<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>BLOGARITHMIC DISFUNCTION &#187; Lottery</title>
	<atom:link href="http://www.bl0g.co.uk/tag/lottery/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.bl0g.co.uk</link>
	<description>Watching the distance between posts increase exponentially.</description>
	<lastBuildDate>Wed, 07 Jul 2010 09:44:42 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Nigerian 419 Lotto Scammers use Fake Lottery Website</title>
		<link>http://www.bl0g.co.uk/20070824/nigerian-419-lotto-scammers-use-fake-lottery-website/</link>
		<comments>http://www.bl0g.co.uk/20070824/nigerian-419-lotto-scammers-use-fake-lottery-website/#comments</comments>
		<pubDate>Fri, 24 Aug 2007 13:43:19 +0000</pubDate>
		<dc:creator>DD</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[Problems]]></category>
		<category><![CDATA[Spam & Viruses]]></category>
		<category><![CDATA[419]]></category>
		<category><![CDATA[Lottery]]></category>
		<category><![CDATA[Scam]]></category>

		<guid isPermaLink="false">http://www.bl0g.co.uk/?p=1233</guid>
		<description><![CDATA[It began, as so many adventures do, with a chance tip from a concerned netizen.  A lady on the Internet had received an email saying she had won the Lottery and had been in communication with the offenders when she decided she didn&#8217;t like the way things were going.  She emailed us, and [...]]]></description>
			<content:encoded><![CDATA[<p>It began, as so many adventures do, with a chance tip from a concerned netizen.  A lady on the Internet had received an email saying she had won the Lottery and had been in communication with the offenders when she decided she didn&#8217;t like the way things were going.  She emailed us, and things happened.</p>
<p>Many moons ago I wrote a <a title="UK Lottery Results" href="http://www.the-lottery.info/" target="_BLANK">Lottery Results</a> website.  The lady emailed us with an alternate address, revealing that the scammers had copied the entire website &#8211; including the list of <a title="Lottery Scams" href="http://www.the-lottery.info/lotto-scam-email-examples.php" target="_BLANK">Lottery Scam Emails</a> &#8211; in order to give their 419 Email Scams that added air of legitimacy.</p>
<p>The original site is at: <a href="http://www.the-lottery.info/" target="_BLANK">www.the-lottery.info</a></p>
<p>The cloned site is at: <a href="http://uknlotteries.com/nationallottery/" target="_BLANK">uknlotteries.com/nationallottery/</a></p>
<p>There were several changes, all geared towards getting an unsuspecting user to type in a username and password (supplied in the scammers&#8217; original email) and then enter their legitimate bank account details.  No doubt the scammers would plunder the account, leaving the scammee high and dry.</p>
<p>The WHOIS for uknlotteries.com showed it was on a free hosting company, Freehostia, and that the domain was purchased through ns.com / tucows.com on 14th August &#8211; just a week before we were told about it.  Pinging the domain gave 64.72.119.253 &#8211; an IP handled by AlphaRed.com.  All of these companies were sent a copy of our 14-Page report.</p>
<p>Next up, we noticed that the &#8216;Contact Us&#8217; page still contained the IP and Host Name of the person who downloaded the first copy of the site &#8211; ironically this was a security thing:</p>
<p>80.178.248.142.satcom-systems.net / 80.178.248.142<br />
Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)</p>
<p>This was an IP address in Israel.  A quick search of the server logs showed that users from  Satcom Systems had been visiting at least as early as October 2006.</p>
<p>Examination of the source code revealed other domains in use by the spammers: CTBPLC.co.uk (Not working) and GCBOFLONDON.com (A holding page on a Microsoft Office service).  Another free hosting company, Multiververs.com, was used for the latter.</p>
<p>The /secured/ folder did not contain an index file and so we were able to examine the other files in  that directory.  We found IP activity mini-logs from Web2FTP.com for the following IP addresses:</p>
<pre style="font-size:10px; margin-left:40px;">IP: 82.206.163.11	Time: 15.08.2007|00:44:50	Uploaded 42 files
IP: 213.185.118.207	Time: 16.08.2007|18:57:22 	Editted 1 file
IP: 41.220.75.3		Time: 17.08.2007|10:11:12 	Editted 1 file
IP: 63.109.248.30	Time: 17.08.2007|13:06:56	Editted 1 file
IP: 213.185.118.227	Time: 21.08.2007|10:42:37 	Editted 1 file</pre>
<p>Further examination of other know file paths that were cloned revealed that 82.206.163.11 was the IP of the user who had uploaded the files to the fake domain.</p>
<p>IP WHOIS Info for 82.206.163.11?  Yep&#8230;</p>
<pre style="font-size:10px; margin-left:40px;">
inetnum:        82.206.163.0 - 82.206.163.255
netname:        CUST-SUBURBANTELE
descr:          Reassignment to Suburban Telecom
country:        NG
admin-c:        BA771-ripe
tech-c:         BA771-ripe
status:         ASSIGNED PA
remarks:        *************************************************************
remarks:        *                                                           *
remarks:        *   For issues of abuse related to this IP address block,   *
remarks:        *         including spam, please send email to at:          *
remarks:        *                                                           *
remarks:        *               s.ayonote@suburbantelecom.com               *
remarks:        *                                                           *
remarks:        *************************************************************
mnt-by:         AS22351-MNT
mnt-lower:      AS22351-MNT
changed:        TAC.OPS@Intelsat.com 20060623
source:         RIPE
person:       Bruce Ayonote
address:      Plot 1105 Durban Street Wuse II
address:      Abuja, Nigeria
phone:        +234 80 3313 7201
e-mail:       bruceayonote@hotmail.com
nic-hdl:      BA771-ripe
mnt-by:       AS22351-MNT
changed:      tac.ops@intelsat.com 20030611
source:       ripe</pre>
<p>A quick IP WHOIS on the other IP addresses confirmed it &#8211; a classic Nigerian 419 Scam.</p>
<p>A copy of everything we&#8217;d found was sent to all concerned parties and the website was gone 10 hours later, with <a title="Free Web Hosting" href="http://freehostia.com" target="_BLANK">Freehostia</a> being first to pull the plug.  As of right now, we don&#8217;t know if the scammers can still access the domain, so it&#8217;s possible that the site will reappear on another hosting company.  We&#8217;ll have to keep an eye out for that one.</p>
<p><strong>Updated 6th June:</strong> It appears the scammers have created more than one site &#8211; <a title="scam scam scam" href="http://www.natuklottocommission.co.uk/index.html" target="_BLANK">this one</a> actually made it into Google&#8217;s listings.  I&#8217;ve tipped off the hosting company, as before, as we&#8217;ll see what happens.</p>
<p><strong>Updated September 12th</strong>:  <em>Finally</em> got rid of it.  The hosting company in this case was a little less willing to help and had to be reminded, and even then asked for proof that it was a cloned and phishing site.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bl0g.co.uk/20070824/nigerian-419-lotto-scammers-use-fake-lottery-website/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Various Musings</title>
		<link>http://www.bl0g.co.uk/20060420/various-musings/</link>
		<comments>http://www.bl0g.co.uk/20060420/various-musings/#comments</comments>
		<pubDate>Thu, 20 Apr 2006 13:11:45 +0000</pubDate>
		<dc:creator>DD</dc:creator>
				<category><![CDATA[Various]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Lottery]]></category>
		<category><![CDATA[Reformat]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://www.bl0g.co.uk/?p=1099</guid>
		<description><![CDATA[Various bits and bobs &#8211; general chunterings while having a break.
Fog on the Road!
A misty morning, guaranteed to get every nonce showing the world how wonderful their fog lights are.  Great.  I can see your car at least a hundred yards in front of me thanks to its car-shaped-ness, but put your fog [...]]]></description>
			<content:encoded><![CDATA[<p>Various bits and bobs &#8211; general chunterings while having a break.</p>
<p><strong>Fog on the Road!</strong><br />
A misty morning, guaranteed to get every nonce showing the world how wonderful their fog lights are.  Great.  I can see your car at least a hundred yards in front of me thanks to its car-shaped-ness, but put your fog lights on anyway &#8211; that&#8217;ll help!</p>
<p><strong>Bulk Email Sender Hacking</strong><br />
OK so it&#8217;s not hacking as such, but I was playing about with a bulk email sender on the Mac and found that it didn&#8217;t check for strict HTML.  Ordinarily it adds a TABLE to the bottom of all HTML emails containing something about using the unregistered version (cough!), and it does this by inserting a snippet of HTML just before the /BODY tag.  If you do this:</p>
<ul><kbd>&lt;DIV STYLE="visibility:hidden"&gt;<br />
&lt;/BODY&gt;<br />
&lt;/HTML&gt;<br />
&lt;/DIV&gt;</kbd></ul>
<p>at the end of your HTML email, this little bit of shareware branding gets hidden away.</p>
<p><strong>Dinosaurs!</strong><br />
One of the reccurring dreams I have is of being chased around the streets by a Tyranosaurus Rex.  I&#8217;ll hide in a room or an alleyway and it&#8217;ll appear outside the window or whatever, so I have so scurry off somewhere else.  It never catches me, but I wake up rigid with fear.  I&#8217;m 36 &#8211; why is this happening?</p>
<p><strong>AOL Spam-Blocked &#8211; hahahah</strong><br />
Sweet, sweet justice.  After revealing their Pay-to-Spam-Our-Users scheme recently, it was gratifying to see at least one AOL SMTP server cropping up on the BlockLists.  It&#8217;s no longer on the SpamCop list which probably means it&#8217;s working in the majority of cases again, but it was nice while it lasted.</p>
<p><strong>Googly Adsense</strong><br />
I managed to talk <a href="http://www.retroleum.co.uk/">Foo</a> info signing up to Google Adsense via my referral link (the big banner, <a href="?d=060409">here</a>) and he&#8217;s already raking in the.. uh.. well a few cents here and there anyway.  Presumably I get a tiny percentage for referring him as well.</p>
<p><strong>The-Lottery.info</strong><br />
I added a chunk of code the <a href="http://www.the-lottery.info" target="_blank">The-Lottery.info</a> last night to allow the owner to enter the prize breakdown for each draw and display it as part of the latest lottery results pages.  After pondering it for, ooooh, a whole ten minutes, I eventually came up with a novel way of including default values for the various winning combinations.  I though it was groovy, anyway.</p>
<p><strong>Reformat Time!</strong><br />
Gah!  I fired up the old laptop today and after it wheezed to a halt into Windows the wireless internet refused to work no matter what.  Since I started working in Scunthorpe the laptop has been a dumping ground for all kinds of software (including bulk email stuff, actually) and is generally a mess &#8211; time to scrub it up!</p>
<p><strong>Barry McGuigan in Cleethorpes</strong><br />
Barry McGuigan is in Cleethorpes on Monday 24th April at Joe Frater&#8217;s boxing night &#8211; more details <a href="http://www.joefraterboxingpromoter.co.uk/events.php" target="_blank">here</a>.  I&#8217;ll be in attendance as usual.  Amir Khan is due at the Christmas show &#8211; that should be a good one.</p>
<p><strong>Site redesign</strong><br />
I know I mentioned the DHTML Window Thing (see right) a while ago and how I was going to implement it, but I&#8217;ve been thinking of cutting right back on the graphics and going back to plain text instead.  The main reasons for this are compatibility and search engine optimisation &#8211; all those tables and shit just get in the way really.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bl0g.co.uk/20060420/various-musings/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
