Charity-collecting tout now hacks into users accounts

You’ll remember earlier in the week when we posted the screenshots and text from Johnny H’s last post on Koptalk. After being a member for over three years, in which time he’d posted information he’d been party to relating to potential transfer deals and so on, he felt it was time to move on. Except it wasn’t his last post after all.

His post was well written but wasn’t particularly nasty towards Duncan Oldham. (Duncan Oldham is the owner of Koptalk.coN, and a confirmed ticket tout, and internet conman). Compared to some we’ve seen it was quite polite. Dunk had done well out of Johnny over those three years, no doubt at all. People stayed because of information from people like Johnny. No doubt those people told their own friends about this kind of information and more members would be enticed in. That’s in no way an attack on Johnny or any of the others who would share this information with fellow forum members. They didn’t know at the time just what sort of person they were helping. They’d never really thought about how much money Oldham was making. The £30 memberships stack up though – Oldham should be grateful.

He isn’t though is he? He is never grateful for anything. He exploits everyone, always has done.

He banned Johnny. Then Johnny clicked the wrong bookmark in his browser, and instead of the message saying “You’re banned” (or “You’ve banned yourself” probably) he found he was back inside Koptalk. He had a look around, and had a look for his last post. It was gone, but there was something very worrying there in the list of posts.

A post in his name, after he’d already left.

Someone had hacked into his account.

#41232 – Yesterday at 09:38 AM
Re: I am in shock…. [Re: Taffy]
Johnny H
Gold Member
****

Registered: 09/07/03
Posts: 793
Loc: Liverpool
We have to remember that we have so many injured players at the moment. Things could have been different.

Johnny never wrote those words.

Johnny never had “Liverpool” as his location. His avatar had been changed.

The number of posts against this user name was 793, one more than it had been when he made his last post.

He didn’t make this post. So who had?

There’s two possibilities that I can see. Either someone not a part of Koptalk had hacked into the software that is used by Koptalk, exposing a security hole that will no doubt have a huge impact on the sales of that product. Or someone from Koptalk had used one of the options included in the software to make the post instead.

Johnny’s account has been hacked. And in the absence of any evidence on any website related to the forum software Oldham uses, it’s pretty much a safe bet that Koptalk had been the ones doing the hacking.

Their initial decision had been to ban Johnny. Then they opened up the account and made this post. Hoping that nobody had noticed that one of the last remaining “big hitters” had left in disgust.

That is going to cause outrage amongst any decent person – you just don’t do this. Not unless you are instinctively corrupt. And we’ve seen this summer how Dunk’s instincts work.

Some members raised concerns on the site. Members who’d been aware of the revelations we’d been making here, members who knew that Oldham was dodgy. Members who knew that he wouldn’t answer them openly and honestly, and who knew they were likely to “ban themselves” by asking questions. Well done to them for asking, because even if they raise suspicions from just one previously unaware member they’ve done a good thing.

#42602 – Today at 03:29 PM
Re: I am in shock…. [Re: Johnny H]
Desertscouser
Honorary Member
**
Registered: 20/09/06
Posts: 9827


Originally Posted By: Johnny H
We have to remember that we have so many injured players at the moment. Things could have been different.

Hold on.

Johnny H has left koptalk for good.(Another top poster leaves)

Has someone hacked into his account?!!
– – – – – – – – – – – – – –
#42631 – Today at 03:47 PM Re: I am in shock…. [Re: Desertscouser]
nonni19
Gold Member
***

Registered: 03/07/04
Posts: 969
Loc: Iceland

Yeah, did you have a change of heart Johnny?
– – – – – – – – – – – – – –
#42654 – Today at 04:05 PM
Re: I am in shock…. [Re: nonni19]
Disco1999
Honorary Member
***
Registered: 17/05/04
Posts: 7301
Loc: Bristol

Originally Posted By: nonni19
Yeah, did you have a change of heart Johnny?

Don’t think so mate.

I think he’s worried his account has been hacked.
– – – – – – – – – – – – – – –

Those posts lasted longer than normal – perhaps Dunk was away shopping for kits at the Toon Army Megastore. Perhaps Steve was at the dog track again. Perhaps Katie was chatting to Rich Tea on MSN, the pair of them distracted from their main job of policing the mess Dunk made. Whatever it was, they lasted a while. And were seen by a lot of users.

“Desert Scouser” was banned for his post as soon as the fat thieving conman had seen it. He was later emailed, as he revealed on est1892. The email is from Koptalk “support”…

With reference to your post on the site this morning regarding another member and their account security.

We noticed that someone claiming to be this person was posting last night so we naturally pulled that username with immediate effect as that former member asked for their account to be closed.

We have seen no other examples of anyone ‘hacking’ anyone’s account and we don’t know if this was a genuine case or not, especially as the former member hasn’t reported this to us. Incase the account had been compromised we chose to delete it immediately along with any individual posts incase they were not made by that member.

With regards your own account. While we appreciate your assistance with this matter, there are proper channels to bring this kind of thing to our attention.

If someone was using someone elses account and they hadn’t been noticed, by posting this openly you could have scared such an offender away where as if you had come to us direct we may have been able to monitor them and where they were logging in from.

As you are concerned about the security of your account, would you like us to close yours for you to allay any fears you may have?

Thanks for raising the issue.

Bullshit from top to bottom. Duncan – you’ve been caught. Again. Add “hacker” to the list of crimes and dodgy scams that we’ve exposed you for. This particular one was exposed thanks to Johnny H, Desertscouser and others.

Let’s go through your “explanation” again. Remember Oldham, very few people are as thick as you. We don’t fall for stuff you’ll fall for. We don’t love you, so we aren’t blind to what you do. We see it straight away. Maybe Katie saw those posts straight away, but family or not, maybe she’s started to see through you as well? Anyway, let’s start with this – “We noticed that someone claiming to be this person was posting last night so we naturally pulled that username with immediate effect as that former member asked for their account to be closed.” I think you’ll find that Johnny H didn’t ask for his account to be closed. He left, with a parting message that he probably wishes had been worded more strongly now, but he left. Then you banned him, before opening his account up again and hacking in as him. As far as I know there was one post, but you are implying that there were numerous posts.

Then this – “We have seen no other examples of anyone ‘hacking’ anyone’s account and we don’t know if this was a genuine case or not, especially as the former member hasn’t reported this to us.” The former member wouldn’t have known though would he? How could he report it? You claim that he’d asked you to close his account. So how would he have known about someone else using his account? Unless someone told him, he could only know by logging in himself. And if he was logging in himself, how could you then have “noticed that someone claiming to be this person was posting”? How? If Johnny H is locked out and his account is closed then he’s not going to be able to see anyone hacking in. If he’s not locked out and so he’s logged in, well how can you be sure it wasn’t him posting? You can’t. You’ve lied. Again.

Your lie about Johnny asking for the account to be closed doesn’t fit does it? Nor does this: “Incase the account had been compromised we chose to delete it immediately along with any individual posts incase they were not made by that member.” Ah – delete the evidence hey? I wonder if your hosts would be in possession of any back-ups of your MySQL database, the one that contains all those posts. You see that post will have had an IP Address recorded against it. Hacking is a crime, an offence. If the police are told about this (including your dealings with hackers in the summer to get at Steve’s Hotmail account without his permission for £50) then they could inspect that database. And then they could find the IP address. And from there, they could find out who was using that IP address at that time.

Of course, if you weren’t the one doing the hacking, and you had nothing to hide, you won’t have actually “deleted” the post as such. (The software generally just hides the posts – so that post is probably still available to look at and can be recalled by someone with ADMIN access to the forum). If you had nothing to hide, and you were worried that your site had seen its security compromised, I think you’ll have taken a note of that IP address. Or addresses, if there were numerous posts as you claim. So – did you take a note of the IP Address(es) used? Do they match anyone else’s? Of course they do – either “Dunk” or “ST3”.

Time for another injection of brown stuff: “With regards your own account. While we appreciate your assistance with this matter, there are proper channels to bring this kind of thing to our attention.” Proper channels being what exactly? Let’s assume you mean that desertscouser should have reported this through a PM. Sorry, they don’t work any more. Through a “support ticket”. What would you have done? You’ve just told us that as soon as you saw this other person posting as Johnny H that you deleted the posts. Then you contradict yourself, as all compulsive-but-stupid liars do: “If someone was using someone elses account and they hadn’t been noticed, by posting this openly you could have scared such an offender away where as if you had come to us direct we may have been able to monitor them and where they were logging in from.” Why delete their posts? You could hide them instead. Why not leave it open anyway, just in case? You could still “monitor” them. Except “them” was you. You are the hacker. You did it to try and pretend Johnny had never left. You’d hoped nobody would notice. And if it wasn’t you, let us know the IP address. We can check it out for you.

More importantly, now that it’s established that “someone” was using Johnny H’s account, don’t you think it should be announced on your site? You don’t need to go into too much detail, just point at that Johnny H has chosen to leave Koptalk and someone hacked in as him. Tell the readers that that post wasn’t by him. Tell them you are sorry and that you will do your best to find out how someone could have hacked in. One or two might believe you. Most will already know, from here and elsewhere. Maybe you’ll tell them about this method of getting into someone else’s account, something pointed by “Hansi” on est1892 –

From UBBCentral’s documentation:
Quote: Member Information Tab
From this tab, you can view and edit the basic user details, such as display name, email address and member title. Additionally, using the buttons below, you can delete the user, email the user’s password to him/her, or become the user – which is especially helpful for troubleshooting problems a user is experiencing.

So which was it then Duncan? You pretending to be Johnny H, or some as-yet-undocumented security hole in the software you use? I know which one I think it is.

Just a reminder – if you are still a Koptalk member – do not pledge any money to this charity appeal being run by Duncan Oldham. If the above doesn’t convince you that he’s a liar and a conman, then ask him whether Lauren, his disabled cousin, ever got that money you pledged. Ask him to show some kind of evidence, after all thousands of pounds were donated. That was his last charity scam and he can’t prove anything. He was flashing the money quite openly at the time though, boasting of his new TVs and the rest.

We’ve set up a page at Just Giving. We don’t touch the money at all – you give to “Just Giving” and they give straight to Alder Hey. Their admin fees are low and if you are based in the UK they can claim an extra 28% on top of your donation. I’ve been taking notes of Dunk’s Alder Hey collection and will post on it in more detail today or tomorrow, all being well. If you do want to donate to Alder Hey, don’t do it through Dunk – do it here – http://www.justgiving.com/notdunk. Thanks to those who got the ball rolling for us too, I do appreciate it.

Whatever you do – don’t trust Dunk. If you are concerned about what happened to your donations to the “Lauren Appeal” then please contact the Charities Commission. And if you think it’s not worth bothering and someone else will write, think again.

And if you work at Alder Hey – please warn them. And warn them in advance of the excuses Duncan will try to give them. Ask them to raise the issue of the Lauren collection with him if he does contact them (he’s claiming he’ll be contacting them tomorrow). I really don’t think they can condone his collection in light of the apparent theft of all that money donated for Lauren.