FreeBSD scraper, spammer

Some entity calling itself OrcaRouter just spammed my inbox, essentially claiming it scraped some FreeBSD site(s) to get my email address. Needless to say, they are now in my spam list, but I think they need further punishment. Like, for one thing, letting the FreeBSD people know what they're up to. Any suggestions for how to reach the appropriate people? Or other suggestions for dealing with those antisocial cretins?
 
If you use that email address at more than one place, kind of hard to say it was scraped from a FreeBSD site.
So what "FreeBSD sites" use an email address?
This one (forums), any FreeBSD mailing list you are subscribed to. I'm not sure if/how many others are there. Mailing lists being publicly viewable, are a prime candidate because anything you send has your email.

So if you are subscribed to a few FreeBSD mailing lists and you've sent at least one your email is visible.
 
Hrrm, your profile doesn't say you're from Nigeria. I suspect you're not being 100 % honest. :)

Bill Blake, I would take it no more seriously than those who send you an email, saying they know what you've been doing because they've hacked your computer, and you can keep them from letting people know by paying them. Just because a scammer says they got your address from somewhere, doesn't mean they're telling the truth. It's probably in their interest to misdirect you about how they got your address.
I realize this is probably something you already know, and just reacted in annoyance when you saw the email, but it might be useful for newcomers to be reminded that spammers and scammers lie.
 
Mailing lists being publicly viewable, are a prime candidate because anything you send has your email.
Not at all limited with @freebsd.org ones, mailing lists are one of the oldest source to obtain someone's email address (another example would be webmaster email addresses). Simply subscribing to any active ML allows to collect active posters' email addresses. No need to cracking / scraping. Just a mutual, historical thing.

Note that some ML servers require to send a email in specific title (notably, "unsubscribe") to regular posting email address regardless its contents (blank is OK), BUT IT'S NOT ALL SERVERS.

For official FreeBSD MLs, need to send to (ML name)+unsubscribe@FreeBSD.org.
For example, if any subscriber want to unsubscribe from stable@freebsd.org, need to send email to stable+unsubscribe@freebsd.org. NOT stable@freebsd.org.

Some ML services would use specific web interface to subscribe, unsubscribe or something else.

Unfortunate fact is that emails titled "unsubscribe" can be seen in such a ML services from email address I've never seen any posts (maybe read-only members).
 
If you use that email address at more than one place, kind of hard to say it was scraped from a FreeBSD site.
So what "FreeBSD sites" use an email address?
This one (forums), any FreeBSD mailing list you are subscribed to. I'm not sure if/how many others are there. Mailing lists being publicly viewable, are a prime candidate because anything you send has your email.

So if you are subscribed to a few FreeBSD mailing lists and you've sent at least one your email is visible.

The spammer said: "we noticed you contributed to freebsd/freebsd-src — thanks for helping build open source. We're running a small program for OSS contributors and would love to invite you." While that *could* be a lie, it seems an odd lie, so I assume they got that email address from something FreeBSD. But the only FreeBSD-related place where I use the spammed address is bugs.freebsd.org. So it's a near certainty that that's where they got it.
 
It's possible that OrcaRouter is lying, because spammers aren't the most honest people who will email you.
No kidding--I've been dealing with spammers since the 90s. But their pitch began, "we noticed you contributed to freebsd/freebsd-src — thanks for helping build open source. We're running a small program for OSS contributors and would love to invite you." which would seem to be an odd lie to spam to a random address list. Odds are they got the spammed address from bugs.freebsd.org and from a recent listing of bugs, since that's the only FreeBSD-related place I use that address, and I only started using that address there a few weeks ago.
 
I seriously doubt that bugs.freebsd.org sold my info. :) It's extremely likely that that's where the address came from. So I assume a scraper.
Scraping isn't a particular technique. It's harvesting large amounts of public content that everybody can read. Maybe after registratiion.
You probably dropped an email address somewhere that's publicly visible or known by a group of which some members collect information of others.
 
Spammers harvest mail address. Unless you use a unique one for every service, you do not know from where they got it. Some spammers may also subscribe to mailing lists to get all the addresses used there. There is nothing you can do about it, but you can place spam traps in your signature etc. that causes the spammers to harvest them too and send mail to them - to get blacklisted. As I operate my own mail server, I can then check against those lists.
 
I didn't come here to be condescendingly told elementary facts that I've already taken into account. If someone wants to actually answer my question--where I should pass my info to--great. If not, I'll be just as happy to forget the issue and whoever is running bugs can deal with it when the complaints get loud enough.
 
... the only FreeBSD-related place where I use the spammed address is bugs.freebsd.org. So it's a near certainty that that's where they got it.

If you posted on a public mailing list, which appears to be the case, then that's where your email was scraped from. Not entirely sure what you expect the "FreeBSD people" to do about that?
 

Took me two seconds to find. I'm quite sure spammers pilfer various public mailing lists. Though it's obfuscated, it's still quite easy to find lots of email addresses.
Except...that's not the address that got spammed. I have oh, maybe a dozen email addresses I use for various purposes. Like I said, the spammed address is one I hadn't used for anything FreeBSD related until fairly recently and then only on bugs.
 
Odds are they got the spammed address from bugs.freebsd.org and from a recent listing of bugs, since that's the only FreeBSD-related place I use that address, and I only started using that address there a few weeks ago.
As you may know, Bugzilla has a functionality to send email to the reporter, maintainer, assignee and anyone want to be CC'ed.

And there are some group maintainers and some areas without maintainers.

For example, if group maintainer X11 is responsible, emails to the maintainer are sent to freebsd-x11 mailing list.

If the PR is about ports and there are no maintainer for the port, emails to the maintainer are sent to freebsd-ports-bugs ML.

If the PR is about base OS, emails to the maintainer are typically sent to freebsd-bugs ML first until triaged and assigned to specific committer.

And more, if anyone on the PR thinks it worth notified widely among affected users, for example, a number of users of main branch of base OS, freebsd-current ML may be CC'ed.
 
Except...that's not the address that got spammed. I have oh, maybe a dozen email addresses I use for various purposes. Like I said, the spammed address is one I hadn't used for anything FreeBSD related until fairly recently and then only on bugs.
bugs.freebsd.org is just a mailing list with a fancy frontend. The frontend shows mail addresses in cleartext; just hover over the names above every comment or in the header details (and obviously the CC list).
 
As you may know, Bugzilla has a functionality to send email to the reporter, maintainer, assignee and anyone want to be CC'ed.
The only bug I have reported since I started using the new email address was on July 9, a pefs-kmod bug, and that port has a maintainer who is the only one cc'd. I kinda doubt he'd be spamming me. :)
 
bugs.freebsd.org is just a mailing list with a fancy frontend. The frontend shows mail addresses in cleartext; just hover over the names above every comment or in the header details (and obviously the CC list).
Sure. And if someone is bypassing that fancy anti-bot annoyance in that fancy frontend to scrape addresses, one would think the admins would want to know.
 
The only bug I have reported since I started using the new email address was on July 9, a pefs-kmod bug, and that port has a maintainer who is the only one cc'd. I kinda doubt he'd be spamming me. :)
PR 296641, right?
It's assigned to freebsd-ports-bugs (Nobody), means, email is sent to freebsd-ports-bugs ML. It's NOT A SPECIFIC INDIVIDUAL PERSON.
screenshot_PR296641_2026-08-03.png

Note that, as far as I've told before, Assignee needs to be a committer, otherwise whichever freebsd-ports-bugs ML or freebsd-bugs ML to allow any committer to self-assign (if I recall correctly, reassigned to freebsd-ports-bugs (Nobody) by a triager with comment, when I've manually assigned to the non-committer maintainer).
 
PR 296641, right?
It's assigned to freebsd-ports-bugs (Nobody), means, email is sent to freebsd-ports-bugs ML. It's NOT A SPECIFIC INDIVIDUAL PERSON.
View attachment 26874
Note that, as far as I've told before, Assignee needs to be a committer, otherwise whichever freebsd-ports-bugs ML or freebsd-bugs ML to allow any committer to self-assign (if I recall correctly, reassigned to freebsd-ports-bugs (Nobody) by a triager with comment, when I've manually assigned to the non-committer maintainer).
Well then, I was mistaken. So it's possible it was taken from that mailing list rather than from the site itself. Either way, it's the first time in, oh, maybe 35 years (yes, I've been around since 386BSD) that I've received spam that seemed related to FreeBSD, and it was a recent scrape. So I sent a message off, did my little bit of civic duty, and the rest is nattering.
 
Back
Top