I have been studying the various methods used by spambots to auto-register and I'm trying to understand their methods so I can better fight them off.
Here's my question:
If a validation email is created for new members, and that email includes a validation code,
how is it that spambots are able to validate if they never received the validation code?
Here is an example:
Spammer used npaqvp@ype.com to signup.
It's the actual email address usd by the spambot - the email address is a bogus, invalid email address that will bounce.
The validation email included among other things, the following links:
The validation code for the above is: dbbce576f9aa08c4f40ef2d5318f616cbf6c39a8
If he never got the email (it was an invalid, bogus email address), that means that he obviously never got the validation code, so how was he (or the spambot) still able to validate?? He doesn't know the validation code because he never got the email... yet he was still able to validate his acct.
Is there some link that would allow him to validate without having that validation code?