Warning to ISPs: 9netave

No doubt I'll get flamed to hell by some folks for this(but this wouldn't
be Nanog without it), however if this character is doing what is described
below you might want to make sure it isn't happening to you and your users
at this very moment, moreso since 9netave, the organization hosting the
site is apparently refusing to take action to stop a clear case of
credit fraud.

Value Net, http://www.value.net is an ISP located in Walnut Creek,
California, which I have an account with.

It appears that a scam artist decided to set up
http://www.valuehelp.net, which copies the site design, logos, etc. and
pops up with a javascript alert saying "This is a secure Value Net
server," and has a place to enter account info & credit card. They then
proceeded to send email to Value Net customers telling
them that they needed to go there and re-enter their information,
including credit card info.

According to information provided to me, 9netave is in no uncertain terms
is refusing to take down the site without a court order.

Beware...

/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\
Patrick Greenwell
                 "This is our time. It will not come again."
\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/

Why beware ? While this is probably off-topic, I would like to point
out some of the more heartless realities of living in a litigious
society, in particular like that of the US. If the service provider
removed the site based on some complaints then they would be opening
themselves up for claims of restricting trade, suppression of the
rights of the customers etc. I am not in the US, nor a lawyer - but
you get the idea. Lots of pointless (or is that punative ?) damages
feasible.

The provider is waiting for an external agency (the courts) to take
the responsibility for saying that the site should be removed. When I
was at Demon, we had a strict policy of not submitting to any third
party requests WRT user account except those either demanded by law,
or those events that clearly breach our AUP - which has the force of
law, as part of the terms and conditions of service.

Regards,

> According to information provided to me, 9netave is in no uncertain terms
> is refusing to take down the site without a court order.
>
> Beware...

Why beware ? While this is probably off-topic, I would like to point
out some of the more heartless realities of living in a litigious
society, in particular like that of the US. If the service provider
removed the site based on some complaints then they would be opening
themselves up for claims of restricting trade, suppression of the
rights of the customers etc.

For obvious fraud, which has been reported to them? I doubt it.

The provider is waiting for an external agency (the courts) to take
the responsibility for saying that the site should be removed.

If I witness someone killing someone, do I need to wait for a court to
take responsibility and tell me what they were doing was illegal, and I
should have taken steps to help prevent it?

I'd love for you to explain how any reasonable person, after viewing the
ISP's site, and the site in question, could not see that
they(valuehelp.net) are attempting to run a scam. Let's see, they are:

1) Directly copying the logos, text, and webdesign of the original ISP.

2) Popping up a Javascript notice saying "You are entering a secure Value
   Net server"

3) Asking for account information as well as credit card information.

4) Emailing Value Net customers, representing themselves as Value Net
   employees, and telling people to go to that site and re-enter their
   information.

Hello? How much more do you want?

Courts are a last resort. They are not the first place you run to whenever
you have a problem. They are also very fond of using a "reasonable person"
litmus test in deciding if people/organizations could have reasonably been
expected to recognize that a crime was being committed.

It is sad to see such irresponsibility being defended.

But *that* is the world we live in.

/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\
Patrick Greenwell
                 "This is our time. It will not come again."
\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/

It looks like this is some new scam going around. The exact same thing
just recently happened to one of our competetors. They took the ISP name,
made "www.(ispname)billing.com", then proceeded to email all their
customers the exact same scam message.

Beware.

-Dan

9netave is also pretty well known for sending unsolicited
  faxes -- which is illegal in the United States, and has been
  since the 1980's.

---------========== J.D. Falk <jdfalk@cybernothing.org> =========---------
  > "But still the screen is flickering |
  > With an endless stream of garbage to |
  > Curse the place |
  > In a sea of random images." -Pink Floyd |
----========== http://www.cybernothing.org/jdfalk/home.html ==========----