It shows rip...@topservice.com is the likely spammer.
WhoWhere.com (Angelfire.com) claims to have shut the site, though I
could still access it.
*******************************************************************************************
<form name="form" method="post"
action="http://141.20.1.96/cgi-bin/formmail.pl">
<input type="hidden" name="recipient"
value="rip...@topservice.com"><input type="hidden"
name="return_link_url" value><input type="hidden" name="title"
value="Thank you, your information has been sent."><input
type="hidden" name="redirect"
value="http://www.angelfire.com/ar/ripley11/thankyou.html"><input
type="hidden"
name="required"
value="Full Name,Marital Status,Address,City,State (Country If
Outside US),Zip,Age,Home Phone# With Area Code,Work Phone# With Area
Code,email,What Credit Card Do You Use?"><input type="hidden"
name="print_config" value="email,realname"><input type="hidden"
name="sort"
value="order:mlnme,Full Name,Marital Status,Spouse Name If
Applicable,Address,City,State (Country If Outside US),Zip,Age,Home
Phone# With Area Code,Work Phone# With Area Code,What Credit Card Do
You Use?,email">
*******************************************************************************************
Received: from corto (corto.ingsud.dga.fr [193.48.233.1]) by
fep2.mail.ozemail.net (8.9.0/8.6.12.PUBLIC) with SMTP id HAA27130 for
<gc...@nospam.ozemail.com.au>; Wed, 16 Dec 1998 07:58:19 +1100 (EST)
From: clare...@nospam.ingsud.dga.fr
Received: from corto.ingsud.dga.fr by corto (SMI-8.6/SMI-SVR4)
id XAA26228; Tue, 15 Dec 1998 23:02:15 +0100
Date: Tue, 15 Dec 98 15:36:59 EST
To: keeble...@nospam.igate.com
Subject: check this link out!
Message-ID: <77434934...@relay-22.mincenet.com>
Reply-To: gordo...@nospam.delphi.com
X-UIDL: 1497a875b93cac66ab988d97fcc3910b
X-PMFLAGS: 33554560 0
To be removed from this mailing list go to:
http://www.angelfire.com/ar/ripley11/removepage.html
ñ¦_`_¦ñ°,++,°ñ¦_`_¦ñ°,++,°ñ¦_`_¦ñ°,++,°ñ¦_`_¦ñ°
FLORIDA / BAHAMAS / CANCUN FAMILY HOLIDAY!!!!
ñ¦_`_¦ñ°,++,°ñ¦_`_¦ñ°,++,°ñ¦_`_¦ñ°,++,°ñ¦_`_¦ñ°
You have been selected to ENTER for a
LIMITED TIME ONLY!
FAMILY GETAWAY FOR 2 ADULTS 3 CHILDREN
OR 4 ADULTS!
Offer now available WORLD WIDE for a limited time only!
For more information go to:
http://www.angelfire.com/ar/ripley11/trip.html
*******************************************************************************************
--
--Regards, Gavan.
--Delete 'nospam.' to email, spam bots please go to this URL:
--http://www.e-scrub.com/spammers-are-leeches/index.htm
>Their highly sophisticated web site, composed with Microsoft FrontPage
>3.0 has the following code.
>It shows rip...@topservice.com is the likely spammer.
>WhoWhere.com (Angelfire.com) claims to have shut the site, though I
>could still access it.
I got this spam TWICE advertising totally different URLs
with totally different "remove" request email addresses.
Looks like that alligator lamer has been busy getting throwaway
sites / accounts.
-TPP
I got an almost identical one pointing to:
http://members.forfree.at/~pluto12/trip.html
I fired off complaints but the site is still active.
Copied to forfree.at in case they want to join in the discussion.
--
sapient...@sengir.demon.co.uk * ICQ #17887309 * Save the net *
Grok: http://www.cauce.org http://www.ybecker.net/ * kill a spammer *
Find: http://www.blighty.com/spam/spade.html http://combat.uxn.com *
Kill: http://dlis.gseis.ucla.edu/people/pagre/spam.html *
G Cook wrote:
> Their highly sophisticated web site, composed with Microsoft FrontPage
> 3.0 has the following code.
>
> It shows rip...@topservice.com is the likely spammer.
>
> WhoWhere.com (Angelfire.com) claims to have shut the site, though I
> could still access it.
Dead now.
Moi
Sam says:
whois -h whois.arin.net 141.20.1
Humboldt Universitaet Berlin (NET-HUBNET)
Unter den Linden 6
D-O-1086 Berlin
GERMANY
Netname: HUBNET
Netnumber: 141.20.0.0
Coordinator:
Schmidt, Burckhard (BS346-ARIN) hub...@RZ.HU-BERLIN.DBP.DE
+37 2 2093 2452
I tried mailing the admin, but the server wouldn't accept my mail.
Perhaps they'd already got the message?
Also I've contacted fortunecity.com, the spammer uses GIFs from a site
hosted there.
>Sapient Fridge <sapient...@sengir.demon.co.uk> wrote:
>
>I got an almost identical one pointing to:
>
>http://members.forfree.at/~pluto12/trip.html
>
>I fired off complaints but the site is still active.
>