Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

It wasn't me, I didn't sign up for your service

jarjar Patron Provider, Top Host, Veteran

Apologies friends. Many of you received registrations for accounts for [email protected] and [email protected], and then received password reset spam for the same. These are not me. I have not signed up for any new services in the last 24 hours. If I do not have an active service with you attached to that registration, please feel free to delete these accounts and take additional measures to prevent your website from receiving spam registrations.

Side note: Of course concern #1 was that this was designed to cover up a compromise. I just finalized my audit and I'm comfortable with the result, this is just spam.

Comments

  • Such an odd thing. I guess I'm too much of a noob to guess why that spam is happening.

  • MannDudeMannDude Patron Provider, Veteran
    edited July 2024

    Same, I haven't signed up for anything at any @incognet.io domain. Seems more like a way to piss Jar off than me. I assume others are likely having their emails used to sign up for services they didn't order and that providers are being spammed with fake orders.

    Shitty ASNs where most of these new user signups are coming from: 397630,200019,209372,211936,205565,3320,203346,207096

  • zGatozGato Member

    @MannDude said:
    Same, I haven't signed up for anything at any @incognet.io domain. Seems more like a way to piss Jar off than me. I assume others are likely having their emails used to sign up for services they didn't order and that providers are being spammed with fake orders.

    Shitty ASNs where most of these new user signups are coming from: 397630,200019,209372,211936,205565,3320,203346,207096

    @alexhost mentioned :O

  • emghemgh Member, Megathread Squad

    Fucking hell now I have to return the 300 custom servers I ordered…

  • MannDudeMannDude Patron Provider, Veteran

    Seems like someone is going around creating automated accounts with a bunch of different providers using a list of scraped emails. I see recent signs up from @jar 's mentioned email, as well as my own email, spamhaus SBL removal's email, etc.

    Not really sure what the point is other than to be mildly annoying.

    Thanked by 1jar
  • @zGato said:

    @MannDude said:
    Same, I haven't signed up for anything at any @incognet.io domain. Seems more like a way to piss Jar off than me. I assume others are likely having their emails used to sign up for services they didn't order and that providers are being spammed with fake orders.

    Shitty ASNs where most of these new user signups are coming from: 397630,200019,209372,211936,205565,3320,203346,207096

    @alexhost mentioned :O

    Together with DTAG :D

  • emghemgh Member, Megathread Squad

    @MannDude said:
    Seems like someone is going around creating automated accounts with a bunch of different providers using a list of scraped emails. I see recent signs up from @jar 's mentioned email, as well as my own email, spamhaus SBL removal's email, etc.

    Not really sure what the point is other than to be mildly annoying.

    WHMCS waiting more of those $$$

    Thanked by 1coolice
  • yoursunnyyoursunny Member, IPv6 Advocate
    edited July 2024

    It wasn't me, it's the one-armed man/woman.

    Thanked by 1jar
  • VoidVoid Member

    Certain small mammal is back

    Thanked by 1yoursunny
  • FlorinMarianFlorinMarian Member, Host Rep

    2 days ago I suddenly woke up with both my business email address and my personal one, I registered, made orders and reset my password only 150 times.

    Thanked by 1jar
  • could be an "email bomb" attack, attacker signs up to many newsletter and accounts using your email and your inbox gets messy, often done to hide alerts emails etc

    but since this is targeting hosting related websites, it could just be an ex customer messing with you

    Thanked by 1jar
  • jarjar Patron Provider, Top Host, Veteran

    @Turbo_Pascal said:
    Such an odd thing. I guess I'm too much of a noob to guess why that spam is happening.

    One theory could be to cover up for a WHMCS vulnerability. Flood people's logs with junk, generate unrelated conversation, slip by under the gathering crowd to steal the databases. I doubt it but when you see a flood, always look for what it might be meant to take your eyes away from.

  • LeviLevi Member

    @Void said:
    Certain small mammal is back

    Highly doubt about that. Tiny would not try to harm jar

  • LowHostingLowHosting Member, Host Rep

    Thanked by 2jar Kris
  • JabJabJabJab Member
    edited July 2024

    @FlorinMarian said:
    2 days ago I suddenly woke up with both my business email address and my personal one, I registered, made orders and reset my password only 150 times.

    all that went to spam on GMail or you moved it manually?

  • jarjar Patron Provider, Top Host, Veteran

    @LowHosting said:

    The thumbnail was all I needed to start singing that classic 🤣

    Thanked by 1LowHosting
  • bdlbdl Member

    @jar was asleep in the car and his buddy tried this old chestnut: https://www.youtube.com/shorts/eO7zswn_QeA

    Thanked by 1yoursunny
  • ErisaErisa Member
    edited July 2024

    @MannDude said:
    Seems like someone is going around creating automated accounts with a bunch of different providers using a list of scraped emails. I see recent signs up from @jar 's mentioned email, as well as my own email, spamhaus SBL removal's email, etc.

    Not really sure what the point is other than to be mildly annoying.

    For Gmail inboxes specifically (though I assume it's similar for other providers), it's also the case that if you spam them hard enough then they get rate limited and start rejecting incoming emails. I've seen spam against a Gmail inbox used as a sort of "denial of inbox" attack in the past, to disrupt someone's operations.

  • FlorinMarianFlorinMarian Member, Host Rep

    @JabJab said:

    @FlorinMarian said:
    2 days ago I suddenly woke up with both my business email address and my personal one, I registered, made orders and reset my password only 150 times.

    all that went to spam on GMail or you moved it manually?

    I marked them as SPAM manually. All of them reached inbox/important folders.

  • alexhostalexhost Member, Patron Provider
    edited July 2024

    @MannDude said:
    Same, I haven't signed up for anything at any @incognet.io domain. Seems more like a way to piss Jar off than me. I assume others are likely having their emails used to sign up for services they didn't order and that providers are being spammed with fake orders.

    Shitty ASNs where most of these new user signups are coming from: 397630,200019,209372,211936,205565,3320,203346,207096

    Hi, dear MannDude can you get in contact with us?
    https://t.me/alexhost_on

    Alexhost doesn't allow spam in our network that is in our AUP.
    Please provider full details with logs etc and we will check.

    Best Regards,
    Alexhost

  • @alexhost said:

    @MannDude said:
    Same, I haven't signed up for anything at any @incognet.io domain. Seems more like a way to piss Jar off than me. I assume others are likely having their emails used to sign up for services they didn't order and that providers are being spammed with fake orders.

    Shitty ASNs where most of these new user signups are coming from: 397630,200019,209372,211936,205565,3320,203346,207096

    Hi, dear MannDude can you get in contact with us?
    https://t.me/alexhost_on

    Alexhost doesn't allow spam in our network that is in our AUP.
    Please provider full details with logs etc and we will check.

    Best Regards,
    Alexhost

    lel

  • MannDudeMannDude Patron Provider, Veteran

    @alexhost said:

    @MannDude said:
    Same, I haven't signed up for anything at any @incognet.io domain. Seems more like a way to piss Jar off than me. I assume others are likely having their emails used to sign up for services they didn't order and that providers are being spammed with fake orders.

    Shitty ASNs where most of these new user signups are coming from: 397630,200019,209372,211936,205565,3320,203346,207096

    Hi, dear MannDude can you get in contact with us?
    https://t.me/alexhost_on

    Alexhost doesn't allow spam in our network that is in our AUP.
    Please provider full details with logs etc and we will check.

    Best Regards,
    Alexhost

    I didn't organize the list by IP / ASN, just took mental note of the largest offenders is all. Was mostly Rackdog LLC, that SEO one, you, and like one other being the main networks.

  • ex-girlfriend.

  • mailcheapmailcheap Member, Host Rep

    How did the bad actors spoof your domain and still get through to the recipients? 🤔
    Might be a good lesson for all of us to tighten up anti-spoofing measures, all the large ESPs now require SPF, DKIM, DMARC for senders so it's unlikely they would've let spoofed messages through.

    Pavin.

  • VoltrinaVoltrina Member
    edited July 2024

    @mailcheap said:
    How did the bad actors spoof your domain and still get through to the recipients? 🤔
    Might be a good lesson for all of us to tighten up anti-spoofing measures, all the large ESPs now require SPF, DKIM, DMARC for senders so it's unlikely they would've let spoofed messages through.

    Pavin.

    You don't have to spoof email headers to mass register what seems to be a scraped list of email addresses on several different services.

    Thanked by 1MannDude
  • mailcheapmailcheap Member, Host Rep

    @Voltrina said:
    You don't have to spoof email headers to mass register what seems to be a scraped list of email addresses on several different services.

    Thanks for that, I fundamentally misunderstood the problem. 🤦‍♂️

    Our client system is also guilty of this, currently it does not perform email address verification on signup but this is due to change soon with email based 2FA as default in addition to existing TOTP and passkeys.

    Pavin.

    Thanked by 1Voltrina
  • mailcheapmailcheap Member, Host Rep

    I just woke up to over 200 registration spam, glad to know this thread is being monitored by the baddies 🥲

    Pavin.

    Thanked by 1jar
Sign In or Register to comment.