May 07, 2007

A new Craigslist scam

I do believe I've divined a new Craigslist scam.

Say you wanted to harvest emails but were defeated by Craigslist's anonymization protocol (they create a synthetic email address which they redirect to your actual address to prevent harvesting by spam-bots)? What would you do?

Well, you might send an email like this:

"Hello, Kindly let me know if the item on subject posted by you, is still available for sale???"

Note the very awkwardly-worded email doesn't refer to the actual item? If I were to write a bot to cruise the Craigslist sale lists and harvest email, I would do it like this. It's sufficiently ambiguous that I think most people would respond.

When they did, they would be giving the bot (receiving the response) a known valid email address.

Pretty bloody sneaky.


Postscript: Turns out it's just that variation on the Nigerian 419 con. Some half-way bright con guy must have figured out how to write a script and just mailbombed his way through the Craigslist sales forums. When I wrote back
from a junk account, this person offered to send the money (419 style) it's even a bit more evil than I originally thought. People actually get taken every day with this con. Sad.

Posted by artandscience at May 7, 2007 07:48 AM
Implementation of James Seng's security plugin: