Educause Security Discussion mailing list archives

DMCA Reports and No-Reply Addresses


From: Eric Pancer <epancer () SECURITY DEPAUL EDU>
Date: Wed, 29 Dec 2004 18:30:49 -0600

[ I apologize in advance if you have received this in another forum. ]

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

It's almost 2005, and more games have started with the DMCA
"enforcers." We received a notice today from BayTSP with the
following "From" and "Reply-To" set:

<universal-studios-no-reply () champ baytsp com>

Replying to this address offers the following error.

<universal-studios-no-reply () champ baytsp com>:
Sorry, I couldn't find any host named champ.baytsp.com. (#5.1.2)

Embedded in the email is the following blob:

"
  All correspondence regarding this notice should be sent to:

  <http://webreply.baytsp.com/webreply/webreply.jsp?customerid=XX&commhash=XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX>

"

Note that anyone can go to this page, no authentication is required.
Then, you'll get to waste your time filling in the pretty boxes
(note that you've already wasted your time by having to open up a
browser since you don't use a graphical email client (you don't,
right?)). The three options you can select are:

"
  1. I've complied and removed all copyrighted material for which
     I'm not the copyright holder

  2. No, I've not complied and I'm still distributing copyrighted
     material.

  3. Mistake, You sent the notice to the wrong person (fill in more
     detail below).

"

You'll then have to check a box that states...

" By checking this box I swear that I have provided truthful
information."

So, for all of you that have automated processing of incoming DMCA
reports, Happy New Year, and get to work on some automated things to
select option #3 above using curl!

- --
Eric Pancer :.: Computer Security Response Team :.: DePaul University
http://security.depaul.edu/ .:`:.:':.:`:. epancer () security depaul edu
pgp: 1024D/7ACBCFF3 C022 4991 41E5 51E7 683C F765 62F7 7F8E 7ACB CFF3

-----BEGIN PGP SIGNATURE-----

iQEVAwUBQdNDvBg79iScdnghAQLckAf9EYloFHz3SEf8QSFYTtAyHCUmFkxcGX3G
afMG67Z8Pl13WUjS2QwSNxJNjuLPLNeEW9K/gsJ60+plH/xVAKO50MEAtCOkOStS
Q2euJRI6tcjSxrZ8P0amfr01g3ixf4ZXpES3biohTIw4QF8hRFHK+b3bGe4rEaN6
0RU+NCtA0FdbOwqNWAoDnG+pr1rrvS7IHQecLq8vfqtYneIrbBzHW4/cCtM6+Tz2
0e/UsddgJiPslQ9sqPLvY23psroszAo0QvsR2R7gjq/L5qkUSmYzdJBFzdof5eRM
xJydYvzsKMq0a46Pj9CmuEMPGey2kSvXtW+D2BIW6JlcF7aD2Q8tcA==
=B7Rj
-----END PGP SIGNATURE-----

**********
Participation and subscription information for this EDUCAUSE Discussion Group discussion list can be found at 
http://www.educause.edu/groups/.

Current thread: