Saturday, March 3, 2012

LittleDumbMan : Check Mate


If you are reading this and you want to take action against these cyber bullies, please print out all these pages and then ask the host of Realscam.com (RS) to disclose the .GZ archive files of the RS web logs. You may need to obtain a court order first. Hire an IT expert to do an analysis in order to establish sock puppetry activity first.

 


MMB, straight as an arrow....
March 13, 2013

Okosh has been established as being the "Littleroundman".

Littleruinedman,

I can't help you if your thinking comes from the wrong end of your anatomy, On your BEST day you're not as smart as I am on my worst day. If you live to be a hundred you will never be as smart as me. My grandma always told me; beauty fades, but dumb is forever!

I have converted IP Detector's time references to your time, so your brain can easily understand how this thing works:

I came to RS to post in your forum on February 17, 5:23 AM (your time), right?
http://www.realscam.com/f8/justbeenpaid-810/index10.html

You approved my post and replied on February 18, 12:15 PM (see exhibit #1):

203.206.69.189 - - [18/Feb/2012:12:15:04] "GET HTTP/1.1" 403 185 "http://www.realscam.com/newreply.php?do=postreply&t=810" "Mozilla/5.0 (Windows NT 5.1; rv:10.0.2) Gecko/20100101 Firefox/10.0.2"


So, we can easily establish that you are the guy who uses the FireFox browser version 10.0.2 with an old NT 5.1 OS computer, right?

Now, if I can establish beyond any doubt that you use multiple accounts to perform this sock puppeteer's deception of yours, then you are guilty as charged, and one can assume that you can be anybody, including Lynn. But remember, just being his 'meat puppet' is bad and dishonest enough.

Now, going back to the first day, when "Whip" shows up and posts at 12:31 PM. It's a one liner (very short comment), so the only possible user who could have seen the new posts would have been someone before that time frame:

And who that user was? YOU, of course! (see exhibit #2):

203.206.69.189 - - [17/Feb/2012:12:20:22] "GET HTTP/1.1" 403 185 "http://www.realscam.com/newreply.php?do=postreply&t=810" "Mozilla/5.0 (Windows NT 5.1; rv:10.0.2) Gecko/20100101 Firefox/10.0.2"

AND HERE YOU ARE VIEWING THE THREAD AND REPLYING TO YOURSELF (POST #239) AT 12:33pm and responded at 12:38PM (see exhibit #3):

203.206.69.189 - - [17/Feb/2012:12:33:11] "GET HTTP/1.1" 403 185 "http://www.realscam.com/f8/justbeenpaid-810/index10.html" "Mozilla/5.0 (Windows NT 5.1; rv:10.0.2) Gecko/20100101 Firefox/10.0.2"
203.206.69.189 - - [17/Feb/2012:12:33:41] "GET HTTP/1.1" 403 185 "http://www.realscam.com/newreply.php?do=postreply&t=810" "Mozilla/5.0 (Windows NT 5.1; rv:10.0.2) Gecko/20100101 Firefox/10.0.2"
203.206.69.189 - - [17/Feb/2012:12:38:42] "GET HTTP/1.1" 403 185 "http://www.realscam.com/newreply.php?do=postreply&t=810" "Mozilla/5.0 (Windows NT 5.1; rv:10.0.2) Gecko/20100101 Firefox/10.0.2"


You like to use the preview function a lot, don't you?


Now in your 'defense', the only users besides you and I, who saw those two posts between 12:15 PM and 12:31 PM on February 17 were only two people: one user from Edmonton, Canada and another one from New Jersey (see exhibit #4):

161.184.96.209 - - [17/Feb/2012:12:18:20] "GET HTTP/1.1" 200 49 "http://www.realscam.com/f8/justbeenpaid-810/" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; GTB7.2; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.5.30729; .NET4.0C; .NET CLR 3.0.30729)"

71.48.99.180 - - [17/Feb/2012:12:28:59] "GET HTTP/1.1" 200 49 "http://www.realscam.com/f8/justbeenpaid-810/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.26) Gecko/20120128 Firefox/3.6.26"


So, you could argue that one of these two users could have been "Whip", right? Well, the closest user present around the time when Whip's post appeared, was the one from New Jersey at (12:28PM). However, Whip didn't make one, but two posts; between 12:31 PM and 1:07 AM, (now February the 18th).

So, in order to prove that any of these two users was "whip", either 161.184.96.209 or 71.48.99.180 would have had to be detected more than once within that time frame. But unfortunately for you, that was never the case and in fact, you were the most active in that thread and constantly refreshing your browser. So, also by this process of elimination I can determine and verify that you were posting as Whip. You can confirm this data exhibits with your host's web logs, it should all match.

So, LittleRoundMan or whoever the heel you are, that's just an example of how IP DETECTOR works and believe me, I am only showing the tip of the iceberg here; sock puppetry coming from your site is at an unprecedented level and way off the BS scale.

I recommend you seek mental therapy at once, before you start talking to the wrong end of your anatomy.

I can also detect even when you try to post, then change your mind, using any of your dynamic IP addresses (see exhibit #5):

124.150.59.11 - - [21/Feb/2012:22:12:14] "GET HTTP/1.1" 301 254 "http://www.realscam.com/newreply.php?do=postreply&t=810" "Mozilla/5.0 (Windows NT 5.1; rv:10.0.2) Gecko/20100101 Firefox/10.0.2"


Indeed your IP is dynamic. iiNet appears to be the ISP of choice for crooks and spammers:
Day Eight: AFACT solicitor grilled on ISP disconnections - iTnews

In fact here is your list of current IP's:
203.206.69.189
203.59.158.16
124.169.230.22
124.169.56.169

As user Okosh
58.165.172.39
124.181.126.118

All of them appear to come from the same computer. While I am not 100% sure that OKosh it's really you, it would be a bizarre coincidence that he uses the same exact OS and and browser, right down to the exact versions. Since his rants and diatribes are almost identical to yours, hey, you decide! :)

But, you are right that this is a privately funded site. It's primarily Lynn Edgington's scam forum (maybe even Patrick Pretty is in on this) designed to highlight his company Eagle Research Associates. Hopefully the IRS audits him, since PayPal already suspects him of being, in his own right, a scammer. PayPal knows when some merchants are very suspicious. As I said from the get go, The MBB makes no distinctions between sock puppets and meat puppets.

So "LRM", please don't pee on my leg and tell me it's raining. This is a real scam forum because of you. Thanks for helping the MMB create content out of thin air. The MMB never had to contend with a dumber sock puppeteer than you. Do you feel as if you're getting the wrong end of your anatomy whipped? (LOL!) You sure are!

MMB

No comments:

Post a Comment