email address harvesting and LJ

Recently, we had our first known case of someone harvesting email addresses from LiveJournal and spamming the users. It appears to have gotten a fairly large distribution, too. A copy of this spam is at the bottom of this post.

I guess my question would be... are we sure that there is no easy method that we aren't protecting against that allowed this spammer to harvest so many email addresses so easily? Is there some kind of system-generated list of email addresses that they might have found, or did they actually run some kind of script searching through userinfo pages to get such a large distribution?

Also, what actions, if any, can we take against the people who did this, so as to discourage others who would try the same thing? Personally, I think the best way to deal with people like this is to find out their personal information and to start making them the victims for a change...


----Original Message Follows----
Subject: hi
Date: Sat, 30 Jun 01 14:36:51 EST

Drive a brand new car and go on a exotic
vacation. Thousands of people are making
HUGE monthly residual incomes, using our
proprietary online system and the power
of the INTERNET. Well show you how to make
a fortune right from the comfort of your home
in the next 72 hours.

For free information!!!!!!!!!!!

Click Here=> http://1075262055/members/h07j

