Jobsite.co.uk Hacked ?

Tags:

I've heard from a few sources that people who have previously signed up to Jobsike.co.uk have been receiving massive amounts of Spam starting just today. This leads me to believe that Jobsite.co.uk's database has been stolen and now many members are being spammed from what appears to be job offers from Jobsite.co.uk. Of course there is no message or anything on the Jobsite website so for now nothing can be confirmed, however this does look like it's almost confirmed.

The IPs being used for this are not those of Jobsite. They look like compromised home computers, most probably running the award winning operation system called Windows...

Of course this would be a different issue they would at least use SPF records, and I don't mean that Softfail lame stuff that makes SPF completely useless.... this is their current record:

jobsite.co.uk. 43200 IN TXT "spf2.0/pra mx ip4:213.165.31.0/24 ip4:195.171.206.128/25 ip4:81.145.143.0/24 ~all" jobsite.co.uk. 43200 IN TXT "v=spf1 mx ip4:213.165.31.0/24 ip4:195.171.206.128/25 ip4:81.145.143.0/24 ~all"

and the ~all means "hey I have SPF but I don't use it". Hopeless.

comments:
avatar

Mark

Appears to have now been updated

jobsite.co.uk. 43200 IN TXT "spf2.0/pra mx ip4:213.165.31.0/24 ip4:195.171.206.128/25 ip4:81.145.143.0/24 -all"
jobsite.co.uk. 43200 IN TXT "v=spf1 mx ip4:213.165.31.0/24 ip4:195.171.206.128/25 ip4:81.145.143.0/24 -all"
avatar

manu - http://manurevah.com

Indeed, thanks for the note.. : ]

Also, there have been a bunch of other falsified mails from many other job type websites.

The up side is people are learning to use SPF.
Leave a comment
You may use the following HTML tags: <p> <a> <strong> <b> <em> <i> <cite> <blockquote> <code> <pre>

Your comments WILL NOT be submitted to any third party (not even for anti spam verification).