- Twitter: @TheAnon0ne | E: theanon0ne@hushmail.com
- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
- This is a sub-op of #OpPedoChat | http://pastebin.com/xvBaU2vd
- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
- Started: 7/29 @ 3pm GMT
- Last update: 7/30 12.45am GMT
- Busy week, see http://bit.ly/MeA2FC for more info.
- ``````````````````````````` #OpEcatel: Teaching a bad host a lesson ```````````````````````````
- Greetings Netizen. Host Ecatel is an evil company that has been lightly profiled before, see
- bit.ly/9hj5fN & bit.ly/PQKUrm for just two examples. Recently, we discovered a cache of sites
- hosted by Ecatel that were targets for #OpPedoChat. When we asked Ecatel to remove the sites,
- they not only refused several times, they literally resorted to "go screw your mom" for reply:
- i.imgur.com/5WMZC.png | TL,DR: Ecatel refuses to remove kiddie porn sites.
- This will not stand. Operation Ecatel: Engaged. Expect Us.
- =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= * ~ *Operation News & More* ~ * =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
- ===============================================================================================
- * 7/29: Some of the targets fluctuate, but billing.ecatel.net & helpdesk.ecatel.net have been
- staying down most of the day. None of Ecatel's holdings have escaped Tango Down today.
- * 7/29: List of all IP addresses tied to Ecatel avail @ http://bit.ly/QVOyCE
- * 7/29: Ecatel sent another email, telling me to go screw my mother: i.imgur.com/5WMZC.png
- In exchange, I gave them this form: http://bit.ly/Owth0Y
- ~ #OpEcatel launched @ 3pm GMT in response to the egregious nature & behavior of Ecatel ~
- * 7/29: Call to arms! Target is ecatel.co.uk & ecatel.net | They REFUSE to remove CP they
- host. Their answer to the opportunity we let them have: i.imgur.com/wmBBH.png
- 7/28 ~ 7/29: We gave Ecatel *another* chance: http://i.imgur.com/ndsQ6.png
- * 7/28: ecatel.co.uk is TangoDown, been down for hours| Bad host REFUSED to remove CP sites
- * 7/21 - 7/28: Several Anons contact Ecatel, nicely, and get rudely rebuffed and ridiculed.
- Jimmies start getting rustled.
- * 7/21: Ecatel.net, responsible for several CP targets, profiled: http://bit.ly/Psoeuw
- ##############################################################################################
- ################################
- Targets (updated 7/29 @ 4pm GMT)
- ################################
- http://ecatel.co.uk
- http://www.ecatel.info
- http://ecatel.net (89.248.167.19)
- http://billing.ecatel.net
- http://mirror.ecatel.net
- http://noc.ecatel.net
- http://helpdesk.ecatel.net
- http://www.smokeping.nl
- DNS servers: 89.248.167.3, 89.248.163.67, & 89.238.154.91
- List of all IP addresses tied to Ecatel avail @ http://bit.ly/QVOyCE
- ##############################################################################################
- #########
- Harvester
- #########
- g.nelson@ecatel.net, r.eeden@ecatel.net, eeden@ecatel.net, sale@ecatel.net, XXXXX@ecatel.net,
- admin@ecatel.net, abuse@ecatel.net, sales@ecatel.net, info@ecatel.net, noc@ecatel.net
- ##############################################################################################
- ####
- Moar
- ####
- Ecatel was rated #1 worst host in the world for serving spam, infected websites and Zeus C & C servers http://news.hostexploit.com/hosts-and-registrars-news/4566-ecatel-speaks-to-dutch-news-about-1-bad-host-position.html
- Ecatel does more than just kiddie porn, they are well-known to facilitate cyber criminals, botnets, etc: http://www.secanalyst.org/2011/08/23/understanding-ecatel/
- http://hphosts.blogspot.com/2010/04/as29073-ecatel-need-more-proof-of-their.html
- http://badhost.info/AS29073
- http://www.scamfraudalert.com/identity_theft_phishing_spam_blackmails/13773-spamhaus_project_reports_ecatel_net_network_host_most_notorious_spammers_cybe.html
- http://www.washingtonpost.com/wp-dyn/content/article/2007/10/12/AR2007101202461.html
- ##############################################################################################
- ######################################################################
- d0x (in progress, not guaranteed accurate). Some credit to @OpPedoChat
- More info available @ http://bit.ly/Psoeuw
- ######################################################################
- Owner of ECATEL LTD
- Name: Ferdinand Reinier Van Eeden
- http://company-director-check.co.uk/director/912188052
- http://www.cdrex.com/ferdinand-reinier-van-eeden/1074299.html
- Short Name: Ferdinand Van Eeden
- Year of Birth: 1986
- Address:
- Singravenstraat
- 42 2548SL
- Gravenhage
- Address 2:
- 235 Spui
- Den Haag
- Netherlands
- 2511 BP
- Number: 070-3944255
- 235 Spui Den Haag Netherlands 2511 BP (Registered to company)
- Person ID: 17485089
- Director ID : 912188052
- Company's ;
- Company Name
- FIBER XPRESS LIMITED - 06466487 (Company registration number)
- REBA ENTERPRISES LIMITED - 06265960 (Company registration number)
- REBA HOLDING LIMITED - 06264749 (Company registration number)
- ECATEL LTD - 05562825 (Company registration number)
- Company Address's ;
- 80 SIDNEY STREET
- FOLKESTONE
- CT19 6HQ
- GB
- Manger of ECATEL LTD:
- Name: Bartholomeus Johannes Karreman
- Short name - Bartholomeus Karreman
- Year of Birth: 1946
- Address
- 2648 Neherkade
- Den Haag
- 2521 Rv
- The Netherlands
- 2521 RV
- Director ID : 912188051
- ##############################################################################################
- ###############################################################################
- Vulnerability Information (send moar to @theanon0ne or theanon0ne@hushmail.com)
- ###############################################################################
- Starting Nmap 6.01 ( http://nmap.org ) at 2012-07-29 11:31 EDT
- Nmap scan report for www.ecatel.co.uk (80.82.67.2)
- Host is up (0.11s latency).
- Not shown: closed ports
- PORT STATE SERVICE VERSION
- 80/tcp open http Apache httpd 2.2.9 ((Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch)
- 111/tcp open rpcbind (rpcbind V2) 2 (rpc #100000)
- 2049/tcp open nfs (nfs V2-4) 2-4 (rpc #100003)
- www.ecatel.co.uk/ [200]
- http://www.ecatel.co.uk [200] HTTPServer[Debian Linux][Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch], PHP[5.2.6-1+lenny9][Suhosin-Patch], Frame, Country[NETHERLANDS][NL], IP[80.82.67.2], Apache[2.2.9], X-Powered-By[PHP/5.2.6-1+lenny9], Title[ Ecatel - Home]
- URL : http://www.ecatel.co.uk
- Status : 200
- Apache ---------------------------------------------------------------------
- Description: The Apache HTTP Server Project is an effort to develop and
- maintain an open-source HTTP server for modern operating
- systems including UNIX and Windows NT. The goal of this
- project is to provide a secure, efficient and extensible
- server that provides HTTP services in sync with the current
- HTTP standards. - homepage: http://httpd.apache.org/
- Version : 2.2.9
- Country --------------------------------------------------------------------
- Description: GeoIP IP2Country lookup. To refresh DB, replace
- IpToCountry.csv and remove country-ips.dat. GeoIP database
- from http://software77.net/geo-ip/. Local IPv4 addresses
- are represented as ZZ according to an ISO convention.
- Lookup code developed by Matthias Wachter for rubyquiz.com
- and used with permission.
- Module : NL
- String : NETHERLANDS
- Frame ----------------------------------------------------------------------
- Description: This plugin detects instances of frame and iframe HTML
- elements.
- HTTPServer -----------------------------------------------------------------
- Description: HTTP server header string
- Os : Debian Linux
- String : Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch (from server string)
- IP -------------------------------------------------------------------------
- Description: IP address of the target, if available.
- String : 80.82.67.2
- PHP ------------------------------------------------------------------------
- Description: PHP is a widely-used general-purpose scripting language
- that is especially suited for Web development and can be
- embedded into HTML. - homepage: http://www.php.net/
- Version : 5.2.6-1+lenny9
- Module : Suhosin-Patch
- Version : 5.2.6-1+lenny9
- Title ----------------------------------------------------------------------
- Description: The HTML page title
- String : Ecatel - Home (from page title)
- X-Powered-By ---------------------------------------------------------------
- Description: X-Powered-By HTTP header
- String : PHP/5.2.6-1+lenny9 (from x-powered-by string)
- ##############################################################################################
- We are Anonymous.
- We do not Forgive.
- We do not Forget.
- Expect Us.
- @TheAnon0ne | theanon0ne@hushmail.com

