Bloguri dofollow
Mihai Iorga
Postat pe data 15-04-2009 de Mihai Iorga

Încă un val de phishing! Iar primesc mail-uri cu sondaje online!
Am verificat html-ul care a venit:

1
document.write(unescape('%3C%48%54%4D%4C%3E%3C%48%45%41%44%3E%3C%4D%45%54%41%20%48%54%54%50%2D%45%51%55%49%56%3D%22%52%65%66%72%65%73%68%22%20%43%4F%4E%54%45%4E%54%3D%22%30%2E%31%3B%20%55%52%4C%3D%68%74%74%70%73%3A%2F%2F%77%77%77%2E%69%66%70%61%74%68%2E%63%6F%6D%2F%73%6F%6E%64%61%6A%2E%68%74%6D%6C%22%3E%0A%3C%4D%45%54%41%20%48%54%54%50%2D%45%51%55%49%56%3D%22%50%72%61%67%6D%61%22%20%43%4F%4E%54%45%4E%54%3D%22%6E%6F%20%63%61%63%68%65%22%3E%0A%3C%4D%45%54%41%20%48%54%54%50%2D%45%51%55%49%56%3D%22%45%78%70%69%72%65%73%22%20%43%4F%4E%54%45%4E%54%3D%22%2D%31%22%3E%0A%3C%2F%48%45%41%44%3E%3C%2F%48%54%4D%4C%3E%0A'));

ceea ce se “traduce”:

1
2
3
4
<html><head><meta HTTP-EQUIV="Refresh" CONTENT="0.1; URL=https://www.if**th.com/sondaj.html">
</meta><meta HTTP-EQUIV="Pragma" CONTENT="no cache">
</meta><meta HTTP-EQUIV="Expires" CONTENT="-1">
</meta></head></html>

care redirecţionează la

1
http://asteriskpbx.g**et.pl/sondaj/

Phishing

Oare e cineva care haleşte prostiile astea ?

LE: Am cenzurat link-urile …