📜 ⬆️ ⬇️

About fraud and police reaction

Good day.
Under the cut a short story about how my wife’s account on a popular social site. networks were hacked, as I wrote a complaint to the prosecutor’s office for this event and what came of it all. By the way, it will be about the user agreement, good week about it on Habré is still going on.

It was March 17th. My wife sat in classmates, then we went to clean the house (Saturday as it was). And then she went back to the site and was surprised to find that on her behalf several messages were sent to several friends with the following content:
"Hello how are you? :) Listen, I want to ask you about a small favor :) just imagine, I take part in the photo contest, and take second place, if not difficult, throw off your voice here <here was the site address> "
My wife came running to me with a question: What is happening?
Quickly checking the computer with 2 anti-virus utilities of different vendors, looking into the hosts file, changing the account password and sending a notification to all my wife's friends so that they did not go to the link, I began to think what to do next.
Going to both of these links (konkuors1.ru/ Choice of classmates> .html and superigrap1.ru/ Choice of classmates> .html), I found the same site. As it turned out their IP address is the same. Having played with different accounts (ivanova, petrova, petrov), and looking at two design options, feminine:

and masculine:

Making sure that for an arbitrary account, its owner is always in second place, I decided that there were fraudulent acts and illegal access to information. And so it became interesting to me, and how our law enforcement agencies will behave in this situation, that they decided to write a statement to the prosecutor’s office. The statement outlined the facts described above, attached a few screenshots, well, in the conclusion I wrote this request:
“On these sites there is a photograph of my wife, taken from odnoklassniki.ru website mentioned above. She did not give permission to use her photo. To vote, it is proposed to send an SMS to the short number 3652. The cost of an SMS is more than 150 rubles.
I ask to initiate a criminal case against the owners of these sites and the short number 3652, under article 152 of the Criminal Code of the Russian Federation and article 272 of the Criminal Code of the Russian Federation. ”
For those who are too lazy to look for articles on the Internet, this is actually “Fraud” and “Illegal access to computer information.” Having written the application in the form of a separate document, I went to the website of the prosecutor's office, indicated my data and, having attached the file, pressed the send button.
Further events developed slowly. Here is their chronology.
1. A couple of days later they called me and said that the file did not join the application. I had to send an application to the post office (e-mail, you don’t think anything here).
2. Then I received a registered letter with the notification that my letter was sent to a specific prosecutor.
3. Then, in a second letter, I was informed that the prosecutor’s office did not deal with such matters and my application was transferred to the ATC.
4. A week later, a representative from the Department of Internal Affairs called me and asked me to meet for an inquiry after my statement. Having agreed that we would meet after working at my home, I gathered information that might be of interest to the investigator. I took several accounts from classmates and went to their sites with their data (to confirm the fact of fraud). I looked at when and for how long these sites were registered (as it turned out on March 12, 2012, and only for 1 day). Well, I looked at which provider these sites are hosted. A young man came in to interview me. I looked at the fraudulent site, it caused genuine admiration for him: “Wow!”, And, writing down the data of the German provider, left.
5. Just a couple of days later, they called me and offered to come to the ATC. The meeting in the Internal Affairs Directorate began with the fact that the investigator showed me an excerpt from the rules of classmates: “3.18. The User, posting Content on the Site, grants the Site Administration and / or Partners of the Administration and / or other Users on the terms of a gratuitous, non-exclusive license the right to use this Content throughout the entire period of validity of the exclusive right to the corresponding Content throughout the world by any means necessary under relevant Services, including paid, including, but not limited to, making available to the public, viewing, reproduction, translation and processing. "And l told me that he sees elements of a crime. I repeatedly (without demonstrations) stated the reasons why the site was fraudulent, and that even if the fraudsters could use the photo, no one gave them the right to send notifications to other members of the social network. Most of all, I was pleased with the question of the investigator, after I listed the ways in which you can install the attackers (to whom the domain is registered, to whom the money is transferred from the content provider, who paid for hosting). Actually the question sounded like this: “What if the attacker registered all this on someone else's passport?”. Those. the investigator expected me to bring him the attacker, but he will only have to file the file?
6. Well, the final touch. On April 26, a letter was sent to me (I received it much later, by the way, fervent greetings to the Russian Post), in which I was once again quoted 3.18 from the classmates' rules, and politely said: “Your wife’s picture of your full name is an integral part of Content used by the Partner of the Site Administration lawfully within the framework of a voluntarily concluded public offer. ” Well, then a couple of references to the laws, and at the end “the materials of the check are written off to the nomenclature case”

Findings:
First nice for me. I somehow assumed the development of events.
Now a couple less pleasant. If you carefully read the wording of the answer, then you noticed that the fraudsters were called “Partner of the Site Administration”, and in this case, indeed there was no “Wrongful access to computer information”. Because The administration of classmates has the right not only to use photos, but also to send any messages as part of their project. But about the fraud ... And the conclusion here suggests a very funny! This activity is not a fraud! They do not see this as illegal seizure of property. So, who else wants to steal money through content providers? Forward! You will not get anything for it.

')

Source: https://habr.com/ru/post/143140/


All Articles