On 06.03.2017 16:12, Kalogrianitis Socratis wrote:
Just to add another data point, after my first e-mail on the list, I started 
getting about 10 spam e-mails per day. None before that.

OK, that's valuable data (and gives me an impression how much spam the Oracle mail infrastructure must be keeping away from me), especially as you send the first mail earlier than the end of last year, when this scam flavor started to infest various places.

In any case it's likely a separate issue, as the scam at hand seems to have a single topic which makes it non-typical.

Wouldn't it be easier for you if you created a new e-mail account, sign up only 
in the mailing list and see what's going on? First hand?

The Oracle network prevents quite a few issues by restricting what's possible (by keeping you away from 3rd party mailboxes). So it would be easier in general, but no for me.

Either way, my second e-mail to the list today (visible by the message IDs in the replies) brought me the attention of Eboni, and this is really far worse than the usual spam, because one mail triggers a whole sequence, even if one never replies. By now 12 mails, mostly with a 300KB picture attachment.

From the timing I'm quite certain that we have a rotten egg in our subscriber list, because from my message hitting the list it took 20 seconds until the ML software shoved everything to the official mail server, and only 20 seconds after that I got contacted. Unlikely that this is scraping addresses off the archive.

I'm thinking about ways to identify the leak within a reasonable amount of time, but can't do something right now as I have higher priority issues.

Klaus


Socratis


On 6/Μαρ/2017, at 14:50, Klaus Espenlaub <klaus.espenl...@oracle.com> wrote:

Hi all,

we have heard of spam mails being sent directly to the poster of a message to 
the vbox-dev mailing list (and not to all subscribers)... since the spam isn't 
going through the mailing list we have a hard time figuring out how exactly the 
spammer gets the information. I haven't seen such a response myself (could be 
that the mail server here filters it out).

Could everyone who got a mail from Eboni in the last days or today forward the 
complete first mail to me. Ideally as an attachment and no point in sending me 
more than one. We might be able to deduct something from the timing of these 
mails.

Sorry about the spams,

Klaus
_______________________________________________
vbox-dev mailing list
vbox-dev@virtualbox.org
https://www.virtualbox.org/mailman/listinfo/vbox-dev

Reply via email to