Archive for the ‘ Tips ’ Category

ACH/FDIC Email Phishing Scam

Over the past couple of weeks, there has been a huge number of emails sent out as part of a phishing scam involving ACH and FDIC. Below are what the emails read (they may change over time):

Subject: FDIC notification
From: no.reply@fdic.gov
Message: Dear customer,
Your account ACH and WIRE transaction have been temporarily suspended for security reasons due to the expiration of your security version. To download and install the newest installations read the document(pdf) attached below.

As soon as it is setup, you transaction abilities will be fully restored.
Best Regards, Online Security departament, Federal Deposit Insurance Corporation.

Subject: ACH Payment 2318207 Canceled
From: account.manager@nacha.net
Message: ACH Payment Canceled

The ACH transaction (ID: 51800395),
recently initiated from your checking account (by you or any other person),
was canceled by the other financial institution.

Rejected transaction
Transaction ID: 8574210513218
Reason for rejection: See details in the attachment
Transaction Report: report_082011-65.pdf.exe (self-extracting archive, Adobe PDF)

13450 Sunrise Valley Drive, Suite 100 Herndon, VA 20171 (703)561-1100 2011 NACHA – The Electronic Payment Association

These emails contain an attachment. Do *NOT* download or open this file. It will install a variant of the Zeus or ZBot trojan on your system. They aim for account information, mostly regarding banking. Again, if you receive an email do not open the attachment. If your email provider allows you to mark it as a phishing email, do so and then delete it (if it hasn’t been already).

Facebook: Block All App Spam

Are you one of the many people that hates all the Facebook application spam crap? Whelp, this entry is going to show you how to block all apps from your feed.

First: Click “Account” at the top-right of the page, and then “Privacy Settings”.
First

Second: Find “Apps and Websites” at the bottom of the page, and click the link entitled “Edit your settings”.
Second

Last: Find “Apps you use”, which should be at the top of the page, and click the link entitled “Turn off”.
Third

After confirming, you should now have an app free news feed on Facebook. Enjoy.

SolaceNet – Indepth

SolaceNet has been a project of mine for about a year and a half. I talked with one of my good friends, and we decided to sit down and start work on it. We didn’t even have a name for it until about two months into the project, lol. Some of you who don’t read my blog or know me are probably asking yourselves ‘what the hell is SolaceNet anyways?’. Whelp, I hope to break down what SolaceNet is in this post since I haven’t really done that yet.

So what is SolaceNet?

We hope that it will become the number one destination for gamers world wide. Social networking for gamers, by gamers is pretty much the basic concept of it. Now we know there’s hundreds of ‘gaming social networks’ out there, but none of them can actually pair you with other gamers you may know from specific games (and we don’t even need your email and password to find them!(Sorry, I just really dislike that type of spam – which is what it is)).

But why reinvent the wheel?

Good question, and the answer is pretty straight forward.. If you have no competition, there is no real motivation to improve and expand. That’s the philosophy that all businesses *should* have, though they usually don’t.

Do you see companies like Facebook or Twitter as competition?

In some ways, yes. Facebook and Twitter are two great social networks, but they’re not really setup for gamers. If I wanted to post that I just earned an achievement on XBL, I’d have to connect a third parties web application to post it for me.

So you’re opposed to using third party applications?

Not at all, I encourage the integration between websites. However, having multiple social networks do the work that could be done by one is wasteful in my opinion. Centralizing all data without having to create, set up, maintain and keep track of multiple accounts sounds a lot easier and cleaner, doesn’t it?

Dennis Fong has already created two gaming social networks. How do you plan on competing with someone with that much experience under their belt?

Yeah, Dennis created two of the largest and most well-known gaming social networks, but it comes back down to the motivation to improve and expand. He has virtually no competition. XFire was purchased by MTv, and hasn’t had any major overhauls since. He then turned around and developed Raptr that trumped XFire in every aspect. So aside from that, there’s no one to compete with. A few social networks here and there, but they’re all platform specific – XBOX here, PS3 there. We have quite a few things on SolaceNet that will make us a strong competitor with Dennis and his team of developers over at Raptr.

Can you be more specific when you say “a few things”?

At this point in the development stage, I can’t disclose every part of SolaceNet. Competition is all about knowing your competitors and creating something bigger and better after all.

Where can gamers go to check out SolaceNet?

Gamers can head over to SolaceNet.com and sign up. We’ll be giving everyone who signs up now exclusive access to our alpha and beta versions of the website and software.

Sheep Mentality

How is it that after so many generations of people fighting for freedom of everything they can, they still just file in line to do what the next guy or gal tells them to? We held our special elections yesterday for mayor, and ended up with one of the most corrupt businessmen in the city.. I’m going to try to breakdown why this probably happened (in my own thoughts)..

First here were our choices..
Tom Richards (Dem), who used to run RG&E until he sold it off for a nice fat severance (I read 24 million dollars), leaving ~200 people jobless. ‘Nough said…

Bill Johnson (Independents & Working Family).. This guy ::sighs:: He was our former mayor, who thought it would be smart to purchase a ferry to run from here to Toronto, CA. The ferry first crashed on its maiden voyage out of a port in Australia, then crashed again in NYC. We sold it, not once, not twice, but three times, buying it back for more than we sold it twice (this means we lost more money). And then he had the audacity to say that he would purchase another ferry if it were privately invested if he won this election… Yeah, he came in second in the ballots – go figure..

Alex White (Green).. I’ve met Alex, and I’ve spent time getting to know him (prior to his campaign). He’s a highly intelligent person, who probably would have done more for the city than any mayor we’ve had in the past 30 years. This was the only one actually giving ideas and suggestions that would help build our city back up into the colossus that it once was. He went live on the net to campaign, allowing free and open suggestions and questions, without any bias, and answered honestly, without pause. Another plus? He didn’t slander – at all.

Out of the three candidates, Alex was the only one that would have brought real change to our city.. So why did Mr. Richards win? Well let’s look at the psyche of a voter.

Voters are more likely to vote for names that they have heard more. Alex wasn’t as well funded as either of the other ‘big dogs’, and didn’t get as much coverage. Johnson and Richards were both on every other commercial in this city. Richards and Johnson were both well known prior to the election. My grandmother (Dem) said something that irked me, but goes with this.. “Not too hard of a choice.. Guy [Johnson] who wants to bring another ferry, guy [Richards] who was in office with Duffy (most recent mayor), or a nobody [White].”. Obviously, she didn’t do her research on White, and just went off what others said.

A voter, especially the older ones, are diehard party voters. Since there was no Republican candidate, I assume that the percentages were split between mostly between Richards and Johnson (Based on talking to Republicans, my estimate is ~ 63% Richards and 35% Johnson, leaving 2% for White. A greater percentage were against Johnson as mayor again).

The main point of this post, is to try and rattle you out of a state of disillusion… People need to stop following what everyone else says and does and think for themselves….

You know what really irks me? People in leadership who sit there and point fingers at their subordinates. Placing all the blame on others. The simple fact of the matter is that being in a leadership role, be it a manager for retail company, ceo of some fortune 500 or just a simple project manager like myself, the majority of the blame rests on your shoulders.

Let’s take myself for example. As a project manager, it’s up to me to make sure that each project I undertake is developed in an orderly fashion with the highest quality and rid of any bugs we can find before it goes live. If it’s not on time it’s my fault, because I didn’t push myself and the rest of the team hard enough to finish with-in the deadline or I didn’t give correct instructions on what needs to be done. If the quality is crap, it’s because I didn’t force the graphic designer to put their heart and soul into the project. If it’s riddled with bugs, it’s because I didn’t make the team test it enough before letting it go live.

Now, don’t get me wrong. Your subordinates are just as guilty as you are, because they didn’t come to you with questions or concerns, or they didn’t seek extra training, but even if that’s the case, it’s still your responsibility to go around and check up throughout the day. Ask them if everything’s going smoothly, if they need any help or if they need extra guidance.

In the military we used the saying “shit rolls downhill”. Which basically meant that if someone in a leadership role got “chewed out”, then the rest of the squad, platoon, company or battalion would as well afterward by the initial person that got “chewed out”. That has to be the stupidest fucking concept I have ever witnessed. I understand that you need to maintain a level of “alpha dog” over your “pack”, but come the fuck on. Negative reinforcement is bullshit, and society has shown time and time again that it brings you barely any real results. The only way negative reinforcement works, is if you can actually do physical or psychological harm to the person (fascist dictator type shit), which is illegal in the US (aside from the military and their corrupt ass-backwards style of the legal system).

Basically, in short.. Don’t treat your employees like shit, and don’t just sit there and point fingers at them because *you* fucked up. Remember that without your employees, you wouldn’t have a business – period.

Focusing on the now

As a project manager, I’m in charge of overseeing the development of projects. I was recently asked about my technique, and how I’m able to output a steady flow of web applications in such short amounts of time, compared to the larger companies who tend to take an exorbitant amount of time.

What can wait, and what can’t?

Sticking strictly with the original idea(s), notes and layout(s) is always the best way to develop a project, but there may be times when you sit down with your team or client and more ideas come up. You have to decide what can wait, and what can’t. There’s a few things you need to consider before you make the decision to archive the idea for after release.

Is it a necessity?
Does it need to be integrated in order for the website to function correctly?

How long will it take to write and integrate?
Time is always a big deal in the development stage. If it’s going to push your projected release back more than a month, you should make sure it’s something that has to be there prior to launch.

Will the database and SQL statements need to be edited or rewritten?
Having to go back and edit or rewrite SQL statements may seem trivial, but after your application is live you’re looking to decrease downtime. Changes to the database structure can prove to be more of a problem than it would be to spend a little more time on the initial development.

These are only a few questions that you should be asking yourself, your team and the client.

Your undivided attention.

Each project should get your undivided attention. This is why smaller web companies and teams tend to thrive more than their larger counterparts. Taking one project per team at a time will put you and your team(s) under a LOT less stress, and allow for the fastest completion of a project. Dealing with client’s one at a time is a lot easier than having an inbox or voicemail full of questions or ideas for multiple and then trying to sort them out in a timely manner.

Wait, what? I didn’t get that email..

Make sure everyone’s on the same page. It’s not fun trying to explain to a client that you’re behind because of no communication or someone not completely understanding what needs to be done.

Large companies make me lol irl.

Big companies tend to take mass projects at once, which put their developers (if they aren’t outsourcing to another country, which at least 1/3 do) in an extremely stressful situation as they’re usually assigned to more than one project at a time. Large companies tend to only see clients as dollar signs. Have you ever actually read some of the contracts these guys make you sign before they agree to developing your dream? Most have clauses stating that even if you back out of the development or postpone it, full payment will still be due. This – in my professional opinion – is wrong. I understand the need for profit, and that when a client cancels a project, you’re potentially losing out, but charge for work completed, not as a whole. This brings me to my next topic – source rights.

Source rights are the rights to the actual source code, images, etc. Many companies will charge you an additional fee for this, starting around $1,000 (lowest I’ve seen). This is mostly used for free advertising, as they can (and most likely will) place their companies name and web link on your front page. For the people that understand the basic concept of SEO (Search Engine Optimization), you know that free link placement on your index is never something you want, unless it’s reciprocal. Even then, it depends on the quality of the web page yours is on.

Server Migration

Sorry about the downtime. After about 12 hours of the site being down, it finally picked up the new DNS servers. We decided to change hosting companies, after our websites were getting throttled for hours, leaving visitors getting only half loaded pages, or pages not loading at all. Not good. So, after a couple of days of combing through web hosts, we’ve come to HostGator with the hopes of a better tomorrow.

Now, for those who don’t know, we were previously with HostMonster. They implemented CPU Throttling on their servers. They say this is for the better good of all accounts. The real reason for this? It’s likely that due to the economy (if you look at the time-line, it makes sense) they implemented a way to throttle the connections to every website across the map, to stop from “over-using” their bandwidth, which in their own writing, is unlimited. Unlimited at what cost? The cost of not having a usable website for an average of 7% of the month. This is a HUGE hit to take, for anyone.

Greedy bastards, pure and simple. And their excuses when you ask why your website is being throttled so much? “Your (As in you, the customer) scripts are faulty” or “You’re calling too many sql queries” <–WTF?! Now, I tested this with a single static pages website. No sql queries, no php. Just simple html, with css, images and some text. It was throttled for an average of 1.8 minutes every 3 hours. Total time up: ~2 days. Total hits: 7… Seven hits, no sql, no php, and it was throttled.. Seriously? All I have to say, is that if you plan on going with HostMonster, make sure you’re ready to have a lot of unexpected downtime.

Bank Fees

Recently, I’ve been asked by a few people what my thoughts and opinions are on the fees that banks impose on their customers. Banking fees are an unneeded hassle. For a lot of people, they can be the difference between eating and going without food. There’s quite a few fees that banks impose to squeeze out every penny they can from people. I’ll be going over some of the ones that I’ve either encountered, or have enough knowledge about to post on.

Overdraft fees are probably the most widely known. This is a fee that a customer is charged because they ended up spending more money than was in their account. Now, my beef with this one is that banks should have a safety net for customers. I’m sure everyone’s aware of the magnet strip on the backside of your debit/credit card(s). This is used to identify your card, and is tracked in real-time. Now, if you take that into affect, a bank *should* be able to in fact track your purchases. Most purchases aren’t updated in your banking account until the transaction has been confirmed via the business you made the purchase at. If this were implemented, a cease could be sent if you try to make a purchase over your balance (The same way your credit cards do if you try to make a purchase over your spending limit). The average overdraft fee is $25 (United States) but, can run up to $40 depending on the financial institute you’re with.

Maintenance fees most likely come in second. This is a fee that is usually imposed if your balance is under a certain limit (determined by the bank). Honestly, you have to seriously ask – who the hell came up with this idea? Now, if my account isn’t at the predetermined balance set by my bank, how could it help to impose a fee? I know from reading that my bank imposes a $8 maintenance fee and a $35 overdraft fee. Here’s a dramatic example based on my banks fees. Say my bank account has $7.99 in it, and they decide to hit me with a maintenance fee. This would deduct $8, leaving me with a balance of negative 0.01. Now because of that, my account would then get an overdraft fee for $35, making my new balance negative $35.01. Could you imagine getting that, all because your account didn’t have the designated amount set by some six figure a year CEO…

The easiest way to avoid fees is to use the bank as little as possible. Some of you are probably saying “But all my money goes in there!”. My question to that is – why? I tell this to everyone I know, and anyone who asks me – If you only have a checking account (most people do these days), always make sure that you keep at least $50 in it at all times for emergencies. This should be your minimum balance, making sure that you won’t get a maintenance fee for not having the min balance limit. On top of the $50 you have, if you pay bills with checks, electronic payments or your debit card, make sure to have just enough to pay them. The rest can be kept in a home safe (You can get firesafe safe starting at $30 – a great investment), or a safe deposit box. If you’re into stocks, then put some into the stocks. Direct Deposit is a great invention, and I strongly suggest that you use it but, I also suggest that you withdraw what you’re not going to use on bills and put away outside of the bank.

PHP Menu: Get Current Page

This is a quick and easy way to determine which page you’re currently on, and then setting your menu button’s overlay based on that page.

First we need to create a function to determine the page we’re on.
function getCurrPage() {
return substr($_SERVER["SCRIPT_NAME"],strrpos($_SERVER["SCRIPT_NAME"],"/")+1);
}

Next we need to check our this against the menu.
$thisPage = getCurrPage();
if($thisPage == 'index.php') { $navHome = '[Current Class]'; } else { $navHome = '[Noncurrent Class]'; }
if($thisPage == 'search.php') { $navSearch = '[Current Class]'; } else { $navSearch = '[Noncurrent Class]'; }
if($thisPage == 'about.php') { $navAbout = '[Current Class]'; } else { $navAbout = '[Noncurrent Class]'; }
if($thisPage == 'faq.php') { $navFAQ = '[Current Class]'; } else { $navFAQ = '[Noncurrent Class]'; }
if($thisPage == 'contact.php') { $navContact = '[Current Class]'; } else { $navContact = '[Noncurrent Class]'; }

After everything’s been checked, you can simply set your menu as-needed.
echo $navHome . $navSearch . $navAbout . $navFAQ. $navContact;

If you’re dealing with a dozen or more menu links, it would be more efficient to create an array to scan and verify the current page, but this will work fine for smaller menus. Enjoy.

I recently received an email from the address security@onlineupdate.com. They’re trying to phish for PayPal accounts. The contents of the email read as follows.

Dear shiping angel,
We recently reviewed your account, and we are suspecting that your PayPal account may have been accessed from an unauthorized computer.
This may be due to changes in your IP address or location. Protecting the security of your account and of the PayPal network is our primary concern.
We are asking you to immediately login and report any unauthorized withdrawals, and check your account profile to make sure no changes have been made.
To protect your account please follow the instructions below:
* DO NOT SHARE YOUR PASSWORD WITH OTHER USERS
* LOG OFF AFTER USING YOUR ONLINE ACCOUNT
Please click on the following link, to verify your account activity:

http://www.paypal.com/cgi-bin/webscr?cmd=_login-run

We apologize for any inconvenience this may cause, and appreciate your support in helping us maintaining the integrity of the entire PayPal system.
Please login as soon as possible.
Thank you,
PayPal Security Center.

Email Content

The link within the email directs you to “cheersandgears.com/waw/”, which has been flagged as a forged website.

The headers are as follows:

Content-Type: text/html; charset=”iso-8859-1″
Date: 02 Apr 2010 22:53:05 +0800 [04/02/2010 08:53:05 AM MDT]
Delivery-date: Mon, 05 Apr 2010 12:34:02 -0600
Envelope-to: [My Email]
From: PayPal
MIME-Version: 1.0
Message-ID: <20100402225305.0A9EC7129E153A42@onlineupdate.com>
Received: * from [72.253.60.56] (helo=server1.tnwre.com) by [My Email Server] with esmtp (Exim 4.69) (envelope-from ) id 1Nyr7Z-0005Dm-K9 for [My Email]; Mon, 05 Apr 2010 12:34:01 -0600
* from onlineupdate.com (h186-210-66-252.seed.net.tw [210.66.252.186]) by server1.tnwre.com with ESMTP; Fri, 02 Apr 2010 05:04:25 -1000
Return-path:
Subject: shiping angel, your PayPal account will be closed on 03/04/2010

Email Headers

Obviously, they have no idea how to read a calendar. If the senders email address doesn’t send a red flag up for you, the subject line should. Since it’s a month behind.

*Tips to keep you safe.
Always scroll over links in your emails. If they don’t lead to the website that the email is referring to, it’s most likely a phishing attempt.
Right-Click the link, and copy/paste it in to Google. This will more than likely bring up reviews and scam reports on the website in question.
If it doesn’t feel right, it probably isn’t. It’s always better to manually type out a URL you know than to click a hyperlink you don’t.

With phishing at its all-time high, you should always be careful of the emails you open, and the links that are contained inside of them.

World of Phish-craft

More and more phishing websites are popping up, making it even harder to navigate an already vast and complex digital universe. Gaming websites are one of the biggest victims when it comes to phishing, considering you can sell game accounts for a month or so rent depending on the network, level and items/gear that account may possess.

I get many phishing emails to an email which has no gaming accounts linked to it, which I find funny and odd at the same time. I must have some how gotten put on to some email list ::shrugs:: Oh well. Anyways, they attempt to duplicate these websites, both with domain names, the website layout and emails. A lot of them don’t succeed, and I will be showing two of them to you here.

First, we have a crudely made website, which has been taken down now. Their layout attempted to mimic the World of Warcraft’s login page, but the styling was off, and had images placed in wrong order and different sides of the screen. Below is the email that was sent, and the URL the hyperlink in the email directs to.

Email 1
[The link below was used for phishing]
worldofwarcraft-consulting.com/index.asp?ref=https://www.worldofwarcraft.com/account/&app=wam

The next website is still up, and I have grabbed a picture of it, as you should not go to this site, even if you don’t input any information. Below is the email received, and website.

Email 2

The link leads to: worldofwcratcft.com
Creating the illusion of the same domain name is a big part of creating a proper phishing website.The closer the name looks to the original, the easier it is to fool victims. A lot of people only quickly glance at a domain name, which in the case of a phishing victim, is bad.

The image below is of the actual phishing website.

Phishing Site

These are only a couple of the phishing emails I’ve received. Phishing has been around for almost as long as websites have, and it’s not going to go away. A few quick tips to help you stay away from phishing sites…

1. Always watch the links you click.
Even if it looks like a site you regular at, just be sure by scrolling over the link and checking where it actually leads.

2. Don’t input sensitive information on unsecure networks.
If it’s not a secure network, it doesn’t need your information. A lot of people (including myself) have an online alias, which can be used in place of actual information for any websites needing information. The only thing that needs your actual information would be Amazon, Ebay, PayPal, etc.

3. If you’re not sure, don’t.
It’s better to be safe than sorry. If you’re unsure about a website, try searching Google for it. You’d be surprised at what you can find out about a website or company through blogs or review websites.

Until next time,
Nito

It seems there’s a new name associated with the rental scam I posted a little while back. Katie Hart, which I assume is the same person who created the Anne Brooks scam.

I won’t go into all the details, because it’s an exact duplicate of the Anne Brooks scam, which you can find in a previous post here.

Remember that by law, no land lord can force you to fill out any personal information over the internet. If they won’t meet you in person, cross off the apartment and move on. Never give anyone your credit information via email, instant message or any other way online (Excluding certified credit monitoring websites).

I’d like to thank all my subscribers for bringing this to my attention.

Until next time,
-Nito

After looking for another hosting company, I managed to find FatCow.com. Now, this company might look worth the little amount you’ll pay for their hosting, but remember that you get what you pay for, lol.

I think I paid around $60 for a one year lease with Fat Cow. As soon as I logged into the control panel, I noticed why it was so inexpensive – there wasn’t much there. My first issue was with cronjob’s – there simply was none. I went through 3 or 4 agents before I got it resolved with a billing guy (I was trying to cancel my account), who asked me to hold for a few minutes while he went and had it put into my account.

So now I have a half-assed cronjob – It had a combobox with ‘Daily, Weekly, Monthly, Yearly’ in it.. Seriously? I can’t even set up a cronjob to run when I want it to? Are you fucking kidding me here?! Whatever, moving on…

My next issue is with their FTP. I managed to upload a few files a day (if I was lucky) before the FTP just started timing out and wouldn’t connect anymore. So, I went into the control panel, thinking I could use their java based FTP – WRONG! Browse for a file, click upload and get a message “PHP extension can not be uploaded for security reasons” or something along those lines. Awesome, right?! I also can’t upload htaccess, so their java ftp client is useless.

I finally contacted their tech team about the FTP *goes to look for chat log*. Oh, that was the chat I actually X’ed out of due to their tech being a complete idiot, and trying to blame me for the issue. I explained to him, that I have no issues with any of the other FTP accounts I work in (around 8 or 9 other servers), but he still tried to say it was on my end. I eventually got sick of that shit, and just closed the window out of frustration.

I called up their billing department right after that, and had the hosting canceled and refunded (or so I was told), leaving me with a parked domain, that was quickly transferred over to another host. After about a week of waiting for the refund, I opened a chat session with their billing dept. a little bit ago.

info: Thank you for contacting support.

Please be prepared to answer your Security Question when we begin chatting. To enhance our security protocols, we’ll need you to provide the answer to your Security Question at the beginning of our conversation. If you have not yet set your Security Question and Answer, please log into your account now to set it up. Thank you.

Please hold for the next available operator to respond.

info: You are now chatting with ‘Nina Scott’
Nina Scott: Hi Nito. My name is Nina Scott, how are you today?
Nito Belmont: Good. I was wondering when I was going to get the refund for my hosting I canceled last week
Nina Scott: Thank you for the authentication.
Nina Scott: Could you please let me know the username of the account which you have cancelled?
Nito Belmont: The same one I entered for this chat.
Nina Scott: May I place you on hold for 2 to 3 minutes while I review your account?
Nito Belmont: Sure
Nina Scott: Thank you for holding.
Nina Scott: I apologize for any inconvenience this has caused you.
Nina Scott: I’m sorry, in order to assist you, I am going to have to ask a member of our team who specializes in this issue to take care of this for you.
Nito Belmont: Ok..
Nina Scott: Could you please hold for 2 to 3 minutes, while I provide you with the link to access the resolution of the issue?
Nito Belmont: Yes
Nina Scott: Thank you for holding.
Nina Scott: I have noticed that we have downgraded your account to Domain Parking account. I have escalated the issue for refund.
Nina Scott: You can expect a response regarding your issue within 24-48 hours. You can view the ticket status and resolution at:
Nina Scott: http://www.fatcow.com/member/sconsole/
Nito Belmont: Now, am I going to expect issues dealing with whoever takes this, due to it being opened on or after my 30 days?
Nito Belmont: Because I canceled the account last week, thinking I wouldn’t have to do anything further.
Nina Scott: No, your account is not yet cancelled. We have downgraded it to Domain Parking account.
Nina Scott: It is a free account.
Nina Scott: We will issue the refund within 24-48 hours.
Nito Belmont: But I canceled the hosting
Nito Belmont: The billing person I spoke to on the phone said I would receive a refund for that
Nina Scott: Yes, hosting plan is canceled and it is downgraded to Domain Parking account.
Nina Scott: Yes, we will issue the refund of your account.
Nito Belmont: Alright
Nina Scott: Is there anything else I can assist you with today?
Nito Belmont: Nope. Have a nice day

So after a week of waiting, and me having to contact their billing department, I should hopefully be getting a refund in the next couple of days. And now, it’s time for the actual review…

This company has semi-decent support, with the occasional assholes who think they know everything and you’re always wrong. You’ll probably end up getting different answers from each staff member you talk to. Example: Two tech’s told me Fat Cow does not support cronjob’s, the billing guy told me they did, and had it added.

Hopefully, if you decide to go with this company, you won’t have the issues I had. I don’t know how this company has managed to be ranked first in a lot of the hosting lists, but that shit needs to be changed. Fat Cow is a decent hosting company, IF you’re running html files or a pre-packaged script you install from their control panel, but that’s about it. I wouldn’t recommend this company to anyone I know after the bullshit I went through.

I think you’re better off using a free hosting provider over these fucking idiots.

[UPDATE: 1PM]

Hello,

Per your request, we have downgraded your account ‘XXX’ to Domain-Parked. This package is for free of cost with no hosting space so that you can manage your domain name. Also, I have refunded the amount of $39.16 to your credit card ending with ‘XXXX’ on July 28, 2009 which was charged towards the hosting. Please allow 7-10 days for this refund to appear on your credit card statement.

If you have any further questions, please update the Support Console.

Sincerely,

(Name Censored)
Billing Specialist

Nito Belmont contacted FatCow
How am I only being refunded $39.16. The original bill was for $62.99. If the domain parking is free that means you’re trying to charge me $23 for the domain name…

Oh yes, fun fucking times… I love when businesses try and rip you off. I’m sure there’ll be more to come, as I try and pull my money from their clammy claws.

Until next time,
Nito

Finding an apartment can be a long and tiresome process, and can be even worse if you come across falsified postings like the one I will be reviewing in this post.

My girlfriend and I are looking for a new apartment, and we found an apartment on Craigslist that was at a decent price in the same area as we are now. I sent an email asking for more information (including an address), and as soon as I got a reply, I knew it was a scam. Googling it finds one other post for the same person/website.

This is the email received, both in image and text format.

Email Image

Hi and thank you for your interest,

My inbox was flooded yesterday with inquiries so I’ll do my best to answer some of the questions:

1) Cable, wireless internet, heat, water, and electricity are included in the monthly rental fee.

2) The security deposit amount depends on your credit score.

3) Move-in can begin as early as next month.

4) I haven’t gotten around to taking more pictures yet but I will be taking groups of interested parties for showings later this week.

Due to the overwhelming response I’ve included a preliminary rental application for any interested parties. I only want to converse with people who are serious about actually moving into this property. It should take about 5 mins. So if you are interested in a showing and further information, please fill out the attached application and email it to me so that I can get back to you soon.

I’ve attached the application. Please reply with the application or paste your responses in the reply email.

or copy and paste the answers onto the reply email.

This will be given on a first-come-first-serve basis. I only have 5 more units like this one unfortunately.

Don’t Delay!

Looking forward to hearing from you,

Anna Brooks

Alright, so right off the bat it’s either an overly-eager sales person, or a template email. I copy/paste their website into a web browser, and it comes up with an empty server – Now we know for sure it’s a template email.

Empty Server Image

Now inside this email is a .DOC attachment, which at first glance looks like a legitimate rental application, but if you look at the second page “she” says she only accepts applicants who do this free credit check from a website she specifies.

Doc Image

3. CREDIT REPORT:
Like most companies today, we require a recent Credit Score. This is only to do a criminal background check and keep our tenants safe. We will only speak to renters with a credit report from ‘My Rental Credit Score’ because we have seen many fraudulent reports. This is a well known company for and should garner some trust.
You can get the free report here:

http://www.MyRentalCreditScore.com

When you go to the the website in the .doc, it will redirect to another site – gofreecredit.com – with a affiliate ID in the link. If you hadn’t already known this was a scam, this should have tipped you off.

This is a classic affiliate scam that I’ve seen been done for as long as I can remember since affiliate networks have been around. On any affiliate network, there is a clear set of ToS (Terms of Service), which layout how you can and can not post your affiliate links. This is a breach of contract, and as such I have written an email to the affiliate website.

Hello,

I was falsely directed to your site via a rental agreement posted on Craigslist. I assume your ToS states that an affiliate can not falsely send users to their affiliate link.

ID: 11619
SubID: 24544-
Redirect Link: myrentalcreditscore.com
Name Used: Anna Brook

Regards,
Nito

So let’s overview what I’ve gone through in this post.

1. Sent an email for more information and got a reply without information I asked for.
2. Copy/Pasted the repliers website into a web browser, and it was an empty server.
2. The replier asked for you to do a credit score. This is a big flag, since any reputable rental manager would have you come in to do this, and usually charge for it.
3. The Credit Score link given was a forwarding link.

What to do if you receive a scam email like this:

1. If you go to the website given, make sure to get the ID’s. The URI will look something like this:

http://www.gofreecredit.com/tab_picture.php?lte=all&id=11619&subid=24544-

From that URI, you’re going to want to grab the numbers after “tab_picture.php?”. It would be the same for any affiliate site that uses this type of link. Simply grab the info after the question mark, and send the website an email with al the info you can about how you got there, and the ID’s.

2. Blog about it. Blogging is THE most powerful tool any civilian has – period. Blog’s enable a normal person like you or I to become a sort of journalist. Just make sure that your posts are true and stay on topic.

2a. If you don’t have a blog, I have set up an email dedicated to responses and such. I will go through each email thoroughly and gather more information on the subject in order to give my readers more clarification on it. The email: reportit [at] phux.org

Legally, there’s not much you can do aside from emailing the company where the link sent you, unless they fraudulently got money out of you. This is why we try to get the information out, it helps others not fall into this sort of trap.

**TIP: NEVER, and I mean NEVER fill out an application and send it through email. If they won’t take it in person, it’s not real.

Until next time,
Nito

In my previous post, I wrote about how Everest doesn’t include back-end languages in their course of study. I sent them an email last night requesting they remove me from enrollment, and let’s just say they don’t take these things very well..

My emails to Everest Institute:

Hey XXXX,

I was asking, because I don’t want to waste money on a degree that doesn’t involve back-end languages. It seems to me that paying close to $30,000 after interest for a website development degree would include not just front-end garbage you can learn off a website in the course of a week.

Hello XXXX,

You can remove my enrollment. I have provided reasoning below.

A higher education institute is nothing more than a business, and as such should be treated like one. Potential customers (Students), should be addressed accordingly and in a timely manner.

I understand that as a Dean or Professor, they may be busy, but I also know that promptness receives better outcomes than waiting. Which is why I pride myself and my company on being prompt on replies to any and all invoices we may receive, whether they be from potential or long-time customers, and refuse to do business with any company who chooses not to.

I know that looking up information on subject matter in order to solidify a customer would have been in the best interest of your company, and would have been no more than asking the professor if subjects in my query were part of the courses. If this is what I have to look forward to by attending the Everest Institute, I’ll pass.

If there is anything I need to do in order to cancel the enrollment process, please respond via this email with instructions.

I removed the name of the person I contacted, because they didn’t do anything wrong, however, Shirley can kiss my ass on the whole fucking privacy thing, as this next part comes from her in a response email.

I’m sorry you feel as though I was not prompt enough with your response. I forwarded your email onto the appropriate people since as an admissions representative, I do not have the correct answers. I would feel more comfortable having the dean, department chair, or teachers respond to specific questions to ensure it is the correct information. The only information I received from Shirley Nagg was as follows:

Hi XXXX!

It’s not that we don’t want to include them, it’s that they go in and out of style too often to be written into a curriculum that takes time to go through accrediting agencies the way we have to (we can’t “turn on a dime”). When we include the “front-end garbage” it is because it is being used and is stable – i.e. not apt to go out of style. This has come up before, and my usual suggestion is for the student to ask the instructor for help in that area with whatever is currently popular as an add-on to the course.

I’m going to forward this to Aaron Sullivan who is the lead instructor for the “front-end garbage” with the request that he contact you.

At this point….since it was YESTERDAY that you asked, I was waiting on a response from the professor to ensure that I get you the correct information. It seems as though you were not all that serious about attending school anyway- I really don’t think it was the “timeliness” of my emails.

Good luck with “Phux” Development.

Oh yes, this is the person I would want representing my business. Get the fuck outta here. How hard would it have been to send the email simply stating that they don’t offer those languages in the course? I love how she capitalizes “yesterday” as if to be screaming it at me, lol. And the statement “It seems as though you were not all that serious about attending school anyway”, makes me lol hard.

I would LOVE to have my degree in web development, but not some bullshit degree where I learn little to nothing. We pay for college not because we simply want a piece of paper, but because we seek to further our knowledge pool. I need to learn front-end garbage, but not the crap they’re teaching there. No (X)HTML, just traditional? Are you serious… See, I know enough about the front-end crap to know if you don’t know shit about web design, you shouldn’t be learning traditional HTML. That shit will rot your fucking brain.

I guess my biggest thing with Everest now, is that they offer this bullshit degree, where you’re gong to learn “outdated” material (ie HTML, Photoshop CS3), but they say they can’t teach you back-end because the material changes too much. PHP5 was released in fucking 2004.. By my count, that’s 5 years ago. How is it constantly changing? There are NO dramatic changes to a back-end language that keep the same fucking major version number.. My guess, is that they don’t want to take the time to teach it to anyone. Whatever.

Final words.. What else is there to say, honestly.. If you read this, and you still decide to go to any Everest Institute for your degree, you’re a fucking idiot and deserve the shit you’ll have to endure there.

I’m not sure if that “Aaron” guy’s sending me another email, but if they do I’ll be sure to add that to the blog.. Oh the fun times.

Until next time.

-Nito