Tuesday, October 28, 2008

Yahoo abuser now using TOR - to evade law enforcement, perhaps?

At 2:59AM on 10/25/08, I was sent this message;

..................................................................
from Yahoo! Message Boards <boards-abuse@cc.yahoo-inc.com>
reply-to Yahoo! Message Boards <boards-abuse@cc.yahoo-inc.com>
to saltydogmn at gmail dot com
date Sat, Oct 25, 2008 at 2:59 AM
subject Auto Confirmation - Your Yahoo! Message Boards support request was received (KMM80090580V21536L0KM)
signed-by cc.yahoo-inc.com

hide details 2:59 AM (13 hours ago)


Reply


Hello,

This is an automated message regarding your recent request for Yahoo!
Message Boards Customer Care support. Your message was received, and you
will hear back from us within the next 48 hours with an answer.

Thank you for reaching out to us. We look forward to helping you!

Sincerely,

Yahoo! Customer Care

**Please do not respond to this message as no one will receive it.
...............................................................................................


I found it odd, since I hadn't sent any reports of any posts at all, especially at that time of day!

Then, some time later, I received the following message;
...............................................................................................................................

from Yahoo! Message Boards <boards-abuse@cc.yahoo-inc.com>
reply-to Yahoo! Message Boards <boards-abuse@cc.yahoo-inc.com>
to saltydogmn at gmail dot com
date Sat, Oct 25, 2008 at 4:12 PM
subject Re: Spam (KMM80114826V69127L0KM)
signed-by cc.yahoo-inc.com

hide details 4:12 PM (3 minutes ago)


Reply


Hello,

Thank you for writing to Yahoo! Message Boards.

We have received your report of potential violations within Yahoo!
Message Boards. We have completed our evaluation, and have taken
appropriate action as per the Yahoo! Terms of Service. For further
details about the Yahoo! TOS, you can visit:

http://docs.yahoo.com/info/terms

Please know that we cannot disclose any action taken on another user's
account. We're unable to make exceptions to this rule.

Thank you again for contacting Yahoo! Message Boards.

Regards,

Ram Delves

Yahoo! Customer Care

54449722

For assistance with all Yahoo! services please visit:

http://help.yahoo.com/




Original Message Follows:
-------------------------

Mail-Id:
w12.help.sp1.yahoo.com-/l/us/yahoo/messages/abuse.html-1224921431-3547

1. What is your name and Yahoo! ID?
Name:
Yahoo! ID:
2. What is your email address?
Email Address: saltydogmn at gmail dot com
3. Who are you reporting?
Yahoo! ID: tuftmail
4. What is the violation?
Subject: Spam
5. On what message board do you believe this abuse is occuring?
Board Name: SCO Group, Inc. (SCOX)
Message ID #: 470858
Board ID: 2942
Message URL: http://messages.finance.yahoo.com/Stocks_%28A_to_Z%29/Stocks_S/threadview?m=tm&bn=2942&tid=470855&mid=470858&tof=24&off=1
6. Enter additional information here:

More off-topic spamming by tuftmail.

"Information Passed In":
------------------------
"otherid_10607" : tuftmail
"text_18572" : SCO Group, Inc. (SCOX)
"text_18573" : 470858
"text_18574" : 2942
"text_18571" : http://messages.finance.yahoo.com/Stocks_%28A_to_Z%29/Stocks_S/threadview?m=tm&bn=2942&tid=470855&mid=470858&tof=24&off=1
------------------------

While Viewing:

Form Name: http://help.yahoo.com/l/us/yahoo/messages/abuse.html

Yahoo ID: : NOT verified, authorized by CAPTCHA Yahoo id undetermined
no need to click
"https://amt.yahoo.com/amt/dosearch?.token=Ell6cP7DQXyAYHzX_915tLQ1seAAG
A--"


Other ID: tuftmail : Other id provided Yahoo id from form
"https://amt.yahoo.com/amt/dosearch?.token=NycKXD7DQXxFltDLKotHBtcav0yz.
EFnJWwr9JPH"


Machine: PC

OS: WinXP

Browser: Firefox 2.0

REMOTE_ADDR: 210.48.159.134

REMOTE_HOST: n01.tor-proxy.org

Date Originated: Saturday October 25, 2008 - 00:57:11

...................................................................................

Several things are rather amiss with this message;

A)There are no submitter names or Yahoo IDs filled in; when ever I have submitted a report, in which I have to fill those fields in, so that the form will actually be submitted, the eventual reply will show my info in those fields.

B)The address that this came to, saltydogmn at gmail dot com, has NEVER been registered with Yahoo. All correspondence with Y! goes to a spam-catcher address, and that's the way I like it.

C)Again, I never sent a report at that time for any spam.

D)More importantly, I would have NEVER sent a report on Tuftmail!

E)I can't really tell, but it looks like the CAPTCHA required to enter might have been bypassed - based on the info shown...

F)The big thing, that I noticed, is that whomever generated the fraudulent report, was using a PC, running Firefox 2.0, and... TOR!
I have never ever used TOR.

Anyone want to guess what that sick bastard is up to now?

NOTE - the URLs listed in the reply from Yahoo are for a feature called Yahoo Guesthouse - Single Corporate Logon ... has our l33t hax0r found a way to crack Yahoo's security for their corporate services? I should think that they would be interested in hearing about that.