Jeff Duntemann's Contrapositive Diary Rotating Header Image

July 31st, 2010:

Classmates: Hacked, or Poor Proctoring?

Quick update: Either Classmates.com was hacked, or nobody over there is paying the least attention to user activity. Textual obscenities and dirty pitchers abound; those with strong stomachs may see it for the time being here.

I’m divided as to whether I should alert them to it. There are 17,000 Lane alumni in the system online, and I can’t imagine that at least one of them hasn’t complained about it yet. (Lane is a big school, and has been around for a very long time.)

I’m definitely watching it, and am still interested in reports from people (especially from other schools) who have gotten forged emails from Classmates lately, containing obscenities or not.

Was Classmates.com Hacked?

Something very weird is going on here: I’ve gotten a scattering of emails in the last 18 hours from Classmates.com. Nothing new in that, except that these are obviously fakes, albeit very convincing fakes. The subject line for the first is:

“You are invited to the Naked Fest with Lane Technical High School.”

The From: field contains a multi-word obscenity that I won’t even try to repeat. (You know what dash characters look like.) The body of the message is pure Classmates, but in the Received: field in the headers is a bogus domain and an IP that doesn’t match classmates.com:

Received: from mta10.prod.iad1.cmates.com (va-in-svc-lb1-mip.iad1.cmates.com [10.12.208.10])

It’s not malware, came in with no attachments, and contains no scripting whatsoever.

One of my friends from Lane got the identical messages about the same time that I did. So: Did anyone else get anything like this? Or is it just the two of us who are being scammed? I don’t see anything about this online, which suggests that somebody is having some fun with him and me and not with Classmates.com as a whole.

Do let me know. Thanks!