[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: www.WhosWhere.com selling access to my employer's passwd file



On Sat, 27 Apr 1996, Sentiono Leowinata wrote:

> I wonder how they can get the e-mail address? Our finger daemon are 
> blocked. Many un-broadcast e-mail addresses (the account never send any 
> e-mails to anyone) are in the database. How?

It's a sad fact that many unscrupulous(sp?) writers of WWW pages use 
non-visilble "on load" HTML to record what the web browser thinks the 
email address of the person browsing the page, and, I presume sell this 
info to the junk email producers.

Part of the WhoWhere archives could have come from such sources. (personally 
my address in netscape is [email protected])

If one really set ones mind to it, I guess that grepping through mailing 
list archives for addresses, and using a webcrawler to search for MAILTO=
would lead to many thousands, or even hundreds of thousands, of addresses.

On the plus side, the search engine will not let "*","\*","?*" and so be 
used, and there are no real matches for "root", apart from stuff like 
"Bob Root" etc.

--
Gus <[email protected]> |-|PGP Fingerprint = 73 83 C0 EA 2E A6 00 3E
http://www.thepulse.co.uk/angus  |=|(Key on request)  08 B1 19 0D 8B BE 87 B9
CIS 100545.720                   |+| "Linux - You know you want to." | "fuck"
|Advertising/Promotional email will result in a campaign of hatred and abuse|