Getting Scam from WP

what i get in my inbox, mods should pay attention to this.

[quote=", post:, topic:"]
ali55 from A Pakistani Tech forum has sent you a message. You can reply to ali55 by replying to this e-mail.

The message reads as follows:


Dearest One,

With warm heart, I offer my friendship, and greetings. However, strange or

surprising this contact might seem to you, as we have not met personally or had

any dealings in the past. I humbly ask that you take due consideration of its

importance and immense benefit.

My name is Ali Rashid, from Ghana. I have a reasonable amount of money

inherited from my late father which I would like to invest in your country

with a very and honest person and again, in a very profitable venture. And for

you being in a business line and for your country being so peaceful I think

you are in a good position to assist me.

Time is not on my side, I will appreciate if you can reply me immediately you

receive this letter so that I can give you more information about my proposal.

Please reply me on this email address ( ).

I’m looking forward to hear from you.

Warmest regards,

Ali Rashid.



A Pakistani Tech forum Mailer


Anyone else received this msg?

not yet

i didn't receive any either, this is a carbon copy of NIGERIAN SCAM, anyway i am still having hard time believing that someone would waste time from this forum to do stupid thing like this.

but if your above post is truth, then please include the e-mail header proving that you really received from WP and Admin team should check the header against the forum log, otherwise i think you are CRYING WOLF.

check his profile,

@ kudos, i m not a weeping baby, i just informed mods.

from ali55


date Thu, Aug 7, 2008 at 9:30 PM

subject Salaam Alaikum,


is this sent by ali55 or some virus sent scam. This can be answered by ali55. if ali55 not post reply than he must be scam sender and should be band.

^ send the above info and also include IPs to Admin team and let them check out, they'll let us if we should be careful from ali55 dude.


this mail sent to my another ID (which is banned).

and i think you can check this 101% chances that forums mailer LOGS all activity.

complete headers

[quote=", post:, topic:"]

Received: by with SMTP id d20cs58110ebb;

Thu, 7 Aug 2008 09:30:12 -0700 (PDT)

Received: by with SMTP id h8mr2644602qaa.90.1218126611059;

Thu, 07 Aug 2008 09:30:11 -0700 (PDT)


Received: from ( [])

by with ESMTP id 6si5035429ywi.1.2008.;

Thu, 07 Aug 2008 09:30:11 -0700 (PDT)

Received-SPF: pass ( best guess record for domain of designates as permitted sender) client-ip=;

Authentication-Results:; spf=pass ( best guess record for domain of designates as permitted sender)

Received: from wiredpak by with local (Exim 4.69)

(envelope-from )

id 1KR8NL-0000Ts-PU

for; Thu, 07 Aug 2008 12:30:07 -0400


Subject: Salaam Alaikum,

From: "ali55"

Date: Thu, 07 Aug 2008 16:30:07 +0000

MIME-Version: 1.0

Content-transfer-encoding: 8bit

Content-type: text/plain; charset=utf-8

X-Mailer: PunBB Mailer


X-AntiAbuse: This header was added to track abuse, please include it with any abuse report

X-AntiAbuse: Primary Hostname -

X-AntiAbuse: Original Domain -

X-AntiAbuse: Originator/Caller UID/GID - [32329 500] / [47 12]

X-AntiAbuse: Sender Address Domain -

X-Source: /usr/bin/php

X-Source-Args: /usr/bin/php misc.php



kudos take your words back. i showed.

i have taken my words back, i'll refund your money which you paid for my words, 4 rupees and 35 paisas do you want cheque or cash. lol


Can you give 35 pisa? You got some old coins of lesser than 50 paisas?

@ kudos :D

do u want argument ? come to IRC channel, i have best reply.

[quote=", post:, topic:"]

@ kudos :D

do u want argument ? come to IRC channel, i have best reply.


we talked on irc chat we are friends now

yes we are.

i just wanted to inform mods abt this scam thing. i done my job.



How about 35 paisas? lolzzzzz

Just wanted to add that I got this mail too. Message was the same as TA's.

[quote=", post:, topic:"]

… and for your country being so peaceful…


its a "form mailer ".. what is interested in is the "misc.php" file seen in the headers above... smtp relay wasnt used for it..

X-Mailer: PunBB Mailer

X-Source: /usr/bin/php

X-Source-Args: /usr/bin/php misc.php


and here is the HACK>>

PunBB is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the misc.php script. A remote attacker could exploit ......


not uncommon..

Updated the forum software, the above issues should be fixed now.

^thanks alot KO

though the formating is a little off