Spam from Blackjack21?

Discussion in 'Blackjack Events (Online Casinos)' started by KenSmith, Jul 31, 2007.

  1. KenSmith

    KenSmith Administrator Staff Member

    I've been getting a lot of "You've received a greeting card" spam over the last few days. However, three of these messages in the last couple of days caught my attention because the From address was at blackjack21.com.

    Spoofed return addresses are the norm in the world of spam, but in this case, the message did arrive from the same IP address as the normal blackjack21.com messages, so it really does come from their server.

    Is anyone else receiving these? I've already emailed them to tell them they seem to have a problem. It appears to me that their email server has been compromised in some way and is allowing outsiders to send unsolicited messages to their customer list.

    The subject line I received is this:
    [customers] You've received a greeting card from a Friend!

    Anyone else?
     
  2. BJFAN4

    BJFAN4 New Member

    Same here.

    I have received 2 or 3 which I deleted without opening via the link they provided.:flame:
     
  3. KenSmith

    KenSmith Administrator Staff Member

    Yes, I definitely wouldn't click the link. I'm sure the destination site attempts to infect you with some form of malware or virus. I should have mentioned that in my message.

    So, it's confirmed that Blackjack21 has an email security issue.
     
  4. LeftNut

    LeftNut Top Member

    There is a LOT of those emails going around. I haven't gotten any from the site you mentioned, but have been getting a half-dozen of them a day. They all say "You have received a grreting card from....", then something generic like Neighbor or Cousin or Friend. Just the latest Internet B.S. going around.
     
  5. KenSmith

    KenSmith Administrator Staff Member

    Yes, I'm getting lots of these as well, but these few specifically came through Blackjack21's server. In the last few minutes, I've also gotten an empty message with a zip file, presumably virus-laden. Again, probably sent to the entire Blackjack21 customer list.
     
  6. London Colin

    London Colin Top Member

    I had one from "a Worshipper"! Kneel before Zod! :D

    No. It's likely just* an 'open relay' that is being exploited, meaning the spammer can log into blackjack21's email server and use it to send their spam. The list of recpients will be their usual victims, culled from all manner of places. Certainly, I haven't had any purporting to be from blackjack21.

    That's assuming it's not possible to spoof the IP address of the originator in the message header, along with the "From:" email address, etc. I don't really know if that's true.

    * Edited to add: 'Just' was probably a bad choice of words. If this is indeed what is happening then it's a serious matter for blackjack21, which they will need to resolve for their own sake. It might also give us cause for concern that their security arrangements, more generally, may not be up to scratch.
     
    Last edited: Jul 31, 2007
  7. bear

    bear New Member

    Our apologies....

    On behalf of Blackjack 21, we apologize for any inconvenience you may have experienced with spam coming from our domain.

    We are aware of the problem, and have blocked a feature on our email servers that was allowing relay emails through it.

    I personally can't stand getting all the junk I get on a daily basis, and can sympathize with how you feel.

    Again, we apologize for any confusion and inconvenience that may have been caused to you.

    Sincerely,

    Bear
     
  8. London Colin

    London Colin Top Member

    Thanks Bear

    As I said, I haven't been receving spam from your domain. However, I have noticed a very sluggish response at times lately when playing. Could this have been a consequence of your systems being swamped by the evil spammers?
     
  9. KenSmith

    KenSmith Administrator Staff Member

    Thanks Bear. I'm glad that's sorted out. I haven't received any of these messages today, so it appears the problem is resolved.
     
  10. casino_jim

    casino_jim Member

    I, too, have gotten many of these emails, but they were blocked by my virus protection since it found a 'trojan' of some sort in it. I am getting 3 or 4 a day. DO NOT OPEN THEM!!
     
  11. LeftNut

    LeftNut Top Member

    In case anybody's wondering, this is what those emails look like.
    Note that the URL has what appears to be an IP address embedded.
    I have removed part of the URL so that (hopefully) no one will be able to use it.....


    Hi. Partner has sent you a greeting ecard.
    See your card as often as you wish during the next 15 days.

    SEEING YOUR CARD

    If your email software creates links to Web pages, click on your
    card's direct www address below while you are connected to the Internet:

    Removed per Mace's suggestion, see below

    Or copy and paste it into your browser's "Location" box (where Internet
    addresses go).

    We hope you enjoy your awesome card.

    Wishing you the best,
    Webmaster,
    greeting-cards.com
     
    Last edited: Aug 3, 2007
  12. bjmace

    bjmace Member

     
  13. LeftNut

    LeftNut Top Member

    Holy crap! Thanks, Mace. It never even occurred to me to check it after I posted.
     
  14. bjmace

    bjmace Member


    No probs, You fimd that the wording and the hyperlink are 2 phase. the wording is similar to a picture that you can click on and it takes you to the web address that is hyperlinked to it, So deleting a fre of the letters still left the hyperlink in place, Glad I caught it before anyone got hurt, Then again have not heard from many other besides us 2 on here for couple of days so maybe in Ultimate Blackjack style they/There computers have been eliminated :laugh:
     

Share This Page