# Somebody stealing Dope content, again.

**URL:** <https://boards.straightdope.com/t/somebody-stealing-dope-content-again/663152>\
**Category:** About This Message Board\
**Created:** [July 10, 2013, 5:34pm UTC](https://boards.straightdope.com/t/somebody-stealing-dope-content-again/663152 "2013-07-10T17:34:36Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cheshire\_Human](https://avatars.discourse-cdn.com/v4/letter/c/5f8ce5/32.png) [@Cheshire\_Human](https://boards.straightdope.com/u/Cheshire_Human)\
**Post date:** [July 10, 2013, 5:34pm UTC](https://boards.straightdope.com/t/somebody-stealing-dope-content-again/663152/1 "2013-07-10T17:34:36Z")

</div>

Here:

[http://www.remortgagebestdeals.com/sdmb/](http://www.remortgagebestdeals.com/sdmb/)

Possibly also phishing for user names and passwords. Don’t try to log in.

---

<div class="post-metadata">

**Author:** ![Qadgop\_the\_Mercotan](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/qadgop_the_mercotan/32/83_2.png) [@Qadgop\_the\_Mercotan](https://boards.straightdope.com/u/Qadgop_the_Mercotan)\
**Post date:** [July 10, 2013, 5:43pm UTC](https://boards.straightdope.com/t/somebody-stealing-dope-content-again/663152/2 "2013-07-10T17:43:39Z")

</div>

I miss the chicken board…

---

<div class="post-metadata">

**Author:** ![TubaDiva](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tubadiva/32/507_2.png) [@TubaDiva](https://boards.straightdope.com/u/TubaDiva)\
**Post date:** [July 10, 2013, 6:36pm UTC](https://boards.straightdope.com/t/somebody-stealing-dope-content-again/663152/3 "2013-07-10T18:36:36Z")

</div>

I’ll pass this on.

Thanks.

---

<div class="post-metadata">

**Author:** ![Fiveroptic](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fiveroptic/32/8257_2.png) [@Fiveroptic](https://boards.straightdope.com/u/Fiveroptic)\
**Post date:** [July 10, 2013, 7:54pm UTC](https://boards.straightdope.com/t/somebody-stealing-dope-content-again/663152/4 "2013-07-10T19:54:06Z")

</div>

How do they do that? I noticed that this thread is not in their version of ATMB.

---

<div class="post-metadata">

**Author:** ![Marley23](https://avatars.discourse-cdn.com/v4/letter/m/45deac/32.png) [@Marley23](https://boards.straightdope.com/u/Marley23)\
**Post date:** [July 10, 2013, 7:57pm UTC](https://boards.straightdope.com/t/somebody-stealing-dope-content-again/663152/5 "2013-07-10T19:57:50Z")

</div>

> [@Fiveroptic](#):
>
> How do they do that? I noticed that this thread is not in their version of ATMB.

I’m not sure how it works, but however they copied the content, they did it around 8:37 Eastern last night. You can see there are no posts more recent than that.

---

<div class="post-metadata">

**Author:** ![Skywatcher](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/skywatcher/32/254_2.png) [@Skywatcher](https://boards.straightdope.com/u/Skywatcher)\
**Post date:** [July 10, 2013, 8:30pm UTC](https://boards.straightdope.com/t/somebody-stealing-dope-content-again/663152/6 "2013-07-10T20:30:04Z")

</div>

Whomever is behind that has been targeting other boards as well.

> **[cnnreporter.com, Neoseeker cloned website - Site/Forums Help and QA](https://www.neoseeker.com/forums/56/t1858634-cnnreporter-com-neoseeker-cloned-website/)**
>
> So first off, I'm not sure if this URL is registered to anyone affiliated with Neoseeker but going to the address cnnrepo

> **[MacRumors clone @ mychildrenhealth.com](https://forums.macrumors.com/threads/macrumors-clone-mychildrenhealth-com.1565555/)**
>
> If you go to http://mychildrenhealth.com/ or http://forums.mychildrenhealth.com/ you end up at what looks like a MacRumors clone. It's not a redirect, because the domain stays at http://mychildrenhealth.com/ whilst you browse the site, and when I...

---

<div class="post-metadata">

**Author:** ![Duckster](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/duckster/32/1244_2.png) [@Duckster](https://boards.straightdope.com/u/Duckster)\
**Post date:** [July 10, 2013, 9:32pm UTC](https://boards.straightdope.com/t/somebody-stealing-dope-content-again/663152/7 "2013-07-10T21:32:46Z")

</div>

> [@](#):
>
> Domain name: [REMORTGAGEBESTDEALS.COM](http://REMORTGAGEBESTDEALS.COM)
> 
> Administrative Contact: Keva Reed ([fenzu.333@gmail.com](mailto:fenzu.333@gmail.com))  
> +1.9899281913  
> Fax: 4738 Juniper Drive  
> Saginaw, AL 48607
> 
> US Technical Contact: Keva Reed ([fenzu.333@gmail.com](mailto:fenzu.333@gmail.com))  
> +1.9899281913  
> Fax: 4738 Juniper Drive  
> Saginaw, AL 48607
> 
> US Registrant Contact: Keva Reed ()  
> Fax: 4738 Juniper Drive  
> Saginaw, AL 48607
> 
> US Status: Locked
> 
> Name Servers:  
> [lola.ns.cloudflare.com](http://lola.ns.cloudflare.com)  
> [norm.ns.cloudflare.com](http://norm.ns.cloudflare.com)
> 
> Creation date: 14 Mar 2013 01:58:41  
> Expiration date: 14 Mar 2014 01:58:00

A Google search [on the street address](https://www.google.com/search?q=Keva+Reed&ie=utf-8&oe=utf-8&aq=t&rls=org.mozilla:en-US:official&client=firefox-a#client=firefox-a&hs=NK3&rls=org.mozilla:en-US%3Aofficial&sclient=psy-ab&q=4738+Juniper+Drive++++Saginaw%2C+AL+48607&oq=4738+Juniper+Drive++++Saginaw%2C+AL+48607&gs_l=serp.3...17814.17814.0.18452.1.1.0.0.0.0.293.293.2-1.1.0....0...1c.1.19.psy-ab.tGyuwuz1joM&pbx=1&bav=on.2,or.r_qf.&bvm=bv.48705608,d.cGE&fp=f63cc7b990c20fb7&biw=1177&bih=702) of the registrant shows a diversity of domain names with a decidedly marketing bent. The street address does not jive with Google Maps nor [zillow.com](http://zillow.com). IIRC, that means a fraudulent domain registration under ICANN rules.

The phone number is a wireless line managed by Verizon.

---

<div class="post-metadata">

**Author:** ![Czarcasm](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/czarcasm/32/4050_2.png) [@Czarcasm](https://boards.straightdope.com/u/Czarcasm)\
**Post date:** [July 10, 2013, 9:37pm UTC](https://boards.straightdope.com/t/somebody-stealing-dope-content-again/663152/8 "2013-07-10T21:37:39Z")

</div>

> [@Duckster](#):
>
> A Google search [on the street address](https://www.google.com/search?q=Keva+Reed&ie=utf-8&oe=utf-8&aq=t&rls=org.mozilla:en-US:official&client=firefox-a#client=firefox-a&hs=NK3&rls=org.mozilla:en-US%3Aofficial&sclient=psy-ab&q=4738+Juniper+Drive++++Saginaw%2C+AL+48607&oq=4738+Juniper+Drive++++Saginaw%2C+AL+48607&gs_l=serp.3...17814.17814.0.18452.1.1.0.0.0.0.293.293.2-1.1.0....0...1c.1.19.psy-ab.tGyuwuz1joM&pbx=1&bav=on.2,or.r_qf.&bvm=bv.48705608,d.cGE&fp=f63cc7b990c20fb7&biw=1177&bih=702) of the registrant shows a diversity of domain names with a decidedly marketing bent. The street address does not jive with Google Maps nor [zillow.com](http://zillow.com). IIRC, that means a fraudulent domain registration under ICANN rules.
> 
> The phone number is a wireless line managed by Verizon.

If I read the other forums correctly, if you plug in just the street address and the zip code, it might give you the correct state.

---

<div class="post-metadata">

**Author:** ![Czarcasm](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/czarcasm/32/4050_2.png) [@Czarcasm](https://boards.straightdope.com/u/Czarcasm)\
**Post date:** [July 10, 2013, 9:43pm UTC](https://boards.straightdope.com/t/somebody-stealing-dope-content-again/663152/9 "2013-07-10T21:43:37Z")

</div>

> [@Czarcasm](#):
>
> If I read the other forums correctly, if you plug in just the street address and the zip code, it might give you the correct state.

The correct state is MI, not AL. The rest of the address is correct.

---

<div class="post-metadata">

**Author:** ![Bullitt](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bullitt/32/5725_2.png) [@Bullitt](https://boards.straightdope.com/u/Bullitt)\
**Post date:** [July 11, 2013, 2:57am UTC](https://boards.straightdope.com/t/somebody-stealing-dope-content-again/663152/10 "2013-07-11T02:57:08Z")

</div>

> [@Cheshire\_Human](#):
>
> Here:
> 
> [http://www.remortgagebestdeals.com/sdmb/](http://www.remortgagebestdeals.com/sdmb/)
> 
> Possibly also phishing for user names and passwords. Don’t try to log in.

That is wild. Didn’t know such a thing could be done.  
To repeat **Cheshire Human** : do not log on there.

---

<div class="post-metadata">

**Author:** ![Little\_Nemo](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/little_nemo/32/3120_2.png) [@Little\_Nemo](https://boards.straightdope.com/u/Little_Nemo)\
**Post date:** [July 11, 2013, 3:45am UTC](https://boards.straightdope.com/t/somebody-stealing-dope-content-again/663152/11 "2013-07-11T03:45:55Z")

</div>

> [@Duckster](#):
>
> The street address does not jive with Google Maps nor [zillow.com](http://zillow.com). IIRC, that means a fraudulent domain registration under ICANN rules.

So abort the drone strike?

Need answer fast.

---

<div class="post-metadata">

**Author:** ![Musicat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/musicat/32/20189_2.png) [@Musicat](https://boards.straightdope.com/u/Musicat)\
**Post date:** [July 11, 2013, 3:53am UTC](https://boards.straightdope.com/t/somebody-stealing-dope-content-again/663152/12 "2013-07-11T03:53:41Z")

</div>

> [@echo7tango](#):
>
> To repeat **Cheshire Human** : do not log on there.

How about trying to register a new account for shits & giggles?

---

<div class="post-metadata">

**Author:** ![running\_coach](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/running_coach/32/15836_2.png) [@running\_coach](https://boards.straightdope.com/u/running_coach)\
**Post date:** [July 11, 2013, 4:05am UTC](https://boards.straightdope.com/t/somebody-stealing-dope-content-again/663152/13 "2013-07-11T04:05:02Z")

</div>

> [@Musicat](#):
>
> How about trying to register a new account for shits & giggles?

Just tried. First page is the registration agreement. When you accept that, you get a blank page.  
Like **Cheshire Human** said, they want you to try to log in.

---

<div class="post-metadata">

**Author:** ![moriah](https://avatars.discourse-cdn.com/v4/letter/m/b2d939/32.png) [@moriah](https://boards.straightdope.com/u/moriah)\
**Post date:** [July 11, 2013, 4:08am UTC](https://boards.straightdope.com/t/somebody-stealing-dope-content-again/663152/14 "2013-07-11T04:08:29Z")

</div>

For those new to the 'Net (hey, we keep reproducing!), this is a phishing site. By fooling you into thinking it is one of the top forums on the 'Net, you log on with your username and password.

What good does that do them? They use or sell your username to black hearted folks who try that same combination on lots of other sites to hack into your account because you used the same password on multiple web sites. Don’t do that.

---

<div class="post-metadata">

**Author:** ![running\_coach](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/running_coach/32/15836_2.png) [@running\_coach](https://boards.straightdope.com/u/running_coach)\
**Post date:** [July 11, 2013, 4:18am UTC](https://boards.straightdope.com/t/somebody-stealing-dope-content-again/663152/15 "2013-07-11T04:18:21Z")

</div>

Just tried to log in(made up name/password. Blank page.

---

<div class="post-metadata">

**Author:** ![Bullitt](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bullitt/32/5725_2.png) [@Bullitt](https://boards.straightdope.com/u/Bullitt)\
**Post date:** [July 11, 2013, 4:36am UTC](https://boards.straightdope.com/t/somebody-stealing-dope-content-again/663152/16 "2013-07-11T04:36:25Z")

</div>

> [@moriah](#):
>
> For those new to the 'Net (hey, we keep reproducing!), this is a phishing site. By fooling you into thinking it is one of the top forums on the 'Net, you log on with your username and password.
> 
> What good does that do them? They use or sell your username to black hearted folks who try that same combination on lots of other sites to hack into your account because you used the same password on multiple web sites. Don’t do that.

I use the same user name and password here and also on another forum. Is there any harm in that?

---

<div class="post-metadata">

**Author:** ![Senegoid](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/senegoid/32/6606_2.png) [@Senegoid](https://boards.straightdope.com/u/Senegoid)\
**Post date:** [July 11, 2013, 5:41am UTC](https://boards.straightdope.com/t/somebody-stealing-dope-content-again/663152/17 "2013-07-11T05:41:10Z")

</div>

> [@echo7tango](#):
>
> I use the same user name and password here and also on another forum. Is there any harm in that?

Not necessarily, but it’s considered a bad idea. If anybody manages to find your password on any account, then they have your password on every other web site where you’ve used the same password. That’s what they are looking for. Especially if you use the same password to sign in to your bank account, your credit card account, your doctor’s office, insurance site, . . . You don’t want that to happen.

---

<div class="post-metadata">

**Author:** ![Crazyhorse](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/crazyhorse/32/31_2.png) [@Crazyhorse](https://boards.straightdope.com/u/Crazyhorse)\
**Post date:** [July 11, 2013, 6:54am UTC](https://boards.straightdope.com/t/somebody-stealing-dope-content-again/663152/18 "2013-07-11T06:54:38Z")

</div>

> [@Duckster](#):
>
> A Google search [on the street address](https://www.google.com/search?q=Keva+Reed&ie=utf-8&oe=utf-8&aq=t&rls=org.mozilla:en-US:official&client=firefox-a#client=firefox-a&hs=NK3&rls=org.mozilla:en-US%3Aofficial&sclient=psy-ab&q=4738+Juniper+Drive++++Saginaw%2C+AL+48607&oq=4738+Juniper+Drive++++Saginaw%2C+AL+48607&gs_l=serp.3...17814.17814.0.18452.1.1.0.0.0.0.293.293.2-1.1.0....0...1c.1.19.psy-ab.tGyuwuz1joM&pbx=1&bav=on.2,or.r_qf.&bvm=bv.48705608,d.cGE&fp=f63cc7b990c20fb7&biw=1177&bih=702) of the registrant shows a diversity of domain names with a decidedly marketing bent. The street address does not jive with Google Maps nor [zillow.com](http://zillow.com). IIRC, that means a fraudulent domain registration under ICANN rules.
> 
> The phone number is a wireless line managed by Verizon.

It’s extremely unlikely that this person has any idea their website has been hacked and used this way.

In most cases scraped sites aren’t hosted by the actual scammers. That obviously wouldn’t work out well for them. They find unused or infrequently updated sites with security vulnerabilities and take them over.

The site is hosted by CloudFlare in San Francisco. If they’re notified that it’s a counterfeit site they can shut it down. Then it’s up to them to worry about finding their customer and notifying them the site was hacked.

> [@Marley23](#):
>
> I’m not sure how it works, but however they copied the content, they did it around 8:37 Eastern last night. You can see there are no posts more recent than that.

There are bunches of web scraping programs out there available for free and commercially. They can’t access the SDMB database but they can take an exact snapshot of every public page at a given point in time. Searching the SDMB weblogs should easily find the IP address of the scraper since you know the times of the last posts when the scrape was done.

---

<div class="post-metadata">

**Author:** ![aruvqan](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/aruvqan/32/2891_2.png) [@aruvqan](https://boards.straightdope.com/u/aruvqan)\
**Post date:** [July 11, 2013, 9:33am UTC](https://boards.straightdope.com/t/somebody-stealing-dope-content-again/663152/19 "2013-07-11T09:33:28Z")

</div>

So what happens if you have SD bookmarked and your computer autologs you?

---

<div class="post-metadata">

**Author:** ![Bullitt](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bullitt/32/5725_2.png) [@Bullitt](https://boards.straightdope.com/u/Bullitt)\
**Post date:** [July 11, 2013, 10:50am UTC](https://boards.straightdope.com/t/somebody-stealing-dope-content-again/663152/20 "2013-07-11T10:50:53Z")

</div>

> [@Senegoid](#):
>
> Not necessarily, but it’s considered a bad idea. If anybody manages to find your password on any account, then they have your password on every other web site where you’ve used the same password. That’s what they are looking for. Especially if you use the same password to sign in to your bank account, your credit card account, your doctor’s office, insurance site, . . . You don’t want that to happen.

Okay but if I use the same uName & (simple) pw for message boards, but then a 12-char complex pw for banks, email, doc, etc. I hope I’ll be okay.

I manage my own pws. They’re memorized. I only have 3 pws, the two above and one for work which auto-expires every 90 days.

[Next page](https://boards.straightdope.com/t/somebody-stealing-dope-content-again/663152.md?page=2)
