<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Warning: Jade Tiger Pet a Scam</title>
	<atom:link href="http://www.worldofmatticus.com/2009/11/20/warning-jade-tiger-pet-a-scam/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.worldofmatticus.com/2009/11/20/warning-jade-tiger-pet-a-scam/</link>
	<description>Where healers come first</description>
	<lastBuildDate>Fri, 19 Mar 2010 16:54:17 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Maaya</title>
		<link>http://www.worldofmatticus.com/2009/11/20/warning-jade-tiger-pet-a-scam/comment-page-1/#comment-24699</link>
		<dc:creator>Maaya</dc:creator>
		<pubDate>Mon, 23 Nov 2009 17:09:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.worldofmatticus.com/?p=6661#comment-24699</guid>
		<description>E-mail header has never been a reliable security mechanism. And with commercial interest from big names like Microsoft and other legal obstruction (like the US munitions export regulations) standing in the way, there&#039;s still a long way to go before email security come to the average user.
.-= Maaya&#180;s last blog ..&lt;a href=&quot;http://maayadiary.blogspot.com/2009/11/leveling-druids-guide-to-healing.html&quot; rel=&quot;nofollow&quot;&gt;Leveling Druid&#039;s Guide to Healing Utgarde Keep&lt;/a&gt; =-.</description>
		<content:encoded><![CDATA[<p>E-mail header has never been a reliable security mechanism. And with commercial interest from big names like Microsoft and other legal obstruction (like the US munitions export regulations) standing in the way, there&#8217;s still a long way to go before email security come to the average user.<br />
<span class="cluv"> Maaya&#180;s last blog ..<a href="http://maayadiary.blogspot.com/2009/11/leveling-druids-guide-to-healing.html" rel="nofollow">Leveling Druid&#8217;s Guide to Healing Utgarde Keep</a> <span class="heart_tip_box"><img class="heart_tip" alt="My ComLuv Profile" border="0" width="16" height="14" src="http://www.worldofmatticus.com/wp-content/plugins/commentluv/images/littleheart.gif"/></span></span></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan-Cat</title>
		<link>http://www.worldofmatticus.com/2009/11/20/warning-jade-tiger-pet-a-scam/comment-page-1/#comment-24694</link>
		<dc:creator>Dan-Cat</dc:creator>
		<pubDate>Mon, 23 Nov 2009 14:58:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.worldofmatticus.com/?p=6661#comment-24694</guid>
		<description>On the splash screen when logging into WOW last night the tip I read was that Blizzard will only send emails from blizzard.com and battle.net. This tip seems fairly useless if the hacking of the from address is &#039;trivial&#039;</description>
		<content:encoded><![CDATA[<p>On the splash screen when logging into WOW last night the tip I read was that Blizzard will only send emails from blizzard.com and battle.net. This tip seems fairly useless if the hacking of the from address is &#8216;trivial&#8217;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lissanna</title>
		<link>http://www.worldofmatticus.com/2009/11/20/warning-jade-tiger-pet-a-scam/comment-page-1/#comment-24666</link>
		<dc:creator>Lissanna</dc:creator>
		<pubDate>Sat, 21 Nov 2009 05:34:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.worldofmatticus.com/?p=6661#comment-24666</guid>
		<description>I get spam e-mail to my blog&#039;s e-mail address, however my battle.net e-mail is NOT the same as the one I post on my blog.
.-= Lissanna&#180;s last blog ..&lt;a href=&quot;http://www.restokin.com/2009/11/save-the-turkeykin/&quot; rel=&quot;nofollow&quot;&gt;Save the turkeykin!&lt;/a&gt; =-.</description>
		<content:encoded><![CDATA[<p>I get spam e-mail to my blog&#8217;s e-mail address, however my battle.net e-mail is NOT the same as the one I post on my blog.<br />
<span class="cluv"> Lissanna&#180;s last blog ..<a href="http://www.restokin.com/2009/11/save-the-turkeykin/" rel="nofollow">Save the turkeykin!</a> <span class="heart_tip_box"><img class="heart_tip" alt="My ComLuv Profile" border="0" width="16" height="14" src="http://www.worldofmatticus.com/wp-content/plugins/commentluv/images/littleheart.gif"/></span></span></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mystiplix</title>
		<link>http://www.worldofmatticus.com/2009/11/20/warning-jade-tiger-pet-a-scam/comment-page-1/#comment-24660</link>
		<dc:creator>Mystiplix</dc:creator>
		<pubDate>Fri, 20 Nov 2009 22:31:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.worldofmatticus.com/?p=6661#comment-24660</guid>
		<description>There is nothing in the SMTP (mail transport) RFC preventing incorrect from addresses being used. Nor anything in the transport chain that demands the sender actually have the rights to send mail from that address. Some systems are trying to put such things in place - but that&#039;s a much larger issue and this comment is not really the best place to talk about how mail servers work, and what sort of options are around to deal with this sort of thing

Matticus isn&#039;t sharing full email headers, so we can&#039;t see the chain of the mail, which likely doesn&#039;t pass through any valid/typical blizzard servers, and if  Blizzard declares SPF records it would certainly fail an SPF test. A test and check that is totally optional. 

The last one of these kinds of mails I got were also not to my Battlenet email address and I believe they&#039;d farmed it out of a comment or post on a wow forum or perhaps from epicadvice.</description>
		<content:encoded><![CDATA[<p>There is nothing in the SMTP (mail transport) RFC preventing incorrect from addresses being used. Nor anything in the transport chain that demands the sender actually have the rights to send mail from that address. Some systems are trying to put such things in place &#8211; but that&#8217;s a much larger issue and this comment is not really the best place to talk about how mail servers work, and what sort of options are around to deal with this sort of thing</p>
<p>Matticus isn&#8217;t sharing full email headers, so we can&#8217;t see the chain of the mail, which likely doesn&#8217;t pass through any valid/typical blizzard servers, and if  Blizzard declares SPF records it would certainly fail an SPF test. A test and check that is totally optional. </p>
<p>The last one of these kinds of mails I got were also not to my Battlenet email address and I believe they&#8217;d farmed it out of a comment or post on a wow forum or perhaps from epicadvice.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Argon</title>
		<link>http://www.worldofmatticus.com/2009/11/20/warning-jade-tiger-pet-a-scam/comment-page-1/#comment-24659</link>
		<dc:creator>Argon</dc:creator>
		<pubDate>Fri, 20 Nov 2009 22:26:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.worldofmatticus.com/?p=6661#comment-24659</guid>
		<description>&quot;from&quot; addresses are trivially faked in email.</description>
		<content:encoded><![CDATA[<p>&#8220;from&#8221; addresses are trivially faked in email.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: We Fly Spitfires</title>
		<link>http://www.worldofmatticus.com/2009/11/20/warning-jade-tiger-pet-a-scam/comment-page-1/#comment-24657</link>
		<dc:creator>We Fly Spitfires</dc:creator>
		<pubDate>Fri, 20 Nov 2009 22:00:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.worldofmatticus.com/?p=6661#comment-24657</guid>
		<description>Wow, that is a very clever spam email. No doubt it will take you to some site with an obscure URL but styled like the official Blizzard site, asking you to log in so they can capture your log in details.

I&#039;m surprised they managed to send using &quot;email.blizzard.com&quot;. I would&#039;ve thought Blizzard would&#039;ve had that locked down tight.
.-= We Fly Spitfires&#180;s last blog ..&lt;a href=&quot;http://feedproxy.google.com/~r/WeFlySpitfires/~3/gidjVdjOeg0/&quot; rel=&quot;nofollow&quot;&gt;The RMT Industry - What I’ve Learnt&lt;/a&gt; =-.</description>
		<content:encoded><![CDATA[<p>Wow, that is a very clever spam email. No doubt it will take you to some site with an obscure URL but styled like the official Blizzard site, asking you to log in so they can capture your log in details.</p>
<p>I&#8217;m surprised they managed to send using &#8220;email.blizzard.com&#8221;. I would&#8217;ve thought Blizzard would&#8217;ve had that locked down tight.<br />
<span class="cluv"> We Fly Spitfires&#180;s last blog ..<a href="http://feedproxy.google.com/~r/WeFlySpitfires/~3/gidjVdjOeg0/" rel="nofollow">The RMT Industry &#8211; What I’ve Learnt</a> <span class="heart_tip_box"><img class="heart_tip" alt="My ComLuv Profile" border="0" width="16" height="14" src="http://www.worldofmatticus.com/wp-content/plugins/commentluv/images/littleheart.gif"/></span></span></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Psynister</title>
		<link>http://www.worldofmatticus.com/2009/11/20/warning-jade-tiger-pet-a-scam/comment-page-1/#comment-24655</link>
		<dc:creator>Psynister</dc:creator>
		<pubDate>Fri, 20 Nov 2009 20:46:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.worldofmatticus.com/?p=6661#comment-24655</guid>
		<description>Haven&#039;t gotten the email yet myself. 

Personally, I don&#039;t believe any WoW-related emails unless I see Blizzard themselves advertising it on the launch screen.
.-= Psynister&#180;s last blog ..&lt;a href=&quot;http://psynister.wordpress.com/2009/11/19/alternate-universe/&quot; rel=&quot;nofollow&quot;&gt;Alt’ernate Universe&lt;/a&gt; =-.</description>
		<content:encoded><![CDATA[<p>Haven&#8217;t gotten the email yet myself. </p>
<p>Personally, I don&#8217;t believe any WoW-related emails unless I see Blizzard themselves advertising it on the launch screen.<br />
<span class="cluv"> Psynister&#180;s last blog ..<a href="http://psynister.wordpress.com/2009/11/19/alternate-universe/" rel="nofollow">Alt’ernate Universe</a> <span class="heart_tip_box"><img class="heart_tip" alt="My ComLuv Profile" border="0" width="16" height="14" src="http://www.worldofmatticus.com/wp-content/plugins/commentluv/images/littleheart.gif"/></span></span></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Angry Gamer</title>
		<link>http://www.worldofmatticus.com/2009/11/20/warning-jade-tiger-pet-a-scam/comment-page-1/#comment-24654</link>
		<dc:creator>Angry Gamer</dc:creator>
		<pubDate>Fri, 20 Nov 2009 20:43:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.worldofmatticus.com/?p=6661#comment-24654</guid>
		<description>Very nasty and tricky. This is a new approach for sure evil bastards!
.-= Angry Gamer&#180;s last blog ..&lt;a href=&quot;http://angrygamer09.wordpress.com/2009/11/20/do-guild-applications-still-work/&quot; rel=&quot;nofollow&quot;&gt;Do guild applications still work?&lt;/a&gt; =-.</description>
		<content:encoded><![CDATA[<p>Very nasty and tricky. This is a new approach for sure evil bastards!<br />
<span class="cluv"> Angry Gamer&#180;s last blog ..<a href="http://angrygamer09.wordpress.com/2009/11/20/do-guild-applications-still-work/" rel="nofollow">Do guild applications still work?</a> <span class="heart_tip_box"><img class="heart_tip" alt="My ComLuv Profile" border="0" width="16" height="14" src="http://www.worldofmatticus.com/wp-content/plugins/commentluv/images/littleheart.gif"/></span></span></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: krizhek</title>
		<link>http://www.worldofmatticus.com/2009/11/20/warning-jade-tiger-pet-a-scam/comment-page-1/#comment-24652</link>
		<dc:creator>krizhek</dc:creator>
		<pubDate>Fri, 20 Nov 2009 20:36:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.worldofmatticus.com/?p=6661#comment-24652</guid>
		<description>Wow this is some serious work behind making this like the real thing.</description>
		<content:encoded><![CDATA[<p>Wow this is some serious work behind making this like the real thing.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
