CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 934
Comments: 25
block bottom
spacer spacer

Republic Czeck and Antiphishing

 
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
pippo888

Cadet
Cadet


Joined: Mar 14, 2008
Posts: 6
Location: Italy

PostPosted: Wed May 28, 2008 8:38 am    Post subject: Republic Czeck and Antiphishing
Reply with quote

Hi all.

I work on anthiphising and I take care on shut down process for a Managed Security Service company. We are not so big as RSA, maybe this is imporant to know.
Anyway, our process consist in contact with email fax and call tipically the ISP where clone site is hosted.
Well, many ISP for many country are quickly and not require any Policy implication to act the shut down.

Unfortunately this process was so very difficult for Telfonica O2, Czeck Republic ISP. It infact require that we submit a request to the policy.

So, I have two question:
1- someone know the right contact in the policy (we want to avoid to contact many people and have a long delay)
2- Why in Czeck republic they ask for Policy contact. (it is just a phishing web page) ?

Thanks so much in advance.
Information Security Manager

Back to top
View users profile Send private message
downie

PIRT Handler


Joined: May 19, 2006
Posts: 3680

Phishing Squad

PostPosted: Fri May 30, 2008 8:53 pm    Post subject:
Reply with quote

Hi,
I asked your question of O2 in the UK,
they would like you to contact them directly.
You can use the form at https://www.o2.co.uk/apps/help/help
As a postcode you can use ZZ3 3ZZ (since this is a required field)
As a mobile phone number you can use 77777777.
Please let us know what they say.


_________________
"For evil to triumph utterly, it is only necessary that good men do nothing"
Back to top
View users profile Send private message
pippo888

Cadet
Cadet


Joined: Mar 14, 2008
Posts: 6
Location: Italy

PostPosted: Tue Jun 03, 2008 8:18 am    Post subject:
Reply with quote

Thanks for your support. I asked just today to UK O2 as you suggested.

I will come back as I have any feedback.

Anyway, just for your information, following is the last email from Telefonica O2 in Prague.

">Dear Sirs,
>the mentioned fraudulent site has been operated by an O2 >customer.
>
> Due to Czech Act No. 127/2005 Coll., on Electronic >Communications and on the Amendments to the Other Acts >(Electronic Communications Act) we are not allowed to analyze >traffic, stop operation or identify any customer not having >appropriate request from Czech Police.
>
> The best and fastest way to solve the problem is to provide >Czech Police with information on illegal fraudulent site operation >and to ask for investigation of the incident.
>
> We are going to stop the fraudulent site operation immediately >after receiving the request from Czech Police.
> I'm sorry I cannot assist you more effectively now.
> Sincerely
> Richard Michalek
> Information Security & BCM manager
> Telefonica O2 Czech Republic, a.s.
"

Back to top
View users profile Send private message
pippo888

Cadet
Cadet


Joined: Mar 14, 2008
Posts: 6
Location: Italy

PostPosted: Wed Jun 04, 2008 9:50 am    Post subject:
Reply with quote

Hi,

unfortunately today, 24 Hours after, No any answer from o2.uk !

Maybe, weapon attach needed Wink

Sometime, I ask myself:
...what is the utility of APWG, Castle..., PhishingThanks, Cert .. and so on if in two months no one is able to shut down jus one IP address !?!?
..I think that this UNCOMMON HAVE TO BE WELL MANAGED by these organizzation !?

Kindly, don't consider my opinion as a polemics, but just as a simple observation !

Regards

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2625

Premium

PostPosted: Thu Jun 05, 2008 8:15 am    Post subject:
Reply with quote

Even registrars that don't respond to spam reports usually respond to phish reports. I think they are afraid the credit card companies will stop working with them. Maybe these guys already can't process major credit cards and have nothing to risk.

Back to top
View users profile Send private message
pippo888

Cadet
Cadet


Joined: Mar 14, 2008
Posts: 6
Location: Italy

PostPosted: Thu Jun 05, 2008 10:49 am    Post subject:
Reply with quote

48 Hours after, No any answer from o2.uk !

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2625

Premium

PostPosted: Thu Jun 05, 2008 11:48 am    Post subject:
Reply with quote

Can you give us the URL in question? There are usually several ways to shut down a questionable site.

Back to top
View users profile Send private message
pippo888

Cadet
Cadet


Joined: Mar 14, 2008
Posts: 6
Location: Italy

PostPosted: Fri Jun 06, 2008 7:45 am    Post subject:
Reply with quote

A little update for you.

Tomorrow the guy whith which I'm in contact in Telefonica O2, who told me that I have to contact police office, reply at my request of police office indications that " ...he don't have indication Very Happy .."

Today I got the fax number of Prague Police Offcie. So, I will try in this way, otherwise I came bac to you with the URLs.

Anyway, I put the URL in the database.

Have nice day
Thanks for now.

Back to top
View users profile Send private message
pippo888

Cadet
Cadet


Joined: Mar 14, 2008
Posts: 6
Location: Italy

PostPosted: Mon Jun 23, 2008 8:41 am    Post subject:
Reply with quote

HI guys,

I got the right number of police, and one day after Telefonica 02 closed the IP Address.

Thanks for your support.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer