GS10, say): $47,360/year 1; $61,570/year 10.

      Now ... let's consider this: say that you're good at what you do, and your section decides that you need a cybersquad ... let's say this happens 5 years in:

      Year1: GS7
      $35158
      Year2: GS8
      $38937
      Year3: GS8
      $40235
      Year4: GS9
      $43006
      Year5: GS9
      $44440
      Year6: GS10 (they promote you to lead the squad)
      $47360
      Year7: GS10
      $48939
      Year8: GS11 (you get off your butt and get a MS)
      $52035
      Year9: GS11
      $53770
      Year10: GS12
      $62366
      Year11: GS12
      $64445
      Year12: GS12
      $66524
      Year13: GS12
      $68603
      Year14: GS12
      $70682
      Year15: GS12
      $72761
      Year16: GS12
      $74840
      Year17: GS13
      $74163
      Year18: GS13
      $76635
      Year19: GS13
      $79108
      Year20: GS14
      $87639

      Then you're free to do whatever you want; you've got a government pension at this point. You also have job security and so on. Maybe people WON'T want to work at the FBI for $35K/year, but I was looking at the FS paygrade (for a Network Security Officer / Foreign Service) and they were STARTING out at $56K/year or so. Also, if you're good in the FBI, it is my impression (if you have clued-in people above you) that you can rack up a nice living for yourself - to the tune of taking an appointment directly at a GS13 grade ($74,163 base) out-of-the-box.

      Everything listed here is the BASE appointment pay. And, of course, don't forget the simple truth these days: it may be the case that a person is choosing between taking a "measly" $35K/year ... and $0/year. ;)

      Head here for the actual pay grad table:
      http://www.opm.gov/oca/03tables/html/sf.as p?

    6. Re:*bzzzzt* by oh · · Score: 2, Insightful
      I hear you on the FBI thing. But consider: somewhere a just-not-worth-the-taxpayer's-money line has to be drawn. The FBI is seriously understaffed

      But how do you cost a crime? If you lose $500 from a stolen Credit Card, well, it's hard to justify a months worth of police time to track down the cuplrit.

      But if say 1,000 people were each defrauded of $500, that half a million dollars obtained illegaly. But each complaint is only $500, too small to be investigated.

      Makes you think, doesn't it.

      --
      Democracy isn't about no one telling you what to do. It's about everyone telling you what to do.
  46. They have geeks too! by mabhatter654 · · Score: 1
    The FBI has "geeks" and like many other geeks in the world just aren't deemed "fit" to talk to outside people! That's what the "lower" scoring field agents are for...duh. It's all about the food chain people.


    That said, even FBI people get to go home sometimes [and contrary to /. opinion they aren't all hot-n-horney doctors or 1-900 addicts] and some of them probably even use AOL. This spammer just mailed the WRONG person. but you're right, normal FBI guys wouldn't have even noticed that the spam was a scam. or that it rhymes!

  47. Originally a Canadian scam by Anonymous Coward · · Score: 2, Insightful

    The lady should have modified the scam a little bit, because it looks like the original scam was against Sympatico users in Canada. That explains the SIN. More reading

  48. conversation with my credit card company by 3ryon · · Score: 4, Interesting

    me: I've received 3 scam e-mails today which are trying to get me to give up my credit card number. Do you have a special card number I can give them that will set off an alert when someone attempts to use it, so that you can apprehend these people?

    CC Company: No, but that sounds like a great idea.

    me: Yes. Now do something about it.

    What do you think the odds are that the idea ever got past the person I talked to on the phone?

    1. Re:conversation with my credit card company by SnprBoB86 · · Score: 1

      That is a nice idea, but problem is that obnoxious people will often enter the card number for legitimate sites just to give them a hard time.

      --
      http://brandonbloom.name
    2. Re:conversation with my credit card company by geekoid · · Score: 2, Insightful

      haha, I was talking to an Executive ofr a CC company at a financial event and suggested the same thing. He thought it was a good Idea to. that was 9 years ago.

      based on that, I'd say the odds are pretty damn slim.

      --
      The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
    3. Re:conversation with my credit card company by Reziac · · Score: 2, Insightful

      Actually, there are poison numbers in some credit card databases, that if are used, will redflag that as being stolen-card activity. I don't recall the details, but this was used back in the era when they mailed blacklists to merchants, who then had to manually check your card against it before they were allowed to take it. (1970s-80s)

      The problem with the general public having its own poison number for inputting into scam forms, is that someone with a grudge could input said number into legit forms, and cause all manner of legal havoc.

      --
      ~REZ~ #43301. Who'd fake being me anyway?
    4. Re:conversation with my credit card company by Kashif+Shaikh · · Score: 1

      You could do something:

      1) Apply for a new credit card(you don't wanna do this with your existing CC)
      2) Once you receive your CC and have activated it, report that you lost your CC after some time.
      3) Your CC Company will mark your old CC as lost/stolen(they take this issue very seriously and will ensure your CC is marked invalid).
      4) Give this the now 'stolen' CC number to email scammers...an include the three digit security number on the back.

      Now its upto the CC company to track fraudulent CC use. Don't know what the CC company will do if they do find their hitman.

    5. Re:conversation with my credit card company by Skuld-Chan · · Score: 2, Informative

      Do you realize that the person you talked to is probably a wage slave working in an outsourcing company you may have never heard of in a country you've never been too? In most cases the agent you talked to probably had no way of actually communicating that request with the actual company they represent.

      I work in such a company - while I don't work on a financial contract there are several in the office I'm in for banks everyone of you has heard of.

      In many countries they don't have as many privacy laws as the US does. Also some call centers are operated out of prisons (search google for twa and prison sometime). Definately something to think about before your company outsources ehh? Think about the potential for abuse. I'm an honest person - but I know for a fact I could collect well over 32-50 valid email addresses/credit cards and phone numbers per day if I wasn't.

    6. Re:conversation with my credit card company by Anonymous Coward · · Score: 0

      I've saved old credit cards from closed accounts so that I have credit card numbers to use in test when setting up shopping carts. When I get scams I always respond to them and enter these invalid numbers, mostly to see how they have set things up and to judge how real they seem. I especially like the ones with typos in them tht are supposed to come from companies like Citibank.

    7. Re:conversation with my credit card company by sn00ker · · Score: 2, Insightful
      In many countries they don't have as many privacy laws as the US does.
      The US has privacy laws? You mean the ones that allow companies to sell the information they collect on you, without your permission? And the ones that have no requirement for companies to protect said information against theft by outside agencies?
      Yes, those're mighty impressive laws.

      If you want to see privacy law, try looking at New Zealand's Privacy Act, or some of the European legislation. The US may as well not bother pretending they have any privacy legislation, because all it does is lull people into a false sense of security.

      --
      "God, root, what is difference?" - Pitr, userfriendly
    8. Re:conversation with my credit card company by Skuld-Chan · · Score: 1

      In the US we can at least sue said companies for privacy violaitons. I wonder what would happen if a New Zealand or US company outsourced to a company in some south pacific island who was also turning around and selling that information to spammers, and telemarketing companies?

  49. Mod up by Anonymous Coward · · Score: 0

    Parent has a nice sense of humor

    1. Re:Mod up by kfg · · Score: 1

      But he needs an editor, or at least a nap.

      KFG

  50. Re:disgusting racist shit by Anonymous Coward · · Score: 0

    Speaking as a white, university-educated, straight male, middle-classed westerner liberal, fuck you.

  51. businesses cause these problems by treat · · Score: 1

    By providing no way to authenticate themselves in a secure manner and by contacting their customers asking for sensitive information. Happens to me all the time. I never got a scam attempt that was even remotely plausible.

    On some occasions I have said I would call back so that I would be sure of their identity, and they get upset. (Yes, from a legitimate business calling for a legitimate reason).

  52. Why must society slow evolution? by SnprBoB86 · · Score: 2, Funny

    Caveman eats poisen berries, caveman dies. Friends of said caveman discover berries were to blame for death, note that no one should ever eat the berries. Another caveman comes along, fails to read the large warning signs posted outside the forest. He eats the berries and dies. Original caveman's friends laugh. The End If you ask me, such obvious scams shouldn't be shut down. Instead they should be allowed to eliminate societies stupider members. -SniperBoB-

    --
    http://brandonbloom.name
    1. Re:Why must society slow evolution? by geekoid · · Score: 1

      So I guess when you go buy a car, they can lie to you all they want, and if your ignorant, it's your own damn fault?

      --
      The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
    2. Re:Why must society slow evolution? by EinarH · · Score: 1

      Funny, but you forgot about the other side of the story.
      Some years later a evil caveman starts his "sell non-working stone stone axe" scam. Victims of the scam rise up against the life treathening sales practise and use real stone-axes to chop up scam-caveman.

      --

      Melius mori in libertate quam vivere in servitute.

    3. Re:Why must society slow evolution? by strike2867 · · Score: 1

      Unfortuantely this doesnt eliminate societies stupider members, the Darwin Awards do.

      --

      Vote for new mod!!! Score:-2,Imbecile
    4. Re:Why must society slow evolution? by Anonymous Coward · · Score: 0

      "So I guess when you go buy a car, they can lie to you all they want, and if you're ignorant, it's your own damn fault?"

      Well, yes, to a certain degree that is true.

      There are points where they must not misrepresent certain facts, and most of them deal with the ink on the paper of the finance agreement. There are rules against downright fraud, but there's a high standard of evidence if you want to claim fraud. Up until becoming a victim of fraud, it is the consumer's responsibility to understand the claims being made and dispute them if necessary.

      It shocks me that people don't actually read the contract. Here they have a document that binds them to terms they don't even understand, yet they sign it. Yes it would take a few hours to read, maybe. That's not a valid reason for not reading it before signing. Yes it's worded so as to confuse the customer, and probably should be interpreted by a lawyer first. That's still not a good reason for not signing or running it past a lawyer that you know trust. Don't know a lawyer you can trust? That's not a good reason, that still makes it your fault ultimately.

      People sign car deals for emotional reasons, sometimes out of desperation. Generally speaking, if it's not on the paper you signed, it doesn't exist. It's going to be hard for you to prove the salesman lied to you if he has a signed and notarized document that says you agreed he did not.

  53. Script kiddies by ElliotLee · · Score: 0, Troll

    A bit surprising that a 55-year-old woman knows how to use a computer.

    1. Re:Script kiddies by Anonymous Coward · · Score: 0

      Elliot, when did you first notice your problem with stereotypes and sexism?

  54. Um, Shouldn't he have got this ON THE JOB by superultra · · Score: 1

    So, the obvious question is: why can't they catch these people on-duty? Why does it take a spam email directly to an FBI agent to get action?

    1. Re:Um, Shouldn't he have got this ON THE JOB by jd_esguerra · · Score: 1
      Why does it take a spam email directly to an FBI agent to get action?

      Because there is a lot of crime to choose from. Hell, if you have to pick one, why not pick the one that irritates you the most.

  55. Aggregation vs.single-time losses by coyote-san · · Score: 1

    There's a serious disconnect in the priorities of law enforcement, but the correct response is far from clear.

    Consider three cases - a single loss of $10k, a hundred people losing $1k, or 10,000 people losing $100.

    There's no way the $100 loss would be investigated by any law enforcement agency, but it's the largest loss by far. Meanwhile the single loss of $10k is the smallest aggregate loss by far, but most people are going to really feel that loss while the $100 loss is usually (but not always) easily absorbed.

    Does this mean that the $100 loss should get highest priority? I would say not... but then again a single complaint may be the tip of the iceberg on losses affecting many people.

    There's no easy answer... but ignoring the cumulative loss or the coarsening effects on society on certain offenses (e.g., how my anger at clearly fradulent spam has colored my perception of ALL flyers, handbills, etc.) isn't the right answer either.

    --
    For every complex problem there is an answer that is clear, simple, and wrong. -- H L Mencken
  56. Spamers lack imagination. by arose · · Score: 3, Insightful

    Why email millions of inteligent people, when all you need to do is to set up an "Free IQ" test, that delivers results via email...

    --
    Analogies don't equal equalities, they are merely somewhat analogous.
    1. Re:Spamers lack imagination. by Skuld-Chan · · Score: 1

      Just like Scientology!

    2. Re:Spamers lack imagination. by Anonymous Coward · · Score: 0

      ...and then only sends the scams to those with sub-par IQs? :D

  57. DEATH! by FatSean · · Score: 1

    Nah...not death. But everyone she and her loser friends scammed should get a free punch on each of them. I'd knock a few teeth loose.

    --
    Blar.
    1. Re:DEATH! by jd_esguerra · · Score: 1
      I'd knock a few teeth loose.

      She's from Akron, OH. She probably doesn't have many teeth left. ;-)

    2. Re:DEATH! by Dimensio · · Score: 1

      What do you mean "Nah"? Yes, DEATH. I'm sick and tired of getting these e-mails, ESPECIALLY when I don't have an AOL account.

      These people are scum-sucking bottom-feeders. They live by exploiting the computer-illiterate and using theft of service and trespass to chattel to send out their attempted fraudulent communications. The only deterrant that will work is rigourously enforced capital punishment.

    3. Re:DEATH! by Anonymous Coward · · Score: 0
      Not only should we demand death for these people, but also for their families, their friends, the people they voted for in the election, and the doctors who have at some point been responsible for their good health.

      And their garbagemen too. And the salesperson who sold them the first computer they spammed from and all subsequent computers. And their ISPs.

      If that doesn't prove to be a big deterent, I don't know what will.

  58. I AGREE by rhizome · · Score: 1

    And another thing...why is she only having to plead guilty to *conspiracy*? It's ridiculous!

    --
    When I was a kid, we only had one Darth.
  59. wasnt just to aol users by Anonymous Coward · · Score: 1

    the spam wasn't just sent to aol users, i got one of these and I've never owned an aol account.

  60. Hah! by Solokron · · Score: 1

    You gotta love the fact she blatently had a field entitled "credit card limit". lol!

    --
    30% off web hosting. Coupon code "SLASHDOT".
    1. Re:Hah! by Anonymous Coward · · Score: 0

      Actually, some legitimate credit card forms (e.g. credit score repots) ask for a credit limit or balance to verify that you are the actual owner of the account.

  61. wouldn't work for long by KalvinB · · Score: 2, Interesting

    Eventually the scammers would figure out what numbers were red-flagged and not use them. All they would need is a CC account and they'd be right on top of the fake numbers just like every other customer.

    I got a very official looking e-mail from "PayPal" asking for all my information. Then I noticed the URL and that my password wasn't getting asteriked and typed in "howwouldyouliketogotoprison" in the entry fields and hit submit. I also e-mailed PayPal and within minutes the site was gone. I doubt I was the first to report it.

    Credit Card companies already have a solid way of dealing with crime. You watch your statement and if something is fishy you report it. What you have is a statement summary. The CC company has far more information at their disposal as companies that take cards have to submit lots of info to get an account.

    The CC company can get just as much information a week or two after the fact as they can "during" the committing of the crime. It's not like they can call up the place that's taking the card and say "hold that customer." Especially since most CC fraud is committed through on-line shops.

    Some moron years ago bought more e-mail space at Yahoo with my CC. I called up Yahoo and asked them to tell me if that purchase was applied to my account. No. And when was the last time I bought something on Yahoo for my account? "Over a year ago." And it was for hosting. I never had to pay a dime and the charges were reversed quickly. Since they bought themselves a personal account tracking down who did it would be trivial. And wouldn't even matter since it's non physical property. Yahoo just needed to cancel the account my CC was used on and everyone that matters is happy.

    I learned at Mervyn's that major credit card companies tend to eat the cost of the fraud. The customer gets their money back and the store the fraud occured at gets their money. Which actually works out better since now the CC company is the only entity taking on the crook. Instead of (not) being sued a million times by all the victims, they're sued and jailed for one massive crime.

    The employee probably thought it was a great idea, told his supervisor, and his supervisor walked him through their tried and true method and explained why your method was flawed.

    Ben

    1. Re:wouldn't work for long by Anonymous Coward · · Score: 0

      There could be an automatic system in which you would request a random number, and then it is automatically red-flagged. After a while it would just be bah-leeted.

    2. Re:wouldn't work for long by Anonymous Coward · · Score: 1, Informative
      I learned at Mervyn's that major credit card companies tend to eat the cost of the fraud.

      Not true. Merchants who accept bad cards tend to eat the cost of fraud. Credit card companies will charge anything where the billing address matches, but even if you're overly anal and you get a chargeback, odds are good that you the merchant are eating that fraud.

    3. Re:wouldn't work for long by Anonymous Coward · · Score: 0

      I got a very official looking e-mail from "PayPal" asking for all my information. Then I noticed the URL and that my password wasn't getting asteriked and typed in "howwouldyouliketogotoprison" in the entry fields and hit submit.

      I had one where the form submit went to and obviously named mail script. I wrote an html file with my own form pointed there and sent them the message "So how about that CREDIT CARD FRAUD, huh?"

      Then I reported 'em to the actual owner of the machine and a few other places.

    4. Re:wouldn't work for long by Anonymous Coward · · Score: 0

      You're wrong if you think CC companies eat the cost of fraud, they do not. Merchants pay for the ability to charge credit cards through discount rates and other fees. For, hopefully, obvious reasons a brand-new merchant with a brand-new merchant account usually has higher fees and much higher discount rates and per-transaction fees(as in 2x, 3x, or higher) than long-established and trusted merchants. That's how the CC companies (attempt to) keep fraud from raging out of control and how they pay for losses due to fraud.

    5. Re:wouldn't work for long by swfranklin · · Score: 1
      I learned at Mervyn's that major credit card companies tend to eat the cost of the fraud. The customer gets their money back and the store the fraud occured at gets their money.
      Nonsense. The merchant takes it in the shorts in most instances. The merchant is only protected in very limited situations - pretty much when shipping a physical product, with proof of delivery, to the recorded billing address of the credit card. Otherwise the merchant is charged back for the fraudulent purchase.
  62. And in case anyone wonders about the name... by Dimensio · · Score: 1

    The "joe" comes from the name of the first well-known incident of this happening. His name was Joe, and he lost his website because his clueless ISP couldn't figure out that he wasn't responsible for the spam run.

  63. What is it with the pump and dumps? by Sycraft-fu · · Score: 1

    I swear, these peopel are the stupidest. I've never got a pump and dump spam, but we get them as faxes all the time. They, of course, have bogus removal information but one problem: We are the operators of the phone switch at the university. If we get annoyed by it, and I'm near that point, we can get the source numbers from the switch and go after these people. You can spoof out the fax source on the fax itself, but the switch always knows the real source number.

  64. Don't judge a book by its cover. by Anonymous Coward · · Score: 0

    Since I'm such a honest looking person with a nice pleasant demeanor, I'm able to make a very good living as a wallet inspector.

  65. Forward to your representative by zpok · · Score: 2, Interesting

    Why not forward all the spam you get to the nearest politician that represents you, with the simple message:
    "Could you please do something about this?"

    Of course, this politician could try and stop you, but imagine the media attention this would get...

    BTW after some rigorous pruning of unnecessary accounts and scrambling my email addresses on the internet, I'm down to 2 spams a week (which get caught by mail.app's excellent spam-filter).

    --
    I think, therefore I am...I think.
  66. Sure it would by bluGill · · Score: 1

    Discover, (for sure, I think the others do or did) offers a one time card, aimed at online purchases. You go to Discover, login to your account, and ask for a one time card, and they give you a number, linked to your account, but only good for one use (I've never done it, but you might be able to specify a credit limit too). If anyone at the company you order from steals your number it does them no good because the card number is cancled first.

    Wouldn't be hard to go a step further and modify this so that you can get a random number which is linked directly to the fraud department, whoever uses it suddenly finds all the numbers used (including numbers from suckers who fell for the scam) are invalid. Needs some strong proof that it is fraud though. Otherwise someone will eventially try to discredit legitimate venders this way, wasting time... (Amazon is likely honest enough that you couldn't discredit them, but things of a tiny startup just trying to make a go of it)

  67. FBI computer crime agent on AOL by use_compress · · Score: 1

    I love how an FBI computer crime agent is using AOL.

    1. Re:FBI computer crime agent on AOL by Anonymous Coward · · Score: 0

      how else can they pose as "dumb users" or to pose as 13 year teenage boys/girls to get the child porn sickos....

  68. 5 year preson max? by Anonymous Coward · · Score: 0

    Geez, talk about getting off light! The max they got is 5? You know that made me wish they are in CA cuz that would be 3 striks and they be in preson for ever!

  69. Well... by Pan+T.+Hose · · Score: 1

    You might suggest to them that next time you will be more careful - if you knew it was government snooping in your private network you would have called the newspaper. The CIA can't legally do this to any US citican, and no police force can do this type of invesitgation without a warrent. The so called patriot act doesn't give everything away.

    You are right, it could've been a great news but, well, let's just say that none of us would've liked the newspapers to know about that incident. They spied on us without a warrant but not without a reason, if you follow my drift. Fortunately all of us agreed to just forget about the whole "cyber-battle," as they called my defensive DDoSing counter-attack and their own counter-counter-attack (quite harmless to my network, I might add -- except the "real world" part).

    --
    Sincerely,
    Pan Tarhei Hosé, PhD.
    "Homo sum et cogito ergo odi profanum vulgus et libido."
    1. Re:Well... by toomuchPerl · · Score: 1
      Without a warrant but not without a reason? Sorry, I don't follow your drift.
      Take this as flamebait if you must, but why the hell are you bragging on slashdot?

      I find this tripe of yours pompous and boring. If you are involved in anything of this nature, you wouldn't be shouting about it on slashdot.

      (ducks)I see that you have bipolar disorder. :P
      You're apparently some sort of boastful security consultant. Whatever, man. If you want to prove it somehow, then put up, otherwise shut up.

  70. Free speech is fun. by Anonymous Coward · · Score: 0

    And by the same rights, we get to mock the troll mercilessly. I love free speech.

  71. Hey, if they are women then... by screwdriver · · Score: 1

    maybe they CAN enlarge my penis!

  72. LOL I'd like that by Anonymous Coward · · Score: 0

    I'd rather have that than a box of tube sox and some boxer shorts.

  73. So gullable they think that... by frenchgates · · Score: 1

    gullible is spelled gullable.

    --
    Syntax error: loose != lose, affect != effect, then!=than
    1. Re:So gullable they think that... by benzapp · · Score: 1

      Is your self esteem so poor that you must resort to correcting people's spelling of an archaic and illogical language?

      At least in your own head you ar far better than the rest of us... Enjoy it.

      --
      I don't read or respond to AC posts
    2. Re:So gullable they think that... by frenchgates · · Score: 1

      Just as the programmers who read Slashdot feel it is appropriate to correct a mistake in a c++ code snippet, I feel it is appropriate to correct frequently made grammar errors in a language I am familiar with. Conflation of "Lose" with "Loose" spring immediately to mind. Don't worry. I am totally aware of the fact that encouraging proper speech is an antique endeavor and doomed to failure. It does surprise me that you, an avowed Fascist who believes in "cultural standards", would balk at a little linguistic discipline. By the way, please enlighten me as to what living human language isn't archaic and illogical?

      --
      Syntax error: loose != lose, affect != effect, then!=than
  74. innumerable people fall for it by dioscaido · · Score: 2, Informative

    I once received one of those pay pal credit card scam SPAMs, and snooped around the server which hosted the credit card acceptor script. The script wasn't an index.* file, and directory listing was enabled, so I was able to see all the files on the account. There were only two, the script and the resulting credit card database.

    There were easily 1,000 credit cards with full name and addresses and even social security #. Do not underestimate how gullible people on the internet can be.

    I reported the site to the host, and not surprisingly it took about a week to get the thing offline.

  75. I hope they will hang the bitch by Anonymous Coward · · Score: 0

    I really do...

  76. um, hacker studd... by Anonymous Coward · · Score: 0

    your page (http://phils.uj.edu.pl/) is down...

  77. Much bettter by dameron · · Score: 1

    I just have to say that preying on the stupid just doesn't sound like that big of a crime to me. At worse you've deprived them of subscribing to the Weekly World News and giving their money to televangelists. Actually, considering how many people get to rip off these people while giving out tax deductions, I'm thinking we should have the entirety of regular spammers be punished by serving as human anti-spam bots for really slow mail servers.

    -dameron

    -dameron

    1. Re:Much bettter by microbox · · Score: 1

      Have you ever read teh Weekly World News? If not, you should, it's a great read.

      How many of you thought that I was some gullible fool that believes in wild tabloid press? You my friends should all read the WWN before you decide what it is. Maybe you'll laugh out loud, and wonder why anybody could think it's real - oh, that's the joke =)

      You can't be smarter than the average Joe if you just go along with the crowd!


      There is No Sig

      --

      Like all pain, suffering is a signal that something isn't right
  78. Light punishment? by EvilStein · · Score: 2, Insightful

    "Carr's sentence will be determined by the amount of fraudulent charges racked up on the stolen credit card numbers -- with a maximum of five years. But the guidelines also dictate that each credit card be valued at a minimum of $500.00, a formula that helped boost Carr co-conspirator George R. Patterson's sentence to 37 months in prison, according to Patterson's attorney."

    That's it? 37 months in prison for her cohort.
    Yet the RIAA is trying to hit people for $150,000... and Ashcroft wants "hackers" sentenced as terrorists and put in jail for LIFE.

    Want to stop identity theft? Jack up the jail term..big time. 3yrs in jail for stealing a ton of credit card numbers is pretty weak.

  79. crack md5 hash with common word dictionary? by YOU+ARE+SUCH+A+FAG! · · Score: 0

    Congratulations! You just re-invented l0phtcrack, or any other number of brute-forcers.

    While you might have the upper hand with a dictionary of actual passwords, you are skewed by the fact that only people stupid enough to enter it on an untrusted form are submitting them.

    Or maybe you only care about idiot's accounts. They make easy prey.

    Yup.

  80. Its all so simple by BigDocJayster · · Score: 1, Funny

    Darwin Awards: People who kill themselves

    Dilbert Awards: People who support spam

    sigh. Can I have some points for -trying- to be funny?

    --
    -Where there is blue screen, there is OWNAGE
  81. She really is a little flabby. (Unbelievable!) by YOU+ARE+SUCH+A+FAG! · · Score: 0


    Take a peek (not work safe).

    That gem was found ON HER OWN computer by the guy who fought back against them before the FBI got involved.

  82. There is some kind of joke in there... by SuperKendall · · Score: 1

    Somewhere in the combination of a woman flashing and a pair of "Demotivational" posters in the background, there is a really funny joke.

    Perhaps that was her recruitment technique... or a demotivator of a different sort.

    --
    "There is more worth loving than we have strength to love." - Brian Jay Stanley
  83. educating others... by isfuglen · · Score: 0

    Part of the problem is that the people who DO know about the workings of these sorts of things don't educate others on the matter.

    My personal experience in trying to educate others is that nobody wants to listen to you. At best they say "tell me something I don't already know." At worst, "you paranoid freak!"

    --
    When life hands you lemons, grab the salt and pass the tequilla...
  84. not to mention... by real_smiff · · Score: 1

    ...that it doesn't 'remove them from the species' or whatever, it just makes them a bit poorer AND encourages these people to try it again.. maybe on you! and waste some of your time. bit like all this slashdot posting.

    --

    This is my Sig, this is my Gun. One is for Slashdot and one is for Fun.

  85. ummm..oww by jman101101 · · Score: 1

    I think it just adds insult to injury in saying the woman was 55 I mean the police could say it was a man 19-27 but 55 P.S.(shut up) am i the only person who got an email for a guy asking how to steal a car.ithougt it was spam till nobody knew what i was talking about.

    --
    3y3 c4|\| |\|0t u|\|d3rs74nd j00
  86. Re:survomies is right. by Anonymous Coward · · Score: 0

    J'raxis, Anal Cocks, Fecal Troll Matter are all the same guy.

  87. um, genius studd... by Anonymous Coward · · Score: 0

    what about an old school "www." prefix, huh?

  88. Why doesn' by Futurepower(R) · · Score: 1
    100,000 FBI agents are spammed 10,000 times each in their personal email boxes every year with illegal schemes. When U.S. citizens call the FBI to report the attempted crimes, the FBI representative just laughs.

    What is the real purpose of the FBI if it isn't to investigate crime?

  89. Why? by Anonymous Coward · · Score: 0

    Look, damnit, why is spam still a problem?

    Regardless of whether spam itself is illegal, the products that I get spam about everyday are! Increase your penis size, reverse aging, etc, etc. These are plainly fraudulent claims and should fall under the "truth in advertising" laws that were passed many, many years ago.

    The companies that hire spammers should be relatively easy to track down. Face it; they can't make money unless they make it fairly easy to contact them. They have to provide ways to collect the money of dupes and that leaves a trail. Once you have the company that collects the money, you have the company that paid for the spam and you then have the company (or individuals) that sent the spam because the spam has to be paid for and that leaves a trail.

    This is a problem that doesn't take genius to solve! And it doesn't take one lone FBI agent receiving one spam-mail and then spending two years to build a case against them.

  90. IE6 by Anonymous Coward · · Score: 0

    IE6 doesn't load the page at all. DNS error. I think IE stopped supporting base-10 IP addresses, probably to avoid scams like this.
    Is there a LEGIT reason to ever use a base 10 IP address?

    1. Re:IE6 by Anonymous Coward · · Score: 0

      Is there a reason NOT to? If you eliminate EVERY alternative method for doing something that could be used for a non-legitimate purpose, we soon won't have any ways of doing things at all. Wanker...

  91. Not just AOL -- Comcast also targetted by kiwimate · · Score: 1

    Two days ago I found a similar e-mail in my inbox which essentially followed the same lines, but was directed at Comcast users. It stated that there had been a problem with my billing credit card, which could be due to any of the following list of plausible-sounding issues, and directed me to click on a hyperlink to rectify the problem. As it happens, my Comcast account is provided by work as part of my on-call requirements, and they pay all the bills. The scary part is, even looking at the header, everything appeared to resolve to a Comcast address (I think it was comcast.biz), except for one little address which was a Qwest address.

    Comcast already knows about it; you can see their (extremely not obvious) warning here.

  92. Well, FWIW by blach · · Score: 1

    ...the security professional appears to be polish, thus not likely an American citizen.

  93. heh by ailaG · · Score: 1

    i used to change nicks to "nickserv" on dalnet and other irc networks. people didn't get their password requests and yet msg'd me their passwords.. which is okay, but when i msg'd them fake server replies, even ones that looked like passwords, none of them got it! :) and then they blocked these nicks, because of people like me ;) (for the record, i never used any of these passwords)

    --
    -= ailaG =-
  94. I forgot about the evidence by Pan+T.+Hose · · Score: 1

    Without a warrant but not without a reason? Sorry, I don't follow your drift.

    Too bad. I've already said too much. Please stop asking.

    Take this as flamebait if you must, but why the hell are you bragging on slashdot?

    I find this tripe of yours pompous and boring. If you are involved in anything of this nature, you wouldn't be shouting about it on slashdot.

    You find my comments "pompous and boring" and yet you waste your precious time reading them and replying to them? Might I suggest you getting a life maybe? Or is that your hobby to answer "pompus and boring [comments]" asking people "why the hell are [they] bragging on slashdot" every time you find something especially boring? What an exciting hobby. I do really wish my life was so exciting.

    (ducks)I see that you have bipolar disorder. :P

    Yes, I have bipolar disorder. Do you find it funny? Do you realize how much does it tell about your intelligence? It also somehow explains the rest of your comment.

    You're apparently some sort of boastful security consultant. Whatever, man. If you want to prove it somehow, then put up, otherwise shut up.

    But of course. Let me prove everyting I write on Slashdot, just like all of other fellow slashdotters do. Please give me a mailing address so I could send you video tapes and timestamped Snort logs proving that what I'm saying is true. I'm sorry I forgot to click this little "attach the evidence" button next to "submit" and "preview." Please take no offense but what are you nuts?!

    --
    Sincerely,
    Pan Tarhei Hosé, PhD.
    "Homo sum et cogito ergo odi profanum vulgus et libido."
  95. I think the CIA should stop watching Bond movies by dbIII · · Score: 1
    I remember when we counterattacked CIA agents scanning our network..
    What on earth were they doing on your network? What did the court order say? In most countries that sort of behaviour could only be carried out after they had convinced a magistrate to let them do it. Since a group like that has a lot of control over domestic policy and an enormous influence on foreign policy, they should be under the control of the judicial system.

    Disclaimer - a US intelligence agency made some ineffectual effort to depose the prime minister of my country in 1975 (he was going to go anyway, so all the US got out of it was bad press and an embarrasing court case), and I live in a country that is a very loyal ally of the USA.

  96. no one 'axed' me but... by LifesABeach · · Score: 0


    any law enforcement officer that uses AOL, or MSN should be thrown in a cage with hanable lecter; or worse, a group of defense attornies. damn, holloween's over, forget the attornies.