Web Hosting Talk







View Full Version : Possible client to watch out for...


TLott
12-30-2003, 05:07 PM
Hello,

I've been operating ServerSeed.com hosting for the last several months, been doing fairly well, too. I've was surprised at the lack of fraudulant or even questional orders - almost two hundred clients in the last couple of months and not one that I didn't feel confident about. Guess that's a testament to well-targetted advertising.

But, it happened.

Earlier this month I received a "suspect" signup with to my largest plan:

jcamz.com (he later parked kcamz.com, I believe)
cr**ik@email.nu
Cecilia Pa***io
310-***-4949
****2 President Ave.
Harbor City, CA 90710 (US)

He paid via PayPal.

IP: 68.121.191.185
This was on 12/9/03

Well, I processed it (had no solid reason to deny his registration), and flagged it to keep an eye on. Everything was fine and dandy for a week or so, didn't appear to have anything on the page.

Then, I received not one, but two emails to my abuse addy accusing the guy of spamming his website to users on AOL Instant Msger and Yahoo IM. These two people claimed to be parents (claiming their children were led to the site). I loaded up his site, and it did appear to be a quasi-porn webcam page. I immediately suspended his account.

Now, my suspended page has a listing of probable reasons for suspension and a link to my support email to request further info. Well, in 5 minutes I received 10 emails from mostly foreign/Spanish speaking people - all asking to see the webcam, and the like. It became obvious to me that this guy was indeed mass spamming users over AOL/Yahoo. So I decided to terminate his account and fire off an email, to which I received no response. (The orig account is still sitting suspended on the server - but he changed the jcamz.com DNS to point elsewhere).



Fast forward to today.

Noticed another signup awaiting processing, took a look at it. And what do I see? A signup from someone with the same last name and similar domain:

livecamzz.com
Ronnel Pa***io
r****l@email.nu
68.121.229.221
Same address/phone as the first signup.
Just a different name & email l addy.

This time he also ordered domain registration. (I'm reselling through Enom).

This time I immediately canceled his account, but being the idiot I am sometimes, I accidently processed it through the API queue. (And his domain got registered). Shot off an email to Enom 5 minutes later explaining the situation. If they reverse registration, fine. If not, I'll pocket the $7.95. No biggie to me. Preferable to hosting the guy. Before I could send him an email, he sent me one labeled "URGENT!" - asking why he couldn't log into the billing system to enter in his credit card info (appears this time he was going to use CC instead of Paypal).

Anyway, I have no clue how this guy found me. I'm not exactly advertising mainstream. So I figure he must be looking through hosting directories and signing up at random.

Just a heads up in the rare chance someone gets a signup for a webcam page... might be this guy. He's trouble.

(This is fairly simple, went into too much detail I think). Larger hosts probably get users like this every day, but it was a notable occurrence for me :).

security
12-30-2003, 05:45 PM
Any domain which replaces "S" with a "Z" has to be slightly suspicious.

Charlottezweb
12-30-2003, 05:54 PM
Originally posted by security
Any domain which replaces "S" with a "Z" has to be slightly suspicious.

True...hey! Wait a minute! :angry:

:D

Jason

JNadolski
12-30-2003, 06:50 PM
Well thanks for sharing this ty.

IRCCo Jeff
12-31-2003, 02:53 AM
I'm more concerned about people without signatures ;)

Reddrake
12-31-2003, 03:03 AM
Just a question, did enom refund you?

I presume your using Modernbill. Do you have any other fraud protection?

Try filtering the email? Do you even allow porn? If not block all porn related domains. Just a few tips.


Edit: Thanks for the heads up.

Project X
12-31-2003, 04:07 AM
Originally posted by DeathNova
I'm more concerned about people without signatures ;)

ahem!

:blush:

ozzie123
12-31-2003, 07:56 AM
Er... I don't have any sig... :P

TLott
12-31-2003, 02:29 PM
Originally posted by Reddrake
Just a question, did enom refund you?

I presume your using Modernbill. Do you have any other fraud protection?

Try filtering the email? Do you even allow porn? If not block all porn related domains. Just a few tips.


Edit: Thanks for the heads up.

I do have other fraud protection, but this wasn't really fraud by definition.

I don't allow porn, that's one reason why I terminated the account, but he was obviously up to no good, beyond simply running a porn site.


Enom did reverse the registration today :)

Reddrake
12-31-2003, 03:01 PM
Thats great, enom hardly ever reverses anything :|

Try and develop a filter that searches the server. Manual searches as well.

Like in shell, updatedb
Then after thats done locate XXX or porn terms that may be in the webpage ;)