Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Other > /etc

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #11 (permalink)  
Old 08-08-2011, 08:45 AM
Junior Member
 
Posts: 7
Default

Quote:
Originally Posted by phoenix View Post
That is your prerogative. If the accounts on the forums or bugzilla had been 'hacked' don't you think we'd all be getting spam?
Indeed, it is. I was not trying to assert that bugzilla has been hacked. You can scrape email addresses from bugzilla simply by creating an account and listing bugs. Once you are logged in, you can see the email addresses associated with the ticket and its comments.

Last edited by pointer; 08-08-2011 at 03:21 PM..
Reply With Quote
  #12 (permalink)  
Old 01-20-2012, 05:18 AM
Member
 
Posts: 11
Default select2gether

Just as a data point, I'm on the Zimbra Forums and Bugzilla, I've gotten these spams for a few months. My coworker is also on the Zimbra Forums and Bugzilla, and gets the same spams. About the only thing we have in common is these two things. I would suspect a scraping rather than an outright hack, though.
Reply With Quote
  #13 (permalink)  
Old 01-20-2012, 05:24 AM
Zimbra Consultant & Moderator
 
Posts: 20,316
Default

Quote:
Originally Posted by bjenkins View Post
I would suspect a scraping rather than an outright hack, though.
That's not likely, the email addresses are not visible for viewing and if that were the case I'd think we'd all be getting spam from these sources.
__________________
Regards


Bill
Reply With Quote
  #14 (permalink)  
Old 01-20-2012, 05:40 AM
Member
 
Posts: 11
Default

Well, in Bugzilla they are if you log in. Maybe that's where they are coming from, rather than the forum?
Reply With Quote
  #15 (permalink)  
Old 01-20-2012, 05:41 AM
Junior Member
 
Posts: 7
Default

Quote:
Originally Posted by phoenix View Post
That's not likely, the email addresses are not visible for viewing and if that were the case I'd think we'd all be getting spam from these sources.
You're wrong on at least one point. Go to this URL and tell me if you see email addresses:

https://bugzilla.zimbra.com/show_bug.cgi?id=38631

I'm asserting that this came from bugzilla.zimbra.com. I use separate email addresses for bugzilla and these forums.

Also worthy of note:

https://bugzilla.mozilla.org/show_bug.cgi?id=261326

Bugzilla appears to allow email harvesting by spammers
- you replied to this one
- the user simply asked Zimbra to enable email address obfuscation in Zimbra's bugzilla instance like Redhat does
- the 4th result when you google 'bugzilla spam'

The email address I registered to bugzilla is behind a cluster of IronPorts with DHAP (directory harvest attack prevention) enabled. Obviously this is not bullet-proof, but it makes the address being harvested much less likely.

Thank you for taking the time to respond to this thread!
Reply With Quote
  #16 (permalink)  
Old 02-05-2012, 03:57 AM
Starter Member
 
Posts: 1
Default

Quote:
Originally Posted by Blinkiz View Post
I use individual email addresses for all sites I register on. Like Zimbra forum.
Today (2011-06-04) I got spam on this unique address from do-not-reply@select2gether.com. A person (nina.crowth) requesting to add me as contact on Select2gether.

Because I use individual email addresses, I suspect my email address here on Zimbra forum has been compromised.
Anyone else got spam from select2gether?
Sorry to hear this- I have actually great experience at Select2gether and have great friends, more than 40000. I sent an email to their admin so they block the person who send you this email. Thank you.
Dave
Reply With Quote
  #17 (permalink)  
Old 03-23-2012, 09:37 AM
Intermediate Member
 
Posts: 19
Default

Just one more data point - I've been getting Select2gether spam on my registered address here and on bugzilla from about the time the OP states. I *do* use this address elsewhere so it is not necessarily an indicator of any problem.

Not sure if this helps, but I thought I'd provide the info
__________________
- Mick Smothers
Memphis, TN USA
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.