{"id":13,"date":"2007-03-07T16:27:16","date_gmt":"2007-03-07T07:27:16","guid":{"rendered":"http:\/\/www.joewein.net\/blog\/?p=13"},"modified":"2007-03-10T15:05:34","modified_gmt":"2007-03-10T06:05:34","slug":"a-tale-of-two-abuse-departments","status":"publish","type":"post","link":"https:\/\/joewein.net\/blog\/2007\/03\/07\/a-tale-of-two-abuse-departments\/","title":{"rendered":"A tale of two abuse departments"},"content":{"rendered":"<p>In the last two days I was in contact with two abuse departments at webhosters. Though the reasons for contacting them were similar, I came away with impressions that were as opposite as could be. I called because of two websites, both highly illegal. Both were advertised in spam and I encountered them when checking suspect domains found by my spam filter.<\/p>\n<p>The first encounter was prompted by a phishing site, a clone of a Wachovia bank website designed to obtain account information to steal money via online banking. The email, subject line &#8220;Update Your Account Now!&#8221; claimed to be from Wachovia Bank, but predictably the links to the site that asks for your password led elsewhere, to a domain named (Wa-) &#8220;choviainfo.com&#8221;. The domain resolved to an IP address that, according to a WHOIS lookup, belonged to Hetzner, a leading webhosting company in South Africa. <\/p>\n<p>I dialled the customer service number listed in the WHOIS entry and spent less than three minutes on the phone altogether. After stating that I found a phishing site on a Hetzner server, I was transfered to the technical department. There I repeated my quick explanation and was transfered to the abuse desk. I explained the problem and spelled the domain name to technician, who immediately checked the site and confirmed the existing of the phishing site on the machine. Using the Linux tool &#8220;chmod&#8221; he then disabled all access to the site. The website stopped working and the phishing gang was prevented from uploading another set of files. I was impressed how quickly Hetzner had resolved the problem and mentioned to the technician that I was a customer of Hetzner in Germany (their parent company) and was pleased to see their service was as efficient in South Africa as in Germany \ud83d\ude42<\/p>\n<p>Today I came across another site I found worth reporting, a child pornography site hosted on a GoDaddy server. Phishing is done by unscrupulous criminals who steal millions of dollars, but child pornography is far worse. It&#8217;s about small, helpless children getting raped and others making money out of that. <\/p>\n<p>This site, created by a criminal gang calling itself &#8220;CP COMPANY&#8221; and claiming to be based in Ukraine, was advertised in spam in the following way:<\/p>\n<blockquote><p>Hello pedo lover!<br \/>\nWe present to you NEW PEDO COLLECTION!<br \/>\nHigh Quality h^rd CP content! Low Prices on the net!<br \/>\nSee free preview now and get instant access!<br \/>\nTHOUSANDS OF HQ CP PICS and MOVIES&#8230;<br \/>\n+ BONUSES AND UPDATES!<br \/>\nLOTS OF FUN FOR CP LOVERS:<\/p>\n<p>http:\/\/www.fulldbcollection.info<\/p><\/blockquote>\n<p>(I only added the actual domain name in this blog posting after the site was finally shut down).<\/p>\n<p>Again, I looked up the IP address and then the WHOIS record for the IP, which included the phone number of the GoDaddy abuse desk.<\/p>\n<p>I called the number and explained I had come across a child pornography site on one of their servers. The representative replied that I would have to put my request in writing because otherwise &#8220;you won&#8217;t get any action on this.&#8221; They needed to be notified in a way that creates a record. I should put the details in an email to abuse (at) godaddy (dot) com. <\/p>\n<p>I said I would do that, but I would like to give him the URL anyway, which I did. The call was finished in less than a minute, but without the desired result.<\/p>\n<p>Checking the details on the domain again, I found it was one of the child pornography sites I had already reported by email as part of my daily spam domain verification procedure, some 15 minutes earlier. So I could only wait, checking at iregular intervals if the site still responded by using the Linux &#8220;wget&#8221; program that lets me download the text portions without having to retrieve the pictures as a browser would. <\/p>\n<p>It is now more than four hours since I reported the site to GoDaddy by email and more than 3 1\/2 hours since I told them by phone. The criminal site is still offering pictures and videos of raped children to willing customers with a credit card.<\/p>\n<p>In the index.html I downloaded with &#8220;wget&#8221; the criminals explain to their prospective customers:<\/p>\n<blockquote><p>Buying production at us you support creation of new kids porn films.<\/p><\/blockquote>\n<p>I only wish a company as large as GoDaddy was able to take action against criminal abuse of their services as quickly as Hetzner.<\/p>\n<p>P.S. The child porn site was still active 29 hours after reporting it, despite two emails, one phone call and one voicemail left. I have contacted a US law enforcement officer about this.<\/p>\n<p>P.P.S. When the site was still active 56 hours after reporting it, I filed a criminal report with the German police. When I checked again on the following day I found that the site had finally been disabled by GoDaddy.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In the last two days I was in contact with two abuse departments at webhosters. Though the reasons for contacting them were similar, I came away with impressions that were as opposite as could be. I called because of two &hellip; <a href=\"https:\/\/joewein.net\/blog\/2007\/03\/07\/a-tale-of-two-abuse-departments\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-13","post","type-post","status-publish","format-standard","hentry","category-spam"],"_links":{"self":[{"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/posts\/13","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/comments?post=13"}],"version-history":[{"count":0,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/posts\/13\/revisions"}],"wp:attachment":[{"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/media?parent=13"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/categories?post=13"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/tags?post=13"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}