Last visit was: Sat Jul 05, 2014 6:57 pm
It is currently Sat Jul 05, 2014 6:57 pm

Pharmacy Expressorator (tm)


All times are UTC - 5 hours [ DST ]


 [ 214 posts ]  Go to page 1, 2, 3, 4, 5 ... 15  Next
Author Message
 PostPosted: Tue May 09, 2006 9:30 am   
Site Admin
User avatar

Joined: Tue May 09, 2006 9:18 am
Posts: 5022
Hello, and thank you for setting up this forum.

Caught onto this forum after reading the awesome lengthy thread over on Digg.

I am quite active in going after spammers via annoying little tools like this one:

http://www.mytempdir.com/653575

I call it the PharmacyExpressorator(tm). It's based on a series of other automated javascript tools which I and others wrote to go after mortgage spammers.

This allows users to post "orders" to the renowned Pharmacy Express series of spamvertised websites.

I know for a fact that it works because I've seen them begin banning any IP address that starts using it. Also: they used to accept all kinds of credit cards. Now they only accept Visa (though they still show a mastercard logo.)

A very small number of people have been running this up til now. In light of the Blue Security attack, I think it's time to share the love.

It takes a bit of effort - you can't just automate it completely as they use .NET sessions to track each shopping cart. But it is definitely worth it.

In brief this tool does the following:

- Loads one of several active PharmacyExpress domains (just got two new ones now. :) )
- You grab the generated ID and paste it into the field provided.
- Order from dozens of randomly selected "products"
- Submit your "order", using 100% randomly generated (but very realistic) names, addresses, zipcodes
- Use a fake, randomly generated (but able to pass mod10 checks) credit card number. This is now modified to only generate fake Visa numbers as well as accurate expiry dates, etc.

The odds of this info ever matching up to any real human being, anywhere in the continental US is precisely zero.

If you like it, tell your friends. The more "orders" that can be processed, the less likely Visa will be to allow them to post orders either. :)

This hits spammers hard. How many of these a day do you folks get? I was up around a few dozen a day until I started running this.

Spammers obviously need to be taught a rather large lesson. Acts like spamming Blue Security members obviously calls for a greater, more organized approach. This is only one of numerous such tools I have helped to create. I'll post more as they become available again (stupid spammers shut down their sites after a few days.)

Thanx for reading,

SiL

P.S. Those who have used this tool previously have said that posting orders manually gives them a peaceful, euphoric feeling. I am not responsible for any undue medical side-effects of using this tool. :)


Top
 Profile  
 PostPosted: Tue May 09, 2006 10:12 am   
User avatar
Hey SiL, dang I was going to notify you about that digg story, looks like you're ahead of me mate :)

Just a quick question, how often does this update to the site, and can it be configured to work on other sites?

Thanks again!
SD


Top
  
 PostPosted: Tue May 09, 2006 10:21 am   
Site Admin
User avatar

Joined: Tue May 09, 2006 9:18 am
Posts: 5022
Some Dude wrote:
Hey SiL, dang I was going to notify you about that digg story, looks like you're ahead of me mate :)


Hehe. :) Man: we are everywhere, you and I!

Some Dude wrote:
Just a quick question, how often does this update to the site, and can it be configured to work on other sites?


Well see: usually these sites are pretty quick to be set up and shut down. I think they must have some crazy "per day" quota before they know they'll be complained about. So usually I see upwards of 40 domains per day set up, spammed, and then later shut down. For whatever reason the current batch of domains has been up for days and they definitely process orders. (yay.)

Unfortunately this is pretty hard-coded to this range of sites. Their methodology is pretty unique. I have made others but they've all gotten smarter about processing their actual orders (notably My Canadian Pharmacy, another series probably from the same assholes.)

It's important to note how dangerous this type of outfit is. They have absolutely no registered pharmacists anywhere on staff. There are no checks and balances in place to verify that you're getting real medicine at all, and in fact many reports have been written verifying that they are selling false products with no active medical ingredients. The possibility of somone suffering some real harm from this is quite real. This is why I wrote this. (Well that and: I friggin' hate spammers.)

Good to see you here too, SD.

SiL


Top
 Profile  
 PostPosted: Tue May 09, 2006 10:29 am   
User avatar
I am routinely hit by MyCanadianPharmacy spams at one of my email addresses, so it's nice to see that you're attacking people of similar ilk (or even the same people, possibly).

Fake orders, this is a thing of beauty.


Top
  
 PostPosted: Tue May 09, 2006 1:24 pm   
Site Admin
User avatar

Joined: Tue May 09, 2006 9:18 am
Posts: 5022
http://www.mytempdir.com/654117

Updated with still more of the spamvertised links.

I wonder if they're spamming more because I'm sending this to more forums... Hmmm....?

Enjoy!

SiL


Top
 Profile  
 PostPosted: Tue May 09, 2006 2:26 pm   
Spammer Killing Machine
User avatar

Joined: Tue May 09, 2006 11:34 am
Posts: 466
spamislame wrote:
http://www.mytempdir.com/654117

Updated with still more of the spamvertised links.

I wonder if they're spamming more because I'm sending this to more forums... Hmmm....?

Enjoy!

SiL

Hey that IS fun! :D Not sure about euphoric but certainly satisfying..


Top
 Profile  
 PostPosted: Tue May 09, 2006 3:35 pm   
User avatar
Well, it looks like I've been IP banned. :roll: (They can dish it out but they can't take it.) I did get about a dozen 'orders' in though. :)

In hindsight, I think it'd be effective to open this in about 20 or more Firefox tabs and just have at it setting them all up, one after another, then press submit on each in quick succession.


Top
  
 PostPosted: Tue May 09, 2006 4:08 pm   
Site Admin
User avatar

Joined: Tue May 09, 2006 9:18 am
Posts: 5022
CG wrote:
Well, it looks like I've been IP banned. :roll: (They can dish it out but they can't take it.) I did get about a dozen 'orders' in though. :)


Yeah they do tend to notice. You can attempt via proxies also. :)

Also: try spacing them out over the day. Sorta like a coffee break.

CG wrote:
In hindsight, I think it'd be effective to open this in about 20 or more Firefox tabs and just have at it setting them all up, one after another, then press submit on each in quick succession.


I guess in theory it's possible. Should give it a try. :) "Order throttling". Who knew?

Thanx for the feedback all. I'll continue to update as I receive more (and god knows they certainly aren't stopping.)

SiL


Top
 Profile  
 PostPosted: Wed May 10, 2006 8:55 am   
Site Admin
User avatar

Joined: Tue May 09, 2006 9:18 am
Posts: 5022
Is here:

http://www.mytempdir.com/655728

Several of the domains are staying up. This is totally unusual.

Thanks to those who continue to use it. I know it eats up a bit of time. But it's fun.

One user yesterday claims to have posted several hundred orders. :) Whuhoo!

SiL


Top
 Profile  
 PostPosted: Wed May 10, 2006 1:03 pm   
Site Admin
User avatar

Joined: Tue May 09, 2006 9:18 am
Posts: 5022
http://www.mytempdir.com/656348

Newer still! They apparently really want these orders :)

SiL


Top
 Profile  
 PostPosted: Thu May 11, 2006 4:20 am   
User avatar
Adding some kind of random proxy access to this would be really helpful I think. I noticed something similar being done with the vampires in another thread, but my Javascript skills aren't suffient...


Top
  
 PostPosted: Thu May 11, 2006 8:50 am   
Site Admin
User avatar

Joined: Tue May 09, 2006 9:18 am
Posts: 5022
http://www.mytempdir.com/658165

It now features 10 domains. I'm also noticing that they randomly refuse certain orders, but at least it eats up their database CPU. :)

I'm complaining to the web host as well. This is the longest I've seen these stay up.

Spammers suck. :(

And I agree that some form of proxy rotation would also be a good idea. Hmm... I'll try that as a "next version" piece.

SiL


Top
 Profile  
 PostPosted: Thu May 11, 2006 9:26 am   
Spam Investigator
User avatar

Joined: Thu May 11, 2006 4:24 am
Posts: 390
Location: Canada
Hmm, I seem to have been unbanned this morning and have gotten twenty or so orders in. :P

Hopefully contacting the upstream service providers will help, that is to say, hopefully these sites aren't hosted on spam-friendly servers.


Top
 Profile  
 PostPosted: Thu May 11, 2006 9:36 am   
Spam Investigator
User avatar

Joined: Thu May 11, 2006 4:24 am
Posts: 390
Location: Canada
Just got spammed by these idiots and I didn't find the domain in domains.js, so here's one to add to the program:

www.enfagerusan.com

:evil:


Top
 Profile  
 PostPosted: Thu May 11, 2006 12:45 pm   
Site Admin
User avatar

Joined: Tue May 09, 2006 9:18 am
Posts: 5022
Duly noted!

There are others as well, of course.

Gr!

http://www.mytempdir.com/658665

Newest update. :)

Thanx for the info.

SiL


Top
 Profile  
 [ 214 posts ]  Go to page 1, 2, 3, 4, 5 ... 15  Next

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Bing [Bot], Wayback machine, Yahoo [Bot] and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  


Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group
Style originally created by Volize © 2003 • Redesigned SkyLine by MartectX © 2008